Risky Bulletin Newsletter
May 20, 2022
Risky Biz News: FSB-linked DDoS tool could also be used for disinformation campaigns
Presented by

News Editor
New Deadbolt ransomware attacks: Taiwanese IoT maker QNAP published a security alert on Thursday warning of a new wave of attacks using the Deadbolt ransomware against its network-attached storage (NAS) devices. The company said the attack targeted NAS devices using QTS 4.3.6 and QTS 4.4.1, and the affected models were mainly the TS-x51 series and TS-x53 series.
Ransomware academic study: A recent academic study on the landscape of ransomware payments has found that the operators of RaaS (Ransomware-as-a-Service) portals are better at laundering their funds than the smaller commodity ransomware crews. According to researchers, RaaS operators are more strict in their laundering patterns and prefer bitcoin mixers or (now-sanctioned) cryptocurrency exchanges over exchanges that adhere to KYC/AML regulations, typically used by the smaller commodity ransomware crews.
Ransomware initial access trends: A recent report published by cybersecurity firm Group-IB has found that many ransomware gangs prefer to use vulnerabilities in unpatched network devices as the preferred way to gain access to victim networks. In addition, the same report found that the average ransom demand grew by 45% to reach $247,000/attack last year in 2021. [Coverage of the report in Bleeping Computer]