TropChaud · @IntelScott
82 followers · 13 posts · Server infosec.exchange

Analyzing overlap for nine top

This originates from analysis of ransomware targeting schools, but most of these families have threatened a range of critical infrastructure & other industries too

Each ransomware covered here has published extortion threats involving a school or university during the past year, and this trend is increasing. I tallied 66 ransomware extortion threats against these entities since last October. A few groups dominate (see pie chart), and victim count jumped especially high in recent months for schools (K-12) (see bar chart).

The covered here (and count of associated extortion threats against education entities) are: (25), (8), 3.0 (7), / (6), LockBit 2.0 (5), (4), (3), , Snatch (2), & , , Sabbath, and Stormous (1 each). Also / , which is used by Vice Society, but no relevant posts were observed.

Visual summary of my analysis: app.tidalcyber.com/share/8d9f2

Overall the nine ransomware map to 131 unique techniques total, sourced from 30 recent public reports, mainly malware analysis & government advisories ("Show only labelled techniques" gives the best view). The underlines & numbers in the cells indicate number of malware mapped to that technique. Background color gradient represents number of sources referencing it. This tool helps with pivoting to defenses and analytics (think Sigma rules), offensive tests (Atomic Red Team), and data sources (make sure you have proper logging enabled) mapped to the same techniques.

#ttp #ransomware #education #malware #vicesociety #pysa #lockbit #ALPHV #blackcat #hive #bianlian #quantum #Conti #revil #hellokitty #FiveHands #threatintel #sharedwithtidal

Last updated 2 years ago