I've said it in more than one opportunity: 2016 was the year of ransomware. Its developers not only discovered a very effective way to make quick money, but also how unprepared we were to face its threat. The folks at SonicWall published a report that accurately reflects the advance of ransomware: from 3.8 million attacks in 2015, we went to 638 million. And this is just the beginning.
At first, ransomware news seemed distant and isolated. Then we noticed that some variants changed their attack profile, infecting computers in hospitals and government agencies. That particular well is far from running dry, but the competition only did more to simplify access to the kits, lower prices, and of course, point their cannons at the average user. The impressive success of ransomware is not limited to technical details. Its psychological impact is very large, and the mechanics of 'pay or lose everything' make millions of users tremble. Yes, I said millions. The security company SonicWall published the latest version of its annual threat report, and what ransomware did in 2016 was chilling.
SonicWall described the increase in attacks as 'meteoric'. 2016 closed with 638 million attacks, compared to just 3.8 million in 2015. In the first quarter of last year, affected companies had already paid about 209 million dollars as 'ransom' for their data. The explosion of activity occurred in March, when attacks went from 282 thousand to 30 million. From there, the trend remained upward, and the last quarter of 2016 closed with 266.5 million attacks.
Why Did This Happen?
Why did this happen? SonicWall shares several reasons in its report. The first was mentioned above: a combination of simplified access to the black market with the low cost of tools, which in some cases were distributed for free. Add to that the concept of 'ransomware as a service', meaning that those interested in launching an attack do not need advanced knowledge to do so. At the same time, ransomware found a critical support point with bitcoins, which guarantee the anonymity of attackers. According to the report, ransomware in 2016 had a fairly balanced presence across different industries, but it is difficult to verify because many victims decided not to report the attacks they suffered.
The Most Used Payload
What was the most used payload? Locky won by a landslide, accumulating more than 500 million attacks. Petya was its immediate follower, with just 32 million.