RANSOMWARE  IN  TARGETED  ATTACKS
Ivanov  Anton
Kaspersky  Lab
CISO  NIGHTMARE  STORIES
CISO  NIGHTMARE  STORY
3Security  Analyst  Summit  2017
CISO  NIGHTMARE  STORY
4Security  Analyst  Summit  2017
HOW  BIG  IS  THE  PROBLEM?
HOW  BIG  IS  THE  PROBLEM?
6Security  Analyst  Summit  2017
WHO  IS  INVOLVED?
7Security  Analyst  Summit  2017
MOTIVATION
8Security  Analyst  Summit  2017
1) Money
2) Diversion  from  APT  attack
3) Unfortunately  it  is  very  easy  and  cheap  for  attackers  L
MONEY
9Security  Analyst  Summit  2017
ACTORS  BEHIND  TARGETED  ATTACKS  
11Security  Analyst  Summit  2017
Actors  behind  targeted  attacks  with  ransomware:
• Mamba  group
• PetrWrap group
• Partners  of  one  famous  underground  group
ACTORS  BEHIND  TARGETED  ATTACKS  
MAMBA  GROUP
12Security  Analyst  Summit  2017
MAMBA  GROUP
13Security  Analyst  Summit  2017
MAMBA  GROUP
14Security  Analyst  Summit  2017
MAMBA  GROUP
15Security  Analyst  Summit  2017
MAMBA  GROUP
16Security  Analyst  Summit  2017
MAMBA  GROUP
17Security  Analyst  Summit  2017
MAMBA  GROUP
18Security  Analyst  Summit  2017
1) Uses  exploits  to  own  an  organization’s  network
2) Installs  PUPY  Rat  for  persistence
3) Uses  mimikatz
4) PsExec for  ransomware  is  installed
PETRWRAP
PETRWRAP
20Security  Analyst  Summit  2017
PETRWRAP
21Security  Analyst  Summit  2017
PETRWRAP
22Security  Analyst  Summit  2017
PETRWRAP
23Security  Analyst  Summit  2017
PETRWRAP GROUP
24Security  Analyst  Summit  2017
PETRWRAP GROUP
25Security  Analyst  Summit  2017
PETRWRAP GROUP
26Security  Analyst  Summit  2017
3RD PARTY  PARTNERS
3RD PARTY  PARTNERS
28Security  Analyst  Summit  2017
3RD PARTY  PARTNERS
29Security  Analyst  Summit  2017
3RD PARTY  PARTNERS
30Security  Analyst  Summit  2017
3RD PARTY  PARTNERS
31Security  Analyst  Summit  2017
3RD PARTY  PARTNERS
32Security  Analyst  Summit  2017
3RD PARTY  PARTNERS
33Security  Analyst  Summit  2017
3RD PARTY  PARTNERS
34Security  Analyst  Summit  2017
CONCLUSIONS
CONCLUSIONS
36Security  Analyst  Summit  2017
CONCLUSIONS
37Security  Analyst  Summit  2017
• Targeted  attacks  with  ransomware  will  be  the  main  ransomware  trend  in  2017
• Protect  the  perimeter
• In  the  event  of  an  attack,  good  IR  could  help
• DO  NOT  PAY
• Use  security  solutions  with  a  behavioral  detection  component
LET'S  TALK?

Ransomware in targeted attacks