Details of The Story
As reported by Bleeping Computer, the start of 2024 has presented challenges for ransomware actors as fewer companies are opting to pay ransoms. Data from cybersecurity firm Coveware indicates a record low, with only 28% of companies capitulating to ransom demands in the first quarter of 2024, a slight decrease from 29% in the previous quarter. This trend of declining ransom payments has been consistent since early 2019, and is attributed to improved security measures, legal pressures, and broken promises by cybercriminals regarding the non-disclosure of stolen data.
In the first quarter of 2024, Coveware reported significant shifts in ransom payment patterns. The average ransom payment has decreased by 32% quarter-over-quarter to $381,980, while the median payment surged by 25% to $250,000. This suggests a reduction in the number of high-value ransoms but an increase in more modest, yet frequent demands.
The report also highlights a concerning trend: nearly half of all ransomware attack vectors in Q1 2024 remain unidentified, indicating evolving tactics by attackers. The most commonly exploited vulnerabilities included CVE-2023-20269 and CVE-2023-4966, signaling a continued focus on remote access and exploiting existing software flaws.
Description: This vulnerability affects the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to potentially perform a brute force attack to identify valid usernames and passwords. Additionally, an authenticated, remote attacker could establish a clientless SSL VPN session with unauthorized users. The vulnerability stems from improper separation of authentication, authorization, and accounting (AAA) between different VPN features.
Impact: A successful exploit could allow an attacker to obtain valid credentials to establish an unauthorized remote access VPN session or, in some cases, establish a clientless SSL VPN session when using earlier versions of Cisco ASA Software.
Mitigation: Cisco has planned software updates to address this issue. In the meantime, workarounds include applying mitigations per vendor instructions for group-lock and vpn-simultaneous-logins, or discontinuing use of the product on unsupported devices.
Severity: The CVSS score from NIST is 9.1 (CRITICAL), while Cisco’s score is 5.0 (MEDIUM), indicating a discrepancy likely due to differing assessments of exploitability and impact.
References: Cisco has provided a security advisory detailing the vulnerability and mitigation steps.
Description: This vulnerability is found in NetScaler ADC and NetScaler Gateway when configured in various roles like VPN virtual server, ICA Proxy, CVPN, and RDP Proxy. It involves sensitive information disclosure that could be exploited under certain configurations.
Impact: The disclosure of sensitive information could potentially allow an attacker to leverage the information to conduct further attacks or bypass security controls.
Mitigation: Citrix recommends applying patches and updates as provided in their advisory. Additionally, users should kill all active and persistent sessions as detailed by Citrix, or discontinue using the product if patches are not available.
Severity: The NIST CVSS score is 7.5 (HIGH), whereas Citrix assesses it as 9.4 (CRITICAL), reflecting significant potential for harm due to the vulnerability.
References: Detailed mitigation and patch information is available on Citrix’s support page and a proof of concept can be found on Packet Storm Security.
Additionally, law enforcement efforts have had a tangible impact on ransomware operations. The FBI’s disruption of the LockBit ransomware operation notably diminished its activity and disrupted other major ransomware groups, leading to internal conflicts and exit scams, like those seen with BlackCat/ALPHV. As a result, many ransomware affiliates have begun operating independently or leaving the cybercrime scene entirely.
Coveware also notes a significant shift in the ransomware landscape, with an increase in independent attacks using affordable ransomware services like Dharma/Phobos and a rise in variants of the Babuk ransomware. Many individuals involved in these ransomware schemes are not career criminals but are driven by the lack of legitimate economic opportunities in their regions.
Finally, Akira ransomware has remained the most active group in the first quarter of 2024, with the FBI attributing at least 250 organizational breaches and $42 million in ransom payments to this group alone.
In order to defend against ransomware implementing comprehensive cybersecurity measures such as regular software updates, robust backup solutions, continuous testing, and employee training on phishing and other common attack vectors is crucial. Additionally, employing advanced threat detection systems and maintaining strict access controls can significantly enhance an organization’s resilience against such threats.
Ultimately, staying informed about emerging threats and collaborating with cybersecurity experts for tailored defense strategies will equip companies like yours with the necessary tools to navigate the complexities of cybersecurity in today’s world.


