Tracking Ransomware Affiliates Across Multi-Platform Ecosystems

Ransomware has become big business across the globe. What used to be a crime committed by individual hackers with higher-than-average technical skills has become industrialized by the Ransomware-as-a-Service (RaaS) model. The model is built on a combination of core developers creating the ransomware while tertiary actors, known as affiliates, execute the actual attacks.

It is a tough model to stop because everyone goes their separate ways when law enforcement gets involved or a service collapses internally. Core developers vanish into secret corners of the dark web while affiliates simply move on to another RaaS provider.

Security teams can no longer fend off attacks by merely tracking known ransomware brands. They also need to track the affiliates that move between services. Fortunately, it is possible to build comprehensive threat actor profiles for each encountered affiliate using a combination of dark web threat intelligence and open-source research.

Smart Affiliates Use Multiple Platforms

DarkOwl, a cybersecurity organization that specializes in dark web threat intelligence, says smart affiliates are harder to track because they use multiple platforms. Rather than limiting themselves to a single platform or darknet marketplace, an affiliate might:

  • Coordinate an intrusion on Telegram
  • Purchase initial access credentials on a dark web forum
  • Deploy an encrypted botnet from an RaaS organization
  • Post stolen data to a well-known leak site

The multi-platform strategy makes individual actions appear isolated and decentralized. Traditional network telemetry often assumes them to be distinct and unrelated events. So if a security team only monitors the particular ransomware dropped on its network, they completely miss all the behavior that preceded the attack. Threat actor profiling answers this challenge.

Connecting the Dots With Threat Actor Profiles

Threat actor profiles are tools that help security analysts connect the dots across multiple platforms. Developing an actionable profile requires looking for behavioral anomalies and structured data left behind during an attack. The interesting thing is that structured data is almost always left behind. It is hard not to leave it. In addition, a threat actor’s operational habits tend to remain the same from one campaign to the next.

By paying attention to structured data and behavioral habits, investigators can track threat actors as they move among their various platforms. Several key indicators give them away:

  • Cryptocurrency – Ransomware affiliates prefer to be paid using cryptocurrency thanks to its ability to hide identities. But tracking the flow of crypto across multiple negotiations and platforms can tie together what otherwise seemed to be unrelated transactions.
  • Infrastructure – Affiliates are creatures of habit. They usually reuse servers, hosting providers, and even scanning tools. By identifying and tracking identical infrastructure configurations, analysts can link multiple attacks to a single individual or affiliate group.
  • Communication – Affiliates can be tracked based on the words and phrases they utilize when communicating with their victims. Even negotiation styles and the handles affiliates use to communicate on the dark web reveal clues about geographic location, national origin, etc.

DarkOwl’s dark web threat intelligence can be integrated into a security team’s workflow to help them better prepare threat actor profiles. Using both OSINT and information gleaned from dark web channels, analysts can cross-reference large amounts of data to figure out exactly who they are dealing with.

Over time, a combination of dark web threat intelligence and threat actor profiling provides a clear picture of individual affiliates, affiliate groups, and the platforms they rely on to plan and execute their attacks. All this knowledge gives security teams a leg up on preventing attacks before they are launched.

If you know how your enemy operates, you can proactively counteract his operations. That’s the point.

Share:
Back To Top