Mcafee Labs Threats Report, JUNE 2021 REPORT
Total Page:16
File Type:pdf, Size:1020Kb
REPORT McAfee Labs Threat Report 06.21 REPORT Table of Contents 3 Letter from Our Chief Scientist 4 Ransomware: From Babuk to DarkSide and Beyond 4 Q1 2021 New Ransomware chart 5 Daily, Weekly, Monthly Ransomware Charts 7 Top Ransomware Families and Techniques 7 Unique Ransomware Families 8 Ransomware Coverage and Protection 9 McAfee Global Threat Intelligence 9 File by Country Charts 10 Queries and Detections 11 Threats to Sectors and Vectors 11 Publicly Disclosed Security Incidents by Continent 12 Publicly Disclosed Security Incidents by Country 13 Publicly Disclosed Security Incidents by Industry 14 Publicly Disclosed Security Incidents by Vectors 15 Malware Threats Statistics 20 TOP MITRE ATT&CK TECHNIQUES APT/CRIME 23 Resources 23 McAfee Labs and Researchers on Twitter 24 About McAfee 24 About McAfee Labs and Advanced Threat Research 2 McAfee Labs Threats Report, JUNE 2021 REPORT Writing and Research In this report we introduce additional context Christiaan Beek into the biggest stories dominating the year Mo Cashman John Fokker thus far and we can look no further than recent Melissa Gaffney Steve Grobman ransomware attacks. While the topic itself is not Tim Hux Niamh Minihane new, there is no question that the threat is now Lee Munson Chris Palm truly mainstream. Tim Polzer Thomas Roccia Raj Samani Letter from Our Chief Scientist Craig Schmugar What a 2021 we have had thus far. In this report we introduce additional context into the biggest stories dominating the year thus far and we can look no further than recent ransomware attacks. While the topic itself is not new, there is no question that the threat is now truly mainstream. This Threats Report provides a deep dive into ransomware, in particular DarkSide, which has resulted in an agenda item in talks between U.S. President Biden and Russian President Putin. While we have no intention of detailing the political landscape, we certainly do have to acknowledge that this is a threat disrupting our critical services. Furthermore, adversaries are supported within an environment that make digital investigations challenging with legal barriers that make the gathering of digital evidence almost impossible from certain geographies. That being said, we can assure the reader that all of the recent campaigns are incorporated into our products, and of course can be tracked within our MVISION Insights preview dashboard. This dashboard shows that—beyond the headlines—many more countries have experienced such attacks. What it will not show is that victims are paying the ransoms, and criminals are introducing more Ransomware-as-a-Service (RaaS) schemes as a result. With the five-year anniversary of the launch of the No More Ransom initiative now upon us it’s fair to say that we need more global initiatives to help combat this threat. We hope you enjoy this Threats Report, please stay safe. —Raj Samani McAfee Fellow, Chief Scientist Twitter @Raj_Samani 3 McAfee Labs Threats Report, JUNE 2021 REPORT Ransomware: From Babuk to DarkSide and Beyond Letter from Our Chief Scientist While the DarkSide Ransomware-as-a-Service (RaaS) attack on Colonial Ransomware: From Babuk Pipeline held recent headlines hostage in Q2 2021, the ransomware to DarkSide and Beyond activity story actually went deeper in the first quarter of the year. McAfee Global Threat Babuk, Conti, Ryuk, and REvil, preceded DarkSide in establishing 2021 Intelligence ransomware trends. Threats to Sectors and We observed that “smaller” ransomware campaigns decreased in Q1 Vectors while the Ransomware-as-a-Service campaigns targeted and breached Malware Threats larger organizations and companies. The number of Q1 samples dropped Statistics as more attackers shifted from mass-spread campaigns, toward fewer, but more lucrative targets. Most of these larger, targeted victims TOP MITRE ATT&CK TECHNIQUES APT/CRIME received a custom created variant of the ransomware family at a low volume. Resources Here’s a breakdown of McAfee Labs Ransomware research and findings About McAfee from Q1 of 2021: About McAfee Labs and Advanced Threat Research Q1 2021 New Ransomware chart New Ransomware 6,000,000 5.12M 5,000,000 4,000,000 3.02M 3,000,000 2.27M 2.51M 2,000,000 1.42M 1.25M 1.29M 1,000,000 0 Q3 Q4 Q1 Q2 Q3 Q4 Q1 2019 2020 2021 Source: McAfee Labs, 2021. Figure 1. While unique ransomware detected in Q1 2021 decreased 50% compared to Q4 2020 detections—in part following a drop in Cryptodefense—ransomware remained a most serious threat against larger organizations and businesses in Q1 and Q2 2021. 4 McAfee Labs Threats Report, JUNE 2021 REPORT Daily, Weekly, Monthly Ransomware Charts Letter from Our Chief Scientist Ransomware Detections Ransomware: From Babuk Daily to DarkSide and Beyond 1/1/21 499 McAfee Global Threat 1/2/21 484 1/3/21 1,028 Intelligence 1/4/21 1,499 1/5/21 1,024 1/6/21 877 1/7/21 642 Threats to Sectors and 1/8/21 336 1/9/21 773 Vectors 1/10/21 808 1/11/21 597 1/12/21 2,956 1/13/21 2,135 Malware Threats 1/14/21 5,116 1/15/21 3,507 Statistics 1/16/21 1,364 1/17/21 2,204 1/18/21 1,971 1/19/21 2,633 TOP MITRE ATT&CK 1/20/21 1,973 1/21/21 1,894 TECHNIQUES APT/CRIME 1/22/21 204 1/23/21 2,824 1/24/21 1,732 1/25/21 381 Resources 1/26/21 2,271 1/27/21 4,415 1/28/21 244 1/29/21 2,756 About McAfee 1/30/21 1,682 1/31/21 2,328 2/1/21 2,187 About McAfee Labs and 2/2/21 2,997 2/3/21 2,244 2/4/21 1,698 Advanced Threat Research 2/5/21 3,053 2/6/21 1,043 2/7/21 1,449 2/8/21 2,571 2/9/21 1,714 2/10/21 2,373 2/11/21 1,726 2/12/21 226 2/13/21 112 2/14/21 1,572 2/15/21 1,736 2/16/21 1,915 2/17/21 2,766 2/18/21 2,005 2/19/21 1,692 2/20/21 1,909 2/21/21 1,898 2/22/21 2,821 2/23/21 2,776 2/24/21 3,924 2/25/21 2,342 2/26/21 2,213 2/27/21 1,848 2/28/21 2,374 3/1/21 2,751 3/2/21 308 3/3/21 2,114 3/4/21 2,139 3/5/21 173 3/6/21 1,719 3/7/21 2,126 3/8/21 2,647 3/9/21 2,818 3/10/21 2,607 3/11/21 2,487 3/12/21 2,842 3/13/21 1,544 3/14/21 2,372 3/15/21 1,852 3/16/21 1,365 3/17/21 2,167 3/18/21 2,999 3/19/21 1,671 3/20/21 1,548 3/21/21 1,967 3/22/21 2,232 3/23/21 1,508 3/24/21 5,284 3/25/21 5,634 3/26/21 2,006 3/27/21 202 3/28/21 1,114 3/29/21 1,526 3/30/21 1,153 0 1,000 2,000 3,000 4,000 5,000 6,000 Source: McAfee Labs, 2021. Figure 2. A snapshot of ransomware detected among McAfee clients in Q1 2021 includes a daily high of 5,634 detections on March 25 and an average of 2,417 detections per day during the last week of March. 5 McAfee Labs Threats Report, JUNE 2021 REPORT Letter from Our Chief Ransomware Detections Scientist Weekly Ransomware: From Babuk to DarkSide and Beyond 1/1/21 2,011 1/3/21 6,179 McAfee Global Threat Intelligence 1/10/21 16,483 1/17/21 13,703 Threats to Sectors and 1/24/21 13,481 Vectors 1/31/21 15,550 Malware Threats 10,171 2/7/21 Statistics 2/14/21 13,595 Week of Week 2/21/21 17,822 TOP MITRE ATT&CK TECHNIQUES APT/CRIME 2/28/21 11,578 3/7/21 17,071 Resources 3/14/21 13,974 About McAfee 3/21/21 18,833 3/28/21 3,793 About McAfee Labs and 0 5,000 10,000 15,000 20,000 Advanced Threat Research Source: McAfee Labs, 2021. Figure 3. The most ransomware detections (18,833) in Q1 2021 were recorded in the week of 3/21-3/27. Ransomware Detections Monthly January 2021 53,157 February 2021 57,184 March 2021 60,965 0 20,000 40,000 60,000 80,000 Source: McAfee Labs, 2021. Figure 4. The greatest number of Q1 Ransomware Detections were recorded in March. 6 McAfee Labs Threats Report, JUNE 2021 REPORT Top Ransomware Families and Techniques Letter from Our Chief Scientist Ransom:W32/REvil (1,358) Ransomware: From Babuk Ransom:Win/RansomeXX (225) to DarkSide and Beyond Ransom:W32/Ryuk (160) Ransom:W32/NetWalker (81) McAfee Global Threat Ransom:W32/Thanos (56) Intelligence Ransom:W32/MountLocker (50) Threats to Sectors and Ransom:W32/WastedLocker (47) Vectors Ransom_Exc0rcist (45) Ransom:W32/Conti (28) Malware Threats Ransom:W32/Maze (18) Statistics Ransom:Win/Babuk (13) Ransom:W32/Suncrypt (12) TOP MITRE ATT&CK Ransom/W32_Clop (1) TECHNIQUES APT/CRIME Ransom/W32_DarkSide (3) Resources Figure 5. Ransomware-related malware families detected in Q1 of 2021 reveals About McAfee the prevalence of Revil, RansomeXX, and Ryuk prior to DarkSide’s headline- grabbing hack of Colonial Pipeline’s systems in May of Q2.