惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
V2EX - 技术
V2EX - 技术
The Last Watchdog
The Last Watchdog
宝玉的分享
宝玉的分享
T
Tenable Blog
WordPress大学
WordPress大学
K
Kaspersky official blog
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Hacker News - Newest:
Hacker News - Newest: "LLM"
P
Palo Alto Networks Blog
Help Net Security
Help Net Security
V
Vulnerabilities – Threatpost
Know Your Adversary
Know Your Adversary
C
CXSECURITY Database RSS Feed - CXSecurity.com
A
Arctic Wolf
Forbes - Security
Forbes - Security
Microsoft Azure Blog
Microsoft Azure Blog
爱范儿
爱范儿
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
H
Hacker News: Front Page
W
WeLiveSecurity
博客园 - 【当耐特】
G
Google Developers Blog
Martin Fowler
Martin Fowler
TaoSecurity Blog
TaoSecurity Blog
Hacker News: Ask HN
Hacker News: Ask HN
人人都是产品经理
人人都是产品经理
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
AI
AI
N
Netflix TechBlog - Medium
C
Cisco Blogs
I
Intezer
aimingoo的专栏
aimingoo的专栏
博客园 - 聂微东
G
GRAHAM CLULEY
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
www.infosecurity-magazine.com
www.infosecurity-magazine.com
小众软件
小众软件
Blog — PlanetScale
Blog — PlanetScale
MyScale Blog
MyScale Blog
L
Lohrmann on Cybersecurity
Engineering at Meta
Engineering at Meta

WeLiveSecurity

Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition Roblox executors: It’s all fun and games until someone gets hacked DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception Watch out for SVG files booby-trapped with malware Gamaredon X Turla collab Small business, big risk: How SMBs can fight back against ransomware HybridPetya: A Petya/NotPetya copycat comes with a twist Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass Are cybercriminals hacking your systems – or just logging in? Preventing business disruption and building cyber-resilience with MDR Under lock and key: Safeguarding business data with encryption GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes This month in security with Tony Anscombe – August 2025 edition Don’t let “back to school” become “back to bullying”
Ransomware’s back office: What the ransom note won’t say
Tomáš Foltýn · 2026-04-20 · via WeLiveSecurity

In March 2024, an affiliate of the BlackCat ransomware gang took to a cybercrime forum with a complaint. They’d carried out the attack on Change Healthcare – one of the largest healthcare data breaches in U.S. history – but never got their cut of the $22 million ransom payment. BlackCat’s operators had taken the money and vanished, putting up a fake FBI seizure notice on their leak site to cover the exit.

The grievance almost feels like a contractor dispute. Strip away the criminal element along with the apparent double-cross, and what’s left is (hints of) something any company executive might recognize: business arrangements complete with supply chains, pricing, competition, and customers who expect their money’s worth. Today’s ransomware runs on this very logic.

From the outside, however, you wouldn’t know it. To the untrained eye, the attacks seem like a break-in with a ransom note attached – someone gets in, locks (and steals) the critical files, leaves a crude demand, and waits for their rewards. Clear and simple, but almost certainly incomplete. Understandably, the blast and especially its impact draw the headlines, while everything that fed it stays ‘off camera.’ But much of what made the attack possible and successful happened where no one was looking.

Too cheap to fail

Behind the ransomware ‘storefront’ sits a kind of franchise operation, or perhaps a gig economy, complete with labor and tooling markets, subscription services, suppliers, partners, and even something akin to service-level agreements between the parties involved.

The industry is designed so that each participant only needs to be competent at their (narrow) function. The developer who maintains the ransomware platform and the brand never has to bother touching a victim’s environment to earn their rewards. The affiliate pays a cut or a fee for access using credentials they didn’t harvest themselves. The initial access broker who sells a foothold into a corporate network doesn’t (even need to) know what the buyer plans to do with the logins. Collectively, they pave the way for the intrusion long before the ransom note arrives.

So if your organization views a ransomware incident only as a near-random break-in that happened almost out of nowhere, its defenses will fail to account for how well-resourced and iterative the threat actually is. And whenever an industry structures itself this way, volume follows.

ESET’s detection data shows ransomware rising by 13 percent in the second half of 2025 compared to the prior six months, following a 30-percent increase in the first half of 2025. Meanwhile, Verizon’s 2025 Data Breach Investigations Report (DBIR) recorded a jump from 32% to 44% in the share of breaches involving ransomware, while the median ransom payment fell from $150,000 to $115,000. The targets are shifting, too. Mandiant’s analysis shows a move toward smaller organizations with less mature defenses.

More (and softer) targets plus smaller bites equate to a textbook volume play.

eset ransomware detections
Figure 1. Ransomware detection trend in H1 2025 and H2 2025, seven-day moving average (source: ESET Threat Report H2 2025)

Ransomware is hardly random

Ransomware actors have applied the logic of the franchise operation to the ancient ‘art’ of the shakedown, splitting the weight of blame along the way. Admittedly, the inner workings of what’s often known as ransomware-as-a-service (RaaS) are messier than those of, say, a fast food chain – coordination is loose and turf wars are real and occasionally public. Still, the underlying logic holds. The industry lives and dies by trust among its participants and the incentives that bind them. And as we know, incentives are famously known to determine outcomes more than anything else.

So much so that the field is crowded accordingly. Competition among humans in general enlarges its own form – first between individuals, then families, then communities, then nations. In the digital world, individual hackers competing for notoriety morphed into organized groups competing for territory, which became an interconnected network of specialists competing for market share. Unencumbered by borders or bureaucracies, cybercriminals compressed an arc that took legitimate industries decades into a couple of years.

Law enforcement doesn’t stand idly by, of course, and targeted disruptions create real uncertainty and impose real costs. But shutting down a firm in a competitive market doesn’t shut down the market. As the incentives stay aligned, the demise of a ransomware group triggers competition among survivors to take its spot. New entrants emerge, others rebrand or team up with peers, customers choose new suppliers, proven playbooks survive. Even the infighting among cybercrime groups amounts to the market purging its weaker players – competition working as advertised.

For example, when LockBit and BlackCat were disrupted by law enforcement in 2024, their affiliates moved mainly to RansomHub. In 2025, DragonForce – a relatively minor player at the time – defaced the leak sites of several rivals and took down the site of RansomHub, the then-leading operation. When RansomHub went quiet, Akira and Qilin absorbed its market share. The pattern holds because the barrier to entry stays low, the tools are available as a service, and the labor is so disposable that the supply can’t be starved of participants. Ransomware operations are built to scale regardless of whether or not any individual 'stakeholder' possesses formidable skills. 

The Red Queen’s race

Over the years, the ransomware playbook of yore – lock the files and demand a ransom – has given way to double extortion, where attackers steal corporate data before encrypting it and publish at least samples from the haul on dedicated leak sites. The FBI and CISA now routinely describe ransomware as a "data theft and extortion" problem.

But the specific dangers also change fast. Barely two years ago, ClickFix – a social engineering technique where a fake error message tricks users into copy-pasting and executing malicious commands – was on almost nobody’s radar. Now it’s widespread and used by state-backed and cybercrime groups alike.

lockbit leak site
Figure 2. LockBit leak site (source: ESET Research)

Then again, this speed of adaptation is hardly surprising once you realize that a version of it has been playing out in nature since, well, forever. Species locked in competition must continuously adapt merely to hold their position. Predators get faster, so prey gets faster. Prey develops camouflage, so predators develop sharper vision. Biology calls this the Red Queen effect, named after a character in Lewis Carroll’s Through the Looking-Glass who must keep running just to stay in place.

Security practitioners will recognize the dynamic, although the more familiar names – such as an arms race and a cat-and-mouse game – may be underselling it. The Red Queen effect describes something more specific: adaptation that produces no net advantage because the other side adapts almost in parallel.

Its clearest manifestation yet inhabits the space between defenders’ tools and attackers’ anti-tools. Endpoint detection and response (and extended detection and response, or EDR/XDR) products are key to catching the kind of activity that ransomware affiliates conduct inside compromised networks. As the products have improved, criminals responded by building a clandestine market for tools designed to disable them.

And where there’s a market, there’s a product – typically, lots of it.

ESET researchers track almost 90 EDR killers in active use. Fifty-four exploit the same underlying technique: loading a legitimate but vulnerable driver onto the target machine and using it to gain the kernel-level privileges needed to shut the security product down. The technique is called Bring Your Own Vulnerable Driver (BYOVD), and the vulnerable drivers are a commodity – the same driver appears across unrelated tools, and the same tool migrates between drivers across campaigns.

eti-ecrime

The EDR killer market mirrors the ransomware economy it serves. These anti-tools come packaged with subscription-based obfuscation services that update regularly to stay ahead of detection. Affiliates, not the ransomware operators, typically choose which killer to deploy – the purchasing decision is made at the franchise level. When the defensive product updates, the obfuscation service follows. Red Queen, again.

The sheer investment in EDR killers is, somewhat perversely, the clearest measure of how much damage the detection tools inflict on the criminal business model. After all, you don’t build an entire product category around disabling something that isn’t hurting your bottom line.

And the anti-tools may scale further still as AI is making the market, not to mention the wider cybercrime economy, even easier to join. ESET researchers suspect that AI assisted in the development of some EDR killers – the wares of the Warlock gang are but one example. In fact, last year ESET experts also spotted the first AI-powered ransomware, albeit not in actual attacks. Separately, other researchers have documented what they call ‘vibeware‘: AI-aided malware produced at volume and intended to flood the target environment with disposable code in the hopes that some will get through. The barrier to producing malware has dropped to a point where the constraint is intent, rather than formidable skills – much like what we’ve witnessed on the broader cybercrime scene itself.

Reading the market

Viewing ransomware only as an attack produces defenses built against attacks. But think about ransomware as an industry and additional priorities come into focus.

The questions worth asking yourself include: How is the Red Queen dynamic between defensive products and anti-tools evolving? Which malicious tools, techniques and procedures are doing the rounds now? Can our security stack ward off a BYOVD attack that uses the drivers now in circulation? What happens to our environment if an MSP in our supply chain is compromised? Which ransomware actors are actively targeting our sector, and which EDR killers are they buying?

If you can’t answer these and other pertinent questions, it could be that by the time the industry’s output reaches you, much of the chain has already executed. You can’t predict which group will target you, when, or through which vector. But you can maintain a current map of where the active groups are going – and whether any of those paths could lead to your door.

eset-world-2026-invite