惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
A
About on SuperTechFans
Vercel News
Vercel News
B
Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
The Cloudflare Blog
Jina AI
Jina AI
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

Heimdal Security Blog

Slow is a design principle, not a delay AI adoption that pays off is built around keeping humans in the driver's seat Phishing in 2026. Latest statistics and analysis Shift Browser is signed adware that fingerprints your endpoint before it drops payload 6 ThreatLocker alternatives that should make your shortlist 50+ insider threat statistics for 2026 The Planting Seeds philosophy. Selling into schools takes years, not quarters What the DfE's cyber security update means for multi-academy trusts 9 Proofpoint alternatives. Pros & cons of the leading options The risk awareness radar. A superpower every MSP needs to train Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes How Heimdal grew from a bold idea into a global cybersecurity platform Tools Change. Teach People How to Keep Up The 4 best managed EDR service suppliers (and how to choose) How to choose the best SOC platform in 2026 (and our top 4) MediaArena malvertising: why a quarantine isn't the end of the incident Top 6 Managed Detection and Response Providers Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors How to scale your patches without scaling your team (the patch wave) AI didn't break patching. It showed us patching was already broken. Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes How Dynamic Defense shuts an attacker out without shutting down the business Static security has run out of road. The case for Dynamic Defense Breaking the MSP Echo Chamber: The Power of Community How attackers built a RAT on a Windows machine using its own .NET compiler Attacker enables RDP, creates admin, erases evidence in ten seconds Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It Your Next Insider Threat May Be an AI Coworker The OSI Model and Its Two Missing Layers
Nearly 40% of 2024 Ransomware Payouts May Have Gone to Ru...
Morten Kjaersgaard · 2025-11-05 · via Heimdal Security Blog

Ransomware victims paid an estimated $813 million in 2024. Nearly 40 percent of that may have gone to actors in Russia, China and North Korea, according to new analysis from cybersecurity firm Heimdal.

Heimdal used recent telemetry, infrastructure tracing and ownership mapping to assess how ransomware revenue is likely distributed.

The $813 million figure comes from Chainalysis and remains the most current full-year total available.

These findings offer new visibility into where ransomware profits go and raise questions about what governments, infrastructure providers and regulators can do to disrupt their flow.

Tracing the money

Heimdal’s analysis, based on internal telemetry, attack-source tracing and ownership mapping, shows how ransomware revenue moves through opaque networks and front entities.

If the 2024 $813 million ransomware payments were distributed proportionally, about $211 million would likely go to entities in Russia.

Russia, China and North Korea together could account for roughly 38 percent of total payouts.

Shell companies are often used to obscure operations.

One example is a German-addressed firm called Razi Network, which appears in European IP registry data but not in German business records, a sign of regulatory blind spots.

Similarly, North Korea’s APT38 group has been linked to operations from Panama-based IP ranges, showing how attackers exploit jurisdictions with weak oversight.

These entities often operate through a combination of national and transnational front companies.

Shell corporations and flexible address registries are frequently used to avoid attribution and delay enforcement efforts.

These findings highlight a core issue.

Ransomware thrives on cheap, accessible infrastructure and the ability to hide within global compliance loopholes.

How infrastructure enables it

The ransomware economy persists because several systemic gaps remain unresolved:

  • Inadequate know-your-customer (KYC) controls at domain registrars, IP allocators and national registries allow untraceable entities to operate.
  • Fragmented jurisdictions make coordinated takedowns slow and inconsistent.
  • There is no central authority or agreed-upon process for verifying IP allocations or legal entity ownership.
  • Profit-driven attackers automate, anonymize and scale operations at minimal cost.

How to raise the cost of attack

Reducing ransomware’s profitability means making attacks harder, riskier and more expensive to conduct.

Key actions include:

  • Strengthening verification at registries and infrastructure touchpoints
  • Increasing data-sharing between infrastructure providers
  • Enforcing transparency around payments and breach disclosures
  • Promoting intelligence collaboration between public and private sectors

Inside organizations, defensive strategies such as network segmentation, least-privilege access and immutable backups can reduce attackers’ returns by limiting damage and denying ransom leverage.

Why this matters

When attacking is cheap and defending is costly, criminals have the advantage.

To change the calculus, governments, industry and enterprises must target the economic foundations of ransomware: ease of set-up, monetization and concealment.

Ransomware is not just a malware problem. It is a business-model problem. Addressing it requires raising operational costs until the payoff no longer outweighs the risk.

Author Profile

linkedin icon

Morten Kjaersgaard is the Founder and Chairman of Heimdal®, a global leader in AI-powered cybersecurity. Under his leadership, Heimdal has grown from a startup in Copenhagen to a trusted security partner for over 16,000 organizations and more than 2,000 MSPs worldwide, defending against 260+ million cyber threats annually. With a sharp focus on unifying cybersecurity operations, Morten is recognized for his ability to align technical innovation with strategic business outcomes. His insights have shaped how organizations and partners alike approach risk reduction, compliance, and security maturity in an increasingly complex digital world. A respected voice in the industry, Morten frequently shares his expertise at international events and through media commentary—championing a more proactive, collaborative, and scalable model for cybersecurity success.