惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园 - 【当耐特】
月光博客
月光博客
C
Check Point Blog
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
美团技术团队
N
Netflix TechBlog - Medium
Stack Overflow Blog
Stack Overflow Blog
Y
Y Combinator Blog
L
LangChain Blog
The Cloudflare Blog

News Archives - Heimdal Security Blog

Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It AI Will Absorb 99.98% of SOC Triage Within a Year, as 79% of IT teams brace for AI-driven workload shift Heimdal Achieves OPSWAT Gold Certification for Anti-Malware Digital Warfare and the New Geopolitical Frontline Nearly 40% of 2024 Ransomware Payouts May Have Gone to Russia, China & North Korea Is Your Tech Stack Killing Profitability? The Silent Bug Crippling MSP Growth Heimdal 5.0.0 RC: RDP Protection, Ransomware Detection, and OS Deployment Digital doppelgängers: How sophisticated impersonation scams target content creators and audiences Heimdal Joins the Tidal Cyber Registry with Its Extended Detection & Response (XDR) Solution Heimdal Investigation: European Organizations Hit by PDF Editor Malware Campaign Colt Technology Services Breached – Warlock Gang Claims Attack Fortinet VPNs Under Coordinated Attack Attack Surface Management: Why MSPs Don’t Need Another Tool Should MSPs Stop Chasing Leads and Start Solving Problems? Agent Fatigue Crisis Hits 89% of MSPs as Security Tools Backfire Your Protection Guide For Cybersecurity in Manufacturing
Where Ransomware Profits Go and How to Cut Them Off
Morten Kjaersgaard · 2025-10-15 · via News Archives - Heimdal Security Blog

Researched and written by Heimdal founder Morten Kjaersgaard, this article exposes how even limited cooperation between registry bodies and law enforcement could cripple ransomware networks and raise the cost for cybercriminals.

This article serves as a wake-up call.

Even limited cooperation between registry bodies and law enforcement could cripple ransomware networks and raise the cost for cybercriminals.

Ransomware payments hit $813 million in 2024 and my expectation is that they will re-surpass $1 billion in 2025, as they did in 2023.

But where is all that money flowing?

Heimdal has conducted an in-depth analysis of internal attack telemetry, tracing attack sources back to ownership and affiliate entities.

Based on this analysis, if $1 billion were distributed proportionally across observed patterns, the resulting payouts by country would include a staggering $211 million flowing to Russia.

Russia, China, and North Korea combined account for roughly 38 percent of all ransomware payouts, equating to approximately $383 million.

Bar chart showing ransomware payouts by country, with Russia leading, followed by China and North Korea, in Heimdal Security’s blue brand palette on a white background.

How obfuscation enables attacks

Russia is known to leverage shell companies based in Germany, such as Razi Network, which is listed at a German address but does not appear in the national company register.

China utilizes entities in France while Hong Kong leverages one named Think Tech.

The degree of obfuscation becomes especially clear when looking at the origin of attacks.

Heimdal observed significant activity from North Korea’s APT38 group, which appears to be launching financially motivated attacks from Panama, using IP ranges like 45.227.254.151 to 45.227.254.156.

For such a small country, Panama hosts an unusually high number of attacks.

A heatmap of attack origins underscores the concentration in Russia, China, and North Korea.

Heatmaps showing ransomware attacks by country origin

The scale and organization behind these campaigns as alarming.

While it’s not a huge surprise to see Russia, China, and North Korea as major operators behind targeted ransomware attacks, the sophistication and automation with which these attacks are executed is staggering.

By spinning up fake or non-existent companies, these actors circumvent Western controls. Organizations like RIPE and ARIN are meant to manage IP allocations in Europe and the US.

Or let me rephrase: they should manage IPs. The current level of control is clearly extremely poor.

Infrastructure loopholes make it easy

Heimdal has found evidence in the RIPE database of companies that do not appear in official business registries still owning IP addresses via European-based records.

For example, Razi Network claims an address in Bergnau, Germany, but no such company is found in German commercial databases.

Such discrepancies reveal systemic weaknesses in Know Your Customer (KYC) enforcement by registrars and create frictionless paths for threat actors to scale operations.

Screenshot of RIPE Database search results for Razi Network showing German and US addresses, contact details, and maintenance records, illustrating suspicious or conflicting registration information.

Call for action

I believe the situation could be reversed with decisive action from governments and registry bodies.

This isn’t an unsolvable problem. German and French law enforcement have jurisdiction. RIPE and the UK’s Companies House have the tools.

All that’s missing is the will to connect the dots.

We urge law enforcement and corporate registry authorities to tighten enforcement and verification. These bodies are well-positioned to dismantle fraudulent networks and significantly raise the cost of doing business for cybercriminals.

This article is intended as a wake-up call.

With even modest cooperation across jurisdictions, many of these ransomware networks could be exposed and disrupted before they cause further global economic harm.

Author Profile

linkedin icon

Morten Kjaersgaard is the Founder and Chairman of Heimdal®, a global leader in AI-powered cybersecurity. Under his leadership, Heimdal has grown from a startup in Copenhagen to a trusted security partner for over 16,000 organizations and more than 2,000 MSPs worldwide, defending against 260+ million cyber threats annually. With a sharp focus on unifying cybersecurity operations, Morten is recognized for his ability to align technical innovation with strategic business outcomes. His insights have shaped how organizations and partners alike approach risk reduction, compliance, and security maturity in an increasingly complex digital world. A respected voice in the industry, Morten frequently shares his expertise at international events and through media commentary—championing a more proactive, collaborative, and scalable model for cybersecurity success.