{"id":10239,"date":"2025-12-29T17:33:15","date_gmt":"2025-12-29T17:33:15","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=10239"},"modified":"2025-12-29T17:33:15","modified_gmt":"2025-12-29T17:33:15","slug":"fame-is-foreign-money-even-within-the-ransomware-economic-system","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=10239","title":{"rendered":"Fame is foreign money \u2013 even within the ransomware economic system"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">Being seen as dependable is nice for \u2018enterprise\u2019 and ransomware teams care about &#8216;model status&#8217; simply as a lot as their victims<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/tony-anscombe\/\" title=\"Tony Anscombe\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2017\/05\/MFE_5108-BW.png\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2017\/05\/MFE_5108-BW.png\" alt=\"Tony Anscombe\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>11 Dec 2025<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>4 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2025\/12-25\/ransomware-raas-reputation.jpg\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2025\/12-25\/ransomware-raas-reputation.jpg\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2025\/12-25\/ransomware-raas-reputation.jpg\" alt=\"Black Hat Europe 2025: Reputation matters \u2013 even in the ransomware economy\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p>Black Hat Europe 2025 opened with a presentation by Max Smeets of Digital Rotes titled \u2018<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blackhat.com\/eu-25\/briefings\/schedule\/index.html#keynote-inside-the-ransomware-machine-50319\" target=\"_blank\" rel=\"noopener\">Contained in the Ransomware Machine\u2019<\/a>. The discuss centered on the LockBit ransomware-as-a-service (RaaS) gang and Max\u2019s analysis into their practices and operations. At their peak, between 2022-2024, the group had 194 associates, of which 110 had managed to get a cyberattack to the purpose of negotiation, with 80 of the associates succeeding in getting paid by the ransomware group. (As a reminder, the enterprise mannequin of ransomware is layered: \u2018affiliate\u2019 refers back to the crew that researches the sufferer\u2019s networks and identifies and exfiltrates the delicate knowledge to a ransomware gang, akin to LockBit.)<\/p>\n<h2>Fame is all the pieces<\/h2>\n<p>A key message delivered by Max was concerning status, each of the sufferer and the ransomware group. The sufferer firm must uphold their status with their prospects and any trace of an information breach can considerably harm it. Apparently, the analysis confirmed that media protection is bigger for the businesses that pay as opposed to people who don\u2019t pay the extortion demand and face longer disruption. The presenter\u2019s view is that the information story turns into concerning the fee and probably provides the indication the sufferer firm has misplaced management and wanted to pay, producing mistrust and harm to their model.<\/p>\n<p>As somebody who has been near the topic for a number of years, I disagree with this view, not less than in some circumstances. From a purely monetary perspective, paying the demand may very well be the cheaper resolution, and there are a lot of examples the place the ultimate prices of a cyber-incident for people who don\u2019t pay are a number of instances larger than people who do pay \u2013 simply suppose again to the assaults on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.risk-strategies.com\/blog\/understanding-mgm-and-caesars-cyberattacks-lessons-learned\" target=\"_blank\" rel=\"noopener\">Caesers Palace and MGM<\/a>. Firms have a duty to shareholders and in some circumstances the only and quickest methodology to get well the enterprise and develop into totally operational could also be to pay the ransomware extortion demand.<\/p>\n<p>In the meantime, restoration of programs will be advanced, new {hardware} must be acquired, and backups have to be restored and analyzed to make sure they&#8217;re clear. The ransomware decryption key unlocking the enterprise in hours reasonably than days can reduce enterprise disruption and lack of income. Then additionally issue within the affect of an insurance coverage underwriter, who too will wish to reduce their prices and take the trail that minimizes any declare that could be made by the sufferer firm.<\/p>\n<p>After all, each quick and long-term downsides are simply as apparent. The fee might purchase time and lower the invoice \u2013 till it does not. For starters, there isn&#8217;t any assure that the decryption key will truly unlock the info. As well as, the victims that conform to ransom calls for could also be seen by attackers as price focusing on once more and, finally, they could additionally inadvertently validate and reinforce ransomware as a viable \u2018enterprise mannequin\u2019.<\/p>\n<p>The ransomware operators are additionally involved about status \u2013 they have to be seen as reliable and to be recognized for upholding their finish of any deal. When large quantities of delicate knowledge is exfiltrated and held to ransom, in addition to inner programs encrypted and acquired to a standstill, any negotiation to unlock programs and make sure the safety of the info must be from a belief standpoint.<\/p>\n<p>If the negotiator has heard unfavourable evaluations on the ransomware group not offering decryptors or holding onto knowledge, they could advise the sufferer to not pay. It\u2019s vital that when handing over the extortion fee the ransomware group delivers precisely as anticipated, offering the service they&#8217;re being paid for in an expert method. The true problem for any ransomware group will not be that of community entry or the exfiltration of information however reasonably whether or not the sufferer trusts them sufficient to pay the extortion demand.<\/p>\n<p>Apparently, the operations by regulation enforcement to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/law-enforcement-disrupt-worlds-biggest-ransomware-operation\" target=\"_blank\" rel=\"noopener\">take down LockBit<\/a> in 2024 additionally included a marketing campaign to destroy belief within the gang, publicly stating that the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/therecord.media\/lockbit-lied-about-deleting-exfiltrated-data-after-ransom-payments\">gang goes not delete exfiltrated knowledge<\/a> however maintain on to it. This mistrust marketing campaign might be sufficient for associates to take their alternatives and enterprise to a different group.<\/p>\n<h2>What units the worth<\/h2>\n<p>My takeaway from the presentation was not one thing the presenter acknowledged outright \u2013 it\u2019s concerning the knowledge and reconnaissance the affiliate conducts concerning the firm. There was a quick point out of the analysis and shifting round an organization community in search of delicate knowledge, together with monetary knowledge that will point out willingness to pay or an quantity that might be acceptable.<\/p>\n<p>This brought on a lightbulb second: probably the most precious doc to a cybercriminal might be the schedule detailing the corporate\u2019s cyber insurance coverage protection. Understanding whether or not the corporate has insurance coverage that features paying an extortion demand and what the extent of protection is supplies the cybercriminal the knowledge on the place to set the extortion demand, in order that the danger turns into a monetary challenge not for the corporate, however for the insurer.<\/p>\n<p>The takeaway is that the cyber insurance coverage coverage and all communication concerning the coverage needs to be segmented with further safety, or utterly air-gapped from the corporate community.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Being seen as dependable is nice for \u2018enterprise\u2019 and ransomware teams care about &#8216;model status&#8217; simply as a lot as their victims 11 Dec 2025 \u00a0\u2022\u00a0 , 4 min. learn Black Hat Europe 2025 opened with a presentation by Max Smeets of Digital Rotes titled \u2018Contained in the Ransomware Machine\u2019. The discuss centered on the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":10241,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[4301,366,500,2215],"class_list":["post-10239","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-currency","tag-economy","tag-ransomware","tag-reputation"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10239","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10239"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10239\/revisions"}],"predecessor-version":[{"id":10240,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10239\/revisions\/10240"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/10241"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-21 03:42:11 UTC -->