The First Decade of Corporate Ransomware

RSA Conference 2024 · South Stage Keynote

Overview

Mikko Hyppönen, Chief Research Officer at WithSecure, delivers a compelling retrospective on the evolution of ransomware, tracing its origins from obscure MS-DOS viruses to the sophisticated, financially driven corporate threats prevalent today. This talk, titled "The First Decade of Corporate Ransomware," provides a historical journey, highlighting key technological shifts, criminal innovations, and the pivotal moments that transformed ransomware into a global cybersecurity crisis. Hyppönen's presentation is not merely a chronicle of attacks but an analytical exploration of the underlying economic, social, and technological factors that have fueled its growth and persistence.

Watch on YouTube

Visual summary for The First Decade of Corporate Ransomware
Visual summary for The First Decade of Corporate Ransomware

Key moments

  1. 0:00 Speaker's introduction and early virus research
  2. 2:00 The world's first ransom Trojan (1989 AIDS Trojan)
  3. 3:45 Strong encryption's role in enabling ransomware
  4. 4:28 Early 'police Trojans' like Reveton
  5. 5:30 Cryptolocker: The first cryptocurrency ransomware
  6. 7:00 Early ransomware targeted home users and photos
  7. 8:00 Popcorn ransomware's unique 'infect others to pay' method

The First Decade of Corporate Ransomware

Speakers: Mikko Hyppönen, Chief Research Officer, WithSecure

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=Ap8gWBNQ24g

Overview

Mikko Hyppönen, Chief Research Officer at WithSecure, delivers a compelling retrospective on the evolution of ransomware, tracing its origins from obscure MS-DOS viruses to the sophisticated, financially driven corporate threats prevalent today. This talk, titled "The First Decade of Corporate Ransomware," provides a historical journey, highlighting key technological shifts, criminal innovations, and the pivotal moments that transformed ransomware into a global cybersecurity crisis. Hyppönen's presentation is not merely a chronicle of attacks but an analytical exploration of the underlying economic, social, and technological factors that have fueled its growth and persistence.

The article delves into how innovations like strong encryption and cryptocurrencies, while beneficial in many contexts, inadvertently empowered cybercriminals, enabling them to execute more effective and lucrative ransomware campaigns. It meticulously details the progression from targeting individual consumers for small ransoms to orchestrating complex attacks against large enterprises, culminating in the rise of "cybercrime unicorns" – highly organized, wealthy, and brand-conscious criminal enterprises. Hyppönen underscores the critical implications for both defenders and policymakers, emphasizing that understanding this decade-long evolution is essential for formulating robust future defense strategies against a threat that shows no signs of abating.

Background

▶ Watch: Speaker's introduction and early virus research (0:00)

The concept of ransomware, though seemingly modern, has roots stretching back further than many realize. Mikko Hyppönen begins by recounting his early career in 1991, reverse engineering MS-DOS viruses, many of which originated from Russia. Among these early digital threats, one stands out as a precursor to modern ransomware: the AIDS Information Trojan from 1989. This antiquated malware, distributed via floppy disks to participants of an HIV research conference, was the world's first documented ransom Trojan. It operated by encrypting the victim's hard drive after 90 system reboots and then displaying a ransom note demanding payment, a mechanism strikingly similar to contemporary ransomware. This early example underscores a fundamental truth: powerful encryption, while a cornerstone of digital security and privacy, can also be weaponized to lock users out of their own data.

After a long hiatus, ransomware re-emerged in a more recognizable form around 2012-2013 with the advent of police Trojans like Reveton. These threats would infect systems, often via Flash exploits through web browsing, and then lock the computer, falsely claiming it was seized by law enforcement due to illegal activities (e.g., pirated content). Victims were then instructed to pay a "fine." While widespread, these early police Trojans faced a significant hurdle: inefficient payment mechanisms, often relying on virtual credit cards or prepaid systems that were relatively easy to trace. The landscape irrevocably changed in 2013 with Cryptolocker, the first ransomware to leverage cryptocurrencies, primarily Bitcoin, for ransom payments. This innovation provided criminals with an anonymous and untraceable payment rail, akin to "cash online," which was a game-changer for the ransomware economy. Cryptolocker was initially distributed through the existing Zeus botnet, controlled by Russian cybercriminal Jevgeni Bogachev, before quickly spreading via email attachments. Its success spawned numerous copycats, including Cryptowall, CTP Locker, Zero Locker, and Lucky, all targeting individual consumers and their personal files like photos and emails, typically demanding around $200. The infamous Popcorn ransomware even introduced a novel distribution method, offering victims free decryption if they successfully infected two other users. The shift from consumer-focused attacks to the more lucrative corporate targets began around the time of the early Petya ransomware, which overwrote the Master Boot Record (MBR) to prevent system boot, signaling the potential for greater disruption and higher financial gains. This evolution laid the groundwork for the "age of the cybercrime unicorn," where ransomware gangs began to amass significant wealth and organizational power.

Key Findings

▶ Watch: Strong encryption's role in enabling ransomware (3:45)

Hyppönen's talk highlights several critical findings that define the modern ransomware landscape:

Firstly, the emergence of ransomware gangs as "cybercrime unicorns." These groups, if legitimate companies, would be valued in the billions due to their immense revenue and profit. Their wealth accumulation is significantly aided by cryptocurrencies; unlike normal investors, criminals tend to hold onto their Bitcoin and other digital assets, benefiting immensely from market appreciation over the years. Furthermore, operating outside the law, these gangs don't pay taxes, further amplifying their net wealth. This financial power enables them to invest in sophisticated tools, talent, and infrastructure, making them formidable adversaries.

Secondly, the strategic importance of branding for ransomware gangs. Groups like Lockbit, Alpha (BlackCat), Clop, Akira, Black Basta, Play, and Quantum actively cultivate distinct brands, complete with names, logos, and dedicated leak sites. This branding serves a dual purpose: it instills fear and urgency in victims, knowing they've been hit by a "serious" and "reputable" gang, but it also establishes a perverse sense of trustworthiness. As Hyppönen notes, victims know that if they pay, these branded gangs will typically deliver on their promise of decryption or not leaking data, as failing to do so would destroy their crucial reputation for reliability. This "honest" criminal enterprise model is essential for their continued success.

Thirdly, the talk identifies WannaCry (May 2017) and NotPetya (June 2017) as major outliers that profoundly impacted the ransomware industry. WannaCry was unique as a worm, leveraging the EternalBlue SMB exploit (stolen from the NSA) to spread rapidly across networks, infecting hundreds of thousands of computers in 150 countries within hours. Its origin was particularly striking: the North Korean government, which used it as a crude attempt to generate revenue to offset budget deficits. However, WannaCry was a financial failure due to its lack of a proper payment and communication mechanism. NotPetya, appearing just six weeks later, was a far more destructive event. Masquerading as ransomware, it was, in fact, a cyber weapon deployed by the Russian GRU (military intelligence) against Ukraine, disguised to look like the earlier Petya. NotPetya didn't encrypt files but wiped them, rendering recovery impossible, despite presenting a ransom note. Its distribution via a supply chain attack through Ukrainian accounting software M.E.Doc led to massive global disruption, famously crippling companies like Maersk.

These two events, where paying the ransom yielded no results, directly undermined the "paying works" narrative that legitimate ransomware gangs meticulously built, highlighting the dangers of state-sponsored cyberattacks masquerading as criminal endeavors. They forced a re-evaluation of ransomware's nature and the motivations behind its deployment.

Technical Deep Dive

▶ Watch: Early 'police Trojans' like Reveton (4:28)

The technical evolution of ransomware, as detailed by Hyppönen, showcases a progression from rudimentary file manipulation to sophisticated network-wide encryption and data destruction.

The AIDS Information Trojan (1989), the first known ransomware, operated on MS-DOS. Its mechanism was relatively simple but effective for its time: after 90 system reboots, it would encrypt the victim's hard drive, making data inaccessible, and then display a ransom note. This early approach relied on direct file system manipulation rather than network-based propagation.

The police Trojans like Reveton (2012-2013) represented a shift towards exploiting vulnerabilities in common software. These typically used Flash exploits to gain initial access when users browsed compromised websites. Once on a system, Reveton would lock the user interface, preventing normal interaction, and display a full-screen message purporting to be from law enforcement, demanding a "fine." The underlying technical challenge for criminals at this stage was the payment system, which relied on traceable virtual credit cards or prepaid services.

The game-changer was Cryptolocker (2013), which introduced cryptocurrency (Bitcoin) as the preferred payment method. This significantly enhanced attacker anonymity and made tracking funds far more difficult. Cryptolocker was initially distributed through the established Zeus botnet, a sophisticated network of compromised machines, demonstrating how existing cybercrime infrastructure could be repurposed for new threats. It also spread via malicious email attachments, a tactic that remains prevalent today. Cryptolocker's technical innovation lay in its use of strong, asymmetric encryption to lock victim files, combined with a robust, anonymous payment system. Its success led to numerous copycats like Cryptowall, CTP Locker, Zero Locker, and Lucky, which adopted similar encryption and payment models.

Popcorn ransomware showcased a unique social engineering and propagation technique. Beyond encrypting files and demanding a Bitcoin ransom (around $400 at the time), it offered victims an alternative: infect two other individuals via a unique URL. If those new victims paid, the original victim would receive their files back for free. This effectively turned victims into unwitting distributors, leveraging a chain-letter-like mechanism.

The early version of Petya ransomware (pre-2017) demonstrated a more fundamental level of system compromise. Instead of just encrypting user files, it would overwrite the Master Boot Record (MBR) of Windows computers. This prevented the operating system from booting altogether, displaying the ransom note directly from the MBR before the OS could even load. This deep system compromise made recovery particularly challenging.

The WannaCry (2017) outbreak was a watershed moment due to its worm-like propagation and the use of a powerful exploit. It leveraged EternalBlue, an SMB exploit developed by the NSA and later leaked, to spread rapidly across vulnerable Windows networks. WannaCry would scan for open SMB ports, exploit the vulnerability, and then execute its ransomware payload, encrypting files and changing the system wallpaper. Its ability to self-propagate made it incredibly effective in infecting approximately 300,000 computers in 150 countries within hours. Technically, its flaw was in its command-and-control (C2) and payment system: it used a hardcoded kill switch domain and lacked a robust mechanism for victims to communicate with the attackers to retrieve decryption keys, leading to its financial failure.

Just six weeks later, NotPetya (2017) emerged, a far more destructive "cyber weapon" masquerading as ransomware. While it presented a ransom note identical to Petya, its underlying functionality was entirely different. Instead of encrypting files, NotPetya was designed to wipe them irrevocably. It rebooted systems and displayed a fake check disk display while actively destroying data. Its primary infection vector was a supply chain attack through M.E.Doc, a popular Ukrainian accounting software. Attackers compromised M.E.Doc's update mechanism to push the NotPetya malware to its users. From Ukrainian offices, it then spread laterally to global corporate networks, exploiting vulnerabilities similar to WannaCry, leading to catastrophic outages for multinational corporations like Maersk, which lost network visibility in just 15 minutes.

The general attack logic for almost all modern corporate ransomware campaigns follows a consistent pattern:

  1. Initial Access: Achieved through stolen credentials, phishing, or remote exploits.
  2. Persistence: Attackers establish footholds to maintain access even if detected.
  3. Privilege Escalation: Gaining higher-level access to critical systems.
  4. Lateral Movement & Reconnaissance: Exploring the network to identify valuable data and critical infrastructure, especially backup systems.
  5. Data Exfiltration: Stealing sensitive data for double extortion.
  6. Backup Destruction: Deleting or encrypting backups to prevent recovery without paying.
  7. Encryption: Encrypting files across the network, rendering systems inoperable.

This multi-stage approach, combining initial compromise with internal network traversal and destruction of recovery options, defines the technical sophistication of modern corporate ransomware attacks.

Demo / Proof of Concept

▶ Watch: Early ransomware targeted home users and photos (7:00)

While Mikko Hyppönen's talk is primarily a historical and analytical overview, it does touch upon the tangible reality of early ransomware. Hyppönen mentioned having a physical copy of the AIDS Information Trojan on a floppy disk, remarking, "I actually have a copy of this one with me right here." This serves as a powerful, albeit implicit, "proof of concept" by demonstrating the historical authenticity and physical artifact of the world's first ransomware. The talk did not feature a live, technical demonstration of ransomware infection or decryption processes, focusing instead on the conceptual and historical aspects of these attacks.

Defensive Implications

▶ Watch: Popcorn ransomware's unique 'infect others to pay' method (8:00)

The detailed history and analysis of ransomware provide crucial insights for organizations seeking to bolster their defenses. Hyppönen emphasizes that no organization can "hide" from this threat; even those who consider themselves uninteresting targets are vulnerable. Therefore, proactive and comprehensive security measures are paramount.

Firstly, robust patching and updating are non-negotiable. Many ransomware attacks, particularly those with worm-like capabilities like WannaCry, exploit known vulnerabilities for which patches are available. A disciplined patching regimen significantly reduces the attack surface.

Secondly, multi-factor authentication (MFA) everywhere is critical. Stolen credentials are a primary initial access vector for ransomware gangs. Implementing MFA across all systems, especially for remote access, privileged accounts, and cloud services, dramatically increases the difficulty for attackers to leverage compromised credentials.

Thirdly, organizations must not merely have backups, but test their recovery process rigorously and regularly. Hyppönen highlights that backups are useless if they take a month to recover. Organizations need to know exactly how long it takes to restore critical systems and data from backups and ensure these recovery times align with business continuity requirements. This includes testing offline or immutable backups that cannot be accessed or encrypted by attackers during a live incident.

Fourthly, a strategic consideration for endpoint security involves re-evaluating computing platforms. Hyppönen notes instances where companies, post-ransomware, have shifted from Windows laptops to Chromebooks or iPad Pros for many end-users. These platforms, with their inherently different architectures and security models, are "pretty hard to infect with ransomware" compared to traditional desktop operating systems, offering a layer of resilience for appropriate use cases.

Fifthly, network visibility is indispensable. "You cannot manage what you can't measure," Hyppönen states. Organizations need comprehensive logging, monitoring, and detection capabilities across their networks to identify suspicious activities, lateral movement, and potential compromise indicators early. This includes endpoint detection and response (EDR) and network detection and response (NDR) solutions.

Finally, and perhaps most importantly, organizations must prepare for the human element of a crisis. Hyppönen recounts the shock experienced by Maersk's CISO during the NotPetya attack, emphasizing the difficulty of making rational decisions under extreme pressure. He strongly advocates for tabletop exercises and incident response rehearsals. These simulations help teams understand what it feels like to operate "blind" – without access to email, internal systems, or even phone lists – and to work effectively while in a state of shock. Such preparation builds resilience and muscle memory, enabling a more effective response when an actual incident occurs. The overarching message is one of resilience: victims of crime can rebuild and recover, provided they have invested in the right preparatory measures.

Key Takeaways

  • Ransomware's Deep Roots & Rapid Evolution: The concept of ransomware dates back to 1989, but it rapidly evolved from consumer-focused threats to sophisticated corporate attacks due to technological advancements.
  • Cryptocurrency as an Enabler: The introduction of cryptocurrencies, particularly Bitcoin, in 2013 by Cryptolocker revolutionized ransomware by providing anonymous and untraceable payment mechanisms, fueling its economic model.
  • Ransomware Gangs as "Cybercrime Unicorns": Modern ransomware groups operate as highly organized, wealthy, and brand-conscious entities, accumulating vast sums of money through tax-free profits and strategic cryptocurrency holdings.
  • State-Sponsored Cyber Weapons Masquerading as Ransomware: Events like WannaCry (North Korea) and NotPetya (Russian GRU) demonstrated that nation-states use ransomware for profit or as destructive cyber weapons, blurring the lines between cybercrime and cyber warfare and undermining the "paying works" promise.
  • Comprehensive Defense is Essential: Effective defense requires a multi-layered approach including rigorous patching, universal multi-factor authentication, regularly tested and resilient backups, enhanced network visibility, and strategic consideration of endpoint platforms.
  • Preparation for Crisis is Paramount: Organizations must conduct tabletop exercises and incident response rehearsals to prepare for the psychological and operational shock of a major attack, ensuring teams can function effectively even when operating blind.

About the Speaker(s)

Mikko Hyppönen is the Chief Research Officer at WithSecure, a leading cybersecurity company. He is a globally recognized expert in cybersecurity, with a career spanning over three decades. Hyppönen began his journey in the field in 1991, focusing on reverse engineering early viruses that spread under MS-DOS, many of which originated from Russia, a region he is intimately familiar with, living just two hours from its border. His extensive experience studying the evolution of malware, from basic floppy-based viruses to complex modern threats, has provided him with a unique perspective on the long-term trends and challenges in cybersecurity. He is known for his ability to translate complex technical issues into understandable narratives, making him a respected voice at conferences worldwide.

All talks from RSA Conference 2024