THE Lab-1 Dark-web Research Team discusses the evolving tactics of ransomware and data-extortion groups, highlighting a shift from bulk data dumps to advanced post-exfiltration analysis techniques. Key points include:
- Ransomware-as-a-Service (RaaS) groups are increasingly analyzing and indexing stolen data to maximize extortion leverage and secondary sale value.
- Three main methodologies for data analysis have been identified: human analysis, AI/ML analysis, and basic scripted extraction, often used in combination.
- The reorganization of stolen data diminishes the effort needed for criminals to exploit it, heightening risks including regulatory issues and reputational damage for victims.
- Data analytics intensifies breach impacts by providing structured inventories for ransom negotiations, increasing the likelihood of data sales, and enhancing risks of secondary abuse.
- Exploitation of hard (e.g., credentials) and soft data pivots (e.g., organizational documents) poses varied risks, with soft pivots often underestimated in their potential for facilitating targeted attacks.