-

McAfee Enterprise Sees Proliferation of REvil and DarkSide Ransomware Surge in Q2 2021

Key Findings

  • In Q2 2021, 73% of ransomware detections in Q2 2021 were related to the REvil/Sodinokibi family
  • DarkSide Q2 ransomware attacks extended beyond Oil, Gas and Chemical sector to Legal Services, Wholesale and Manufacturing
  • Government was the sector most targeted by ransomware
  • Financial Services targeted most among reported cloud incidents

SAN JOSE, Calif.--(BUSINESS WIRE)--McAfee Enterprise today released its Advanced Threat Research Report: October 2021, examining cybercriminal activity related to ransomware and cloud threats in the second quarter of 2021. With the shift to a more flexible pandemic workforce and the highly publicized Colonial Pipeline attack, cyber criminals introduced new – and updated – threats and tactics in campaigns targeting prominent sectors, such as Government, Financial Services and Entertainment.

“Ransomware has evolved far beyond its origins, and cybercriminals have become smarter and quicker to pivot their tactics alongside a whole host of new bad-actor schemes,” said Raj Samani, McAfee Enterprise fellow and chief scientist. “Names such as REvil, Ryuk, Babuk, and DarkSide have permeated into public consciousness, linked to disruptions of critical services worldwide. And with good measure, since the cybercriminals behind these groups, as well as others, have been successful at extorting millions of dollars for their personal gain.”

Each quarter, McAfee assesses the state of the cyber threat landscape based on in-depth research, investigative analysis, and threat data gathered by the McAfee Global Threat Intelligence cloud from over a billion sensors across multiple threat vectors around the world.

Ransomware Increases Dominance with Colonial Pipeline Impact

The second quarter of 2021 was a vibrant quarter for ransomware, earning its place as a high-profile cyber agenda item for the U.S. administration following the Colonial Pipeline attack. The impact of the abrupt halt in the supply chain affected much of eastern U.S., creating a frantic consumer run on fuel. Beyond the supply chain impact, ransomware expelled from the historically safe cybercriminal underground forums. The political response to the Colonial Pipeline attack saw two of the most influential underground forums- XSS and Exploit- announce a ban on ransomware advertisements. It also appeared to cause the DarkSide ransomware group to abruptly halt its operations, though McAfee Enterprise strongly believes its silence, at the same time the BlackMatter group appeared, is more than coincidental, especially as it mirrors the same move made before and after REvil’s period of silence. Despite these notable shifts in behavior, McAfee Enterprise’s global threat network identified a surge in DarkSide attacks from the group upon legal services, wholesale, and manufacturing targets in the United States.

Equally concerning to DarkSide’s activity were other ransomware groups operating similar affiliate models, including Ryuk, REvil, Babuk, and Cuba. They deployed business models supporting others involvement to exploit common entry vectors and similar looks to move within an environment. In fact, REvil/Sodinokibi topped our ransomware detections in Q2 of 2021, accounting for 73% of our top-10 ransomware detections.

COVID-19 Impact on Workforce Continues to Increase Cloud Threats

In the second quarter of 2021, we continued to see the challenges of shifting cloud security to accommodate a more flexible pandemic workforce and an increased workload, which presented cybercriminals more potential exploits and targets.

According to McAfee Enterprise Advanced Threat research, in Q2 2021, the following cloud threat incidents and targets ranked high among the top 10 reporting countries (United States, India, Australia, Canada, Brazil, Japan, Mexico, Great Britain, Singapore and Germany):

  • Financial Services were targeted the most among reported cloud incidents, followed by Healthcare, Manufacturing, Retail, and Professional Services.
  • Financial Services were targeted in 50% of the top 10 cloud incidents, including incidents in the United States, Singapore, China, France, Canada, and Australia.
  • Cloud incidents targeting verticals in the United States accounted for 34% of incidents recorded, with a 19% decrease in Great Britain
  • The most cloud incidents targeting countries were reported in the United States followed by India, Australia, Canada, and Brazil.
  • Cloud incidents targeting the United States accounted for 52% of incidents recorded.

Q2 2021 Threat Activity

Ransomware Focus. The most targeted sector by ransomware in Q2 of 2021 was Government, followed by Telecom, Energy, and Media & Communications.

Attack vectors. In Q2 2021, malware was the technique used most often in reported incidents. Spam showed the highest increase of reported incidents – 250% -- from Q1 to Q2 2021, followed by Malicious Script with 125% and Malware with 47%.

Sector Activity. McAfee Enterprise tracked a 64% increase in publicly reported cyber incidents targeting the Public sector during the second quarter of 2021, followed by the Entertainment sector with a 60% increase. Notably, Information/Communication had a 50% decrease in Q2 2011, with Manufacturing down 26%.

Regions. These incidents surged in primarily in the Unities States and Europe in Q2 2021. The United States experienced the most reported incidents in the second quarter, and Europe saw the largest increases in reported incidents in Q2 with 52%.

Resources:

About McAfee Enterprise Advanced Threat Research

McAfee Enterprise Advanced Threat Research are a leading source for threat research, and threat intelligence. With data from over a billion sensors across key threats vectors—file, web, message, and network—McAfee Enterprise Advanced Threat Research delivers real-time threat intelligence, critical analysis, and expert thinking to improve protection and reduce risks.

About McAfee Enterprise

McAfee Enterprise is a pure play enterprise cybersecurity company. Positioned to solve enterprise customers’ changing security needs with a world-class solution leading portfolio, McAfee Enterprise delivers on the needs of modern businesses, organizations and governments around the world. For more information, please visit www.mcafee.com/enterprise

McAfee Enterprise’s technology features and benefits depend on system configuration and may require enabled hardware, software, or service activation. No computer system can be absolutely secure.

Contacts

McAfee Enterprise
Ashley Dolezal
media@mcafee.com

McAfee Enterprise


Release Versions

Contacts

McAfee Enterprise
Ashley Dolezal
media@mcafee.com

More News From McAfee Enterprise

Skyhigh Security Named a Leader by Independent Research Firm in Cloud Workload Security

SAN JOSE, Calif.--(BUSINESS WIRE)--Skyhigh Security, formerly McAfee Enterprise, today announced that its Skyhigh Cloud Native Application Protection Platform (CNAPP) has been named a leader in the Forrester Research, Inc. report, The Forrester Wave™: Cloud Workload Security, Q1 2022. The report evaluated 12 providers based on 33 criteria, conducting a detailed technical evaluation as well as in-depth analysis. In the assessment, Skyhigh Security was listed as one of the only two leaders, recei...

Cyber Threats Have Increased 81% Since Global Pandemic

SAN JOSE, Calif.--(BUSINESS WIRE)--McAfee Enterprise and FireEye today released Cybercrime in a Pandemic World: The Impact of COVID-19 findings, revealing the imminent need for organizations to prioritize and strengthen their cybersecurity architecture. The findings indicate that during the pandemic, 81% of global organizations experienced increased cyber threats with 79% experiencing downtime due to a cyber incident during a peak season. As the holiday season approaches, supply chain and logis...

 A Look Ahead to 2022: McAfee Enterprise & FireEye Predict Top Cyber Threats

SAN JOSE, Calif.--(BUSINESS WIRE)--McAfee Enterprise and FireEye today released its 2022 Threat Predictions, examining the top cybersecurity threats they predict enterprises will face in 2022. Bad actors have taken note of successful tactics from 2021, including those making headlines tied to ransomware, nation states, social media and the shifting reliance on a remote workforce. We expect them to pivot those into next years’ campaigns and grow in sophistication, wielding the potential to wreak...
Back to Newsroom