Ransomware Escalates – Darren Williams – BlackFog
BlackFog CEO Darren Williams explains why the pace at which ransomware attacks are being launched continues to escalate.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Darren Williams is the CEO for black fog and we're talking about ransomware. You guys just put together a report that suggests that there's more ransomware and that may not be surprising but it's also disappointing. So why don't we seem to be able to solve this issue what's going on?
Yeah, it's a really good question. In fact, we're just about to publish next week so I can give you a bit of a preview but it looks like we're going to breach break all records in June. So which is a phenomenal because 2022 has been amazing already as you know, but we're just we're in New Territory territory at this point.
I think Mike so it's going to be interesting to see where it goes from here. You never think it's going to keep breaking records, but it does in terms of how did we get here? I think I think the strategies always been if you look back at version one products like antivirus software, you know, when it was just a few hundred viruses that we had to protect against it was relatively easy.
We could fingerprint just like we fingerprint criminals these days when they come and break into your property. I think these version one tactics really don't work effectively against modern cyber security. Everyone has access to machine learning artificial intelligence and they basically train against antivirus software to begin with so we know effectively that about 80% of all of these antivirus products don't really stop the modern ransomware.
So then we fast forward to current generation products version two products. We like to call them. I think these are these will working fairly effectively, you know a few years ago, but again we've moved on and so I think there's now we're looking at a whole new category version three products, which is you know, sort of where we are playing emergent technology where we're looking at different approaches and different tactics.
So instead of looking at the Cyber criminals coming at you all the time, which is what the traditional approach has been. When you consider things like firewalls and modern cyber security software that's sort of their approach. We look at it differently.
We just assume the bad guys going to get into the building and grab your jewels and we watch the back door instead. So we're watching for data leaving the devices and when you actually start thinking about it just by accident. 9% of all cyber attacks.
They have to get data back out because let's think about it an attack is all about getting data off the device. It's all about extorting you for information for money effectively. And so if they can't get data out, they got nothing to extort you with there will be no data breach and no successful attack.
So in essence that sort of how we got there and and what we're trying to do something different and sort of a unique approach to the problem. And those attacks are all so how they double dip right first, they'll encrypt and get you to pay for that meanwhile that I seen and then they'll say but by the way, we're going to put it up on the dark web. So is it right with engaging with these people in negotiating or you kind of damn?
Yeah, you damned if you don't no matter what? I would say probably don't even bother to be honest because there's so many sophisticated business bottle. These cybercriminals are using now it used to be you know, we're back in a year ago.
Everything was being encrypted and breaking your computer. They're sort of moved away from that tactic now and they sort of didn't even bother encrypting. So they really just focus on the extortion capability and making financial gain and you know, some of these cyber criminal organizations are way more sophisticated than I think the media really give people credit for their run like small businesses, but they're Global operations, you know, they're multinational with people in all sorts of places all over the world working together as teams and groups and resale channels and and partnership programs.
And so, you know, I could start a business just attacking people just by going into the dark web joining some of these groups and saying hey Mike, you've got the best technology for extorting people. Can I To use that software and that technology and then put my own spin on it release it as you know, Visa, you know ransomware whatever and then I will give you a percentage of the take that I make from it. So this is how sophisticated they're getting it's it's really fascinating, you know, we study this stuff every day.
So whenever we're always intrigued by the new business models. Even to the extent now we're starting to see new tactics where the gangs are saying. What are the other Revenue channels?
I can actually use well, what about we provide pre-release information about who we're going to attack and provide that to maybe some Financial guys maybe on Wall Street to maybe short some stocks. So I pay you for that information on who you're about to attack I go short the stock and then I basically wait for the attack to happen. So again and another great business model, so it's fascinating to me.
I love love watching what they're doing next. It's hard to say whether that classifies as Insider information or not. But I'm good question.
Okay, good point. Do you think that the other part of this equation is if I paid someone Ransom then just go tell the next guy and now he knows that I'm willing to pay. So by the fact that I'm pain restaurant just make myself a bigger Target.
Anyway, that's one of my big things. Right? So it's like we've all familiar with the problem, you know, you charity giving in shareable donations giving someone Rings you you give the money and all of a sudden your phone never stops ringing because they start sharing it with all their buddies saying hey this guy's a player let's ring him and get some money out of him.
It's no different to ransomware. I think once you get on that list It's Not Unusual that we typically see and you know confidentially we have clients that have been in this situation where they will be attacked two three four times. Because they've already paid up once so it's a bit of a problem.
How do you think the relationship between cybersecurity teams and it people as evolved as a result of this? I think we've been talking about trying to close the loop between data protection and security for decades. But do you think we're finally getting forced down that path?
I mean, is there some goodness coming out of all this? And I think the goodness is the meteor attention that's paid to this area is good because it's making people aware. That's not a matter of you know, if you'll be attacked, but when you'll be attacked, I mean you can see the increase in the amount of cyber insurance policies that are being taken out.
But the problem with that approach is you know, while cyber security Insurance just like you take up building insurance for fire protection you seem to do the same for cyber insurance, but the trouble is we're seeing the insurance carriers saying These rates are going to go up because they're being yeah paying out so much they're saying okay now we need to start all over again and say we will only protect you if you do x y z and most of them as mandating some sort of cyber security tools that have been in place to help protect them. So yes, I think it's good news that there's an awareness. I think we are getting more sophisticated in how we approach the problem governments are now being engaged in in a much more serious way than they've ever been providing, you know notifications to small business things to look out for and to be aware of so, it's still cat and mouse though, you know it as we get more sophisticated I was talking to somebody the other day.
And a lot of companies will say yeah, but we've already got two or three tools. Why do we need your tool as well? Well, it's sort of like saying, you know, why do we keep in investing in new technology for for Warfare?
Generally if we were focused on we've we did if you thought muskets were the biggest, you know, best tool that we ever had we would never have invested any more Technologies. The problem is that the the people that you're attacking also get more sophisticated. They learn how to actually combat your new tools and then they come up with countermeasures.
So then you've got a you know, it's one up everyone's one up them. So that's why you have to keep investing in newer and better technology. So are we ultimately engaged in some sort of permanent arms race then with these other folks who are The Bad actors, they keep investing in Automation and new platforms and new capabilities and then we have to respond.
And is that the cycle we're on forever? I don't know if it's forever. But excuse me.
It's certainly a cycle that we're on right now. And I think there's things that we can do as as a government. Generally that can help mitigate some of these responses to there are you know, why is it if we can stop the money flow then it's going to be less of an issue for cybersecurity gangs because if they can't get paid, what are they doing it for so, you know where you know, like they do with drug trafficking and and they they follow the money trial.
It's very similar. So, you know cryptocurrencies a great topic at the moment given the increase in Awareness in that in the media and the advertising that we're saying but cryptocurrency's part of the problem too. So unless we can actually combat the money flow and an anonymous payments to these, you know cyber gangs.
I think it's going to be like you're saying constant arms race. Seniors suggesting that me beyond the technology there's a whole financial aspect of this thing involving, you know Bitcoins and all this currency and how these people get paid and if we can figure out some way to make it not possible for then the monetize this is that where we're going is that the other half of this equation. Yeah, I think so if you wish we really want to stop the constant arms race.
I think that's the inevitable way that we're gonna have to do it. But you know, it's difficult because cryptocurrency by Design is a non-regulated environment and has no control by any centralized government part of its blessing and curse. So, you know, I think like any great technology which it is a great technology.
I think there's you know people that will abuse it and and people will use a legitimately but you know, is that because it's maturing now at will mature to that level where we'll be a viable alternative and we can maybe mitigate some of the problems associated with Of the nefarious elements. We're seeing There Was You Know cyber gangs? It's interesting.
There may be one day machine learning algorithms. And AI in general will save us from ourselves here because it seems like we're just making it too easy right now. Yeah, saving is from ourselves.
I don't know. I mean it's it's a great technology. I don't know that it's in a Panacea for everything.
I mean machine learning has its own problems. I mean, we're all familiar with some of the the algorithms that have been developed. I don't know if you read about the one I think it was a Stanford study or there was some University that came out with some training algorithm based on machine learning where they were actually detecting malignant melanoma versus non-milling that melanomas and they trained it with millions of samples and it worked a hundred percent perfectly when they were training it, but when they put it into a real situation it ended up working out that it was no better than guesswork in terms of detecting it and when they went back over the raw data source and tried to understand why that would be it turned out when they were actually taking the samples for the the scans the ones with malignant.
Melanoma had a ruler next to To measure it in the other ones didn't so actually what it was measuring was the presence or absence of a ruler. So so these are the things we're going to be very careful when we use these Technologies to understand their limitations as well. They can be used for good if they use correctly.
So what's your best advice to folks? I mean other than visiting your website obviously, but you know, what is it you wish more folks would do to kind of combat this thread or be smarter about it. What's the thing that we're missing?
I think we're always missing the stuff. We can't see and the focus we have is obviously a data leaking. com you pull down our website what people don't see is what's going back the other way.
So when you pull down that website, it's instrumenting the entire page with lots of little widgets all over it. And then those widgets actually have callbacks so you not only get to the news but you're getting all this other code which often injects payloads onto the device and then they call back and you know, one of the widgets might be your political affiliation one might be male or female one might be you know, any other particular things you've been shopping for over the Internet. Well, we've all experienced that so they all collect individual pieces of information.
Not one of them actually has enough data to actually breach any regulation. But what they do do is they'll send the date. At the cloud and then they'll share it up there and then they consolidate that information back into one profile on you and then they sell that information.
So I think the problem is that we never see the data going back the other way. So we ignore it. Everyone watches it coming at you not leaving you so that's what I would say for people to be quite conscious of when they're consuming stuff.
It's more than you think there is happening. All right, folks. You heard it here first.
There's a lot you can do on your own to protect your environments, but one thing for sure the bad guys aren't going away anytime soon, Darian. Thanks for being on the show. No problems, pleasure.
Thanks very much, Mike. Bye all right back to you guys in the studio.