How AI Can Stop Zero-Day Ransomware

Over the past year, the sheer number of ransomware attacks have increased dramatically, with organizations of all stripes being affected: government entities, educational institutions, healthcare facilities, retailers, and even agricultural groups.
While the bulk of the media attention has been on critical infrastructure and large organizations, attackers are not limiting themselves to just those types of victims.
“That’s really just the tip of the iceberg,” says Max Heinemeyer, director of threat hunting at Darktrace. “We see not just big names being hit. It’s basically any company where adversaries think they can pay the ransom. Anybody who’s got money and running some kind of digital business is basically in the crosshairs.”
What’s even more concerning – more than the fact that pretty much any organization can be targeted – is that ransomware attacks are evolving rapidly to add new capabilities. Where past attacks involved one – or a handful – of compromised machines, attacks now take down whole networks. Where the malware focused on just encrypting files and making them inaccessible, now the malware exfiltrates the data outside the network. Gangs now threaten secondary attacks on top of the initial infection, such as launching denial-of-service attacks or dumping the files in public. The latter action would expose the organization to a whole other set of problems associated with the data breach.
Ever-Evolving ThreatsThere is a tendency to assume that ransomware gangs always follow a set script when designing their attacks. However, the “professionalization” of the ransomware landscape means these attackers have their own supply chain to work with.
“They have specialized penetration operators to hack into systems, they buy access to networks, and they have negotiators to discuss ransoms,” Heinemeyer says.
Ransomware gangs don’t always use phishing, exploit zero-days, or abuse supply chains, either, he adds.
“They go with whatever their hackers bring on board,” Heinemeyer says. “If [hackers] want to use Cobalt Strike, they use Cobalt Strike. Or they can use their own malware. If they prefer domain fluxing, they use domain fluxing. If they are very adept at social engineering, they’re going to use that. If they buy access on the Dark Web, such as access cookies or pr-compromised systems, they can use that.”
While random and opportunistic attacks still exist, these gangs are increasingly researching the targets beforehand to find the suitable attack method.
“You think, ‘Oh, my God, that’s 1995-style, but it still works because there’s so many companies out there that are vulnerable. They have open infrastructure, or they run on edge systems,” Heinemeyer says. But the gangs don’t have to stick with just one attack method. They are taking the time to understand the networks they are targeting and can swap out tools as needed.
The industry tends to predefine the threat — “Mimikatz is the latest rage, or this version of Cobalt Strike” — and focus the solutions on those elements, Heinemeyer says.
“You don’t want to have your domain controller have an open RDP port without any brute-force protection now. And you don’t want to have an unpatched Exchange server that didn’t get patched,” he explains. “But for most organizations, there is the problem of what to do next: Should I create more security awareness campaigns because phishing is the latest thing? Should I increase my patch cycles or get more threat intelligence?”
Heinemeyer cautions against relying too much on defining what the attack would look like. Defenders focusing only on techniques, tools, and procedures (TTPs) and indicators of compromise (IoCs) are likely to see only legacy ransomware and attacks that are utilizing already-known methods.
“There’s no longer any common modus operandi anymore,” he says. “We [the industry] try to extrapolate tomorrow’s attack from yesterday’s attacks: Let’s look at yesterday’s threat intelligence.


