Analyzing the Ransomware Attack on D.C. Metropolitan Police Department by Babuk

Emily Caroscio, Jack Paul, John A. Murray, Suman Bhunia · 2022 IEEE International Systems Conference (SysCon) · 2022

Ransomware attacks are a fast-growing cybercrime that pose a large threat to society. These attacks can result in losing significant amounts of data and money for their victims. Many industries such as aerospace, governmental organizations, etc., have been targeted in the last couple of years. This paper examines the recent attack incidents by one of the famous ransomware groups, Babuk, on the aerospace industry and a police department. It provides an in-depth analysis of the methodology of the attack and examines the impact at a local and global level. A total of 250 gigabytes of data were stolen from one of the victims, the D.C. Metropolitan Police Department. Babuk first had to gain access by infiltrating the system to attack the victims successfully; however, there is no clear evidence on how this was specifically done. Babuk likely gained access by scanning for vulnerable ports in the victim’s system, sending employees a phishing email with a malicious link, or cracking passwords that the victim used for admins in their system. After gaining access, Babuk had to maintain access while stealing and encrypting files. Finally, they demanded ransom from the victims and threatened to post the sensitive data if the ransom was not paid. The attack has impacted not only specific organizations but also public security officials. This paper provides an in-depth analysis of the possible attack methodologies and defense strategies against such ransomware attacks. The defense strategies may include changing government policies, regulating cryptocurrency, and adhering to FBI-listed advice.

Read the paper · More papers on PaperTik