Cyber Extortion Unveiled: The Evolution, Tactics, Challenges, and Future of Ransomware

Salahaldeen Duraibi, Chamandeep Kaur, Aniket B. Pawar · 2023

The adaptability and malicious efficiency of ransomware, a sort of malicious software that encrypts files or restricts system access until a ransom, frequently in the form of cryptocurrency, is delivered to the attacker, is unmatched by other computer dangers. This article covers ransomware's unrelenting evolution, from its historical roots to sophisticated modern varieties that use cutting-edge encryption and the ominous “double extortion” tactic. Attacks with ransomware offer serious risks, including financial hardships, breaches of data privacy, interruptions of vital infrastructure, and psychological effects on victims. The paper explores encryption methods, such as the AES and RSA algorithms, and finds common entry vectors for ransomware, including social engineering, phishing emails, and software weaknesses. It highlights difficulties in ransomware mitigation, including dangers in the supply chain, human weaknesses, resource limitations, ransomware's dynamic nature, encryption and evasion strategies, data exfiltration, and cryptocurrency transactions. Application whitelisting, behavioral analysis, and threat intelligence are all examples of mitigation methods. Response strategies like data backups and incident response plans are examples of mitigation strategies. The efficacy analysis highlights the necessity for a comprehensive strategy by highlighting strengths and shortcomings. The review advocates for interdisciplinary integration to combat the evolving ransomware threat landscape by outlining promising approaches and future research needs, such as multi-modal authentication techniques, resilience-centric security measures, ransomware attribution techniques, and user-centric security designs.

Read the paper · More papers on PaperTik