Site navigation

Cheap Virtual Machines Are the Backbone of Modern Ransomware

Tom Quinn

,

ransomware virtual machines
Thousands of ransomware operators are sharing mass-produced virtual machines tied to just a handful of autogenerated Windows hostnames.

Ransomware gangs are renting cheap virtual machines (VMs) to scale their operations, remain anonymous, and keep their nefarious activities running around the clock, according to new research from Sophos.

Following an investigation of WantToCry ransomware incidents, the cyber firm discovered that the same autogenerated Windows hostnames kept popping up across incidents and multiple countries.

Digging deeper revealed that thousands of criminal servers are effectively sharing the same infrastructure, with ransomware “service providers” MasterRDP exploiting legitimate hosting infrastructure to lease VMs to criminals.

The tactic effectively turns ransomware crews into a hydra – even if one server is taken down by law enforcement, hundreds just like it still exist.

Investigating two hostnames used in the WantToCry campaign, Sophos found each one associated with thousands of internet-facing devices, adding up to more than 10,000 live hosts.

While most of the devices using these hostnames were in Russia, others were discovered operating in former satellite states like Kazakhstan and Ukraine, though more were identified across Europe, the US, and even the UK.

Sophos said the use of virtual machines can be traced back at least five years, with the hostnames linked to well‑known ransomware groups, including LockBit, ALPHV, and Qilin.

Notably, the study also linked the top two providers of the VMs used by these gangs back to cybercriminal and Russian state‑sponsored operations, where many of these gangs are based and recruit members.

According to the report, because the malicious hostnames are clustered around only a few providers and geographic regions, it’s likely they’re being deployed from mass‑produced virtual machine templates instead of being set up separately by each attacker.


Recommended reading


This type of distributed infrastructure commonly supports ransomware command and control (C2) servers, malware distribution, phishing campaigns, botnet management, and data exfiltration staging.

“It is highly likely that MasterRDP is one of many bulletproof hosting providers within the cybercriminal ecosystem that lease…virtual machines hosted on abuse-tolerant infrastructure to customers with malicious intentions, including those engaged in ransomware operations and malware delivery,” Sophos analysts concluded.

“Its low cost, low barrier to entry, and turnkey deployment capabilities make it attractive to cybercriminals while its widespread legitimate use provides operational cover among thousands of compliant deployments.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data