Site navigation

Comment | The History of Ransomware

Cian Heasley

,

History of ransomware
In this contributed piece for DIGIT, Cian Heasley, principal consultant, Acumen Cyber, traces the evolution of ransomware from its earliest attacks in the late 1980s to today’s sophisticated extortion models.

While it’s easy to think of ransomware as a constant and fixed threat, looking back at its history shows how much it has evolved since its inception.

From the late eighties to the present day, ransomware threat actors have diversified their tactics, exploiting changes in how organisations use digital technologies and leveraging technological innovation to increase their profits.

However, as much as technology has advanced the threat, the ransomware actors of today are still motivated by the same principles as those carrying out the very first attacks: To make money by holding an organisation and its data to ransom.

The origins of ransomware

There are two events that mark the origin point of ransomware, one in 1989 and one in 2000.

In 1989 tens of thousands of floppy disks were physically mailed from the U.K., to people who had attended a WHO AIDS conference and to subscribers of PC Business World magazine.

The disk itself came with printed instructions informing the recipient that the disk contained an interactive questionnaire that claimed to predict AIDS infection risk.

In reality, installing the questionnaire also installed a computer virus that would make files and directories inaccessible after a set number of system reboots, then victims were met with a demand to pay a “license fee” to a PO Box in Panama.

American biologist Dr. Joseph Louis Popp was eventually arrested for spreading the computer virus, becoming in effect the grandfather of ransomware.

In 2000 a blackmail scheme emerged involving CD Universe, an online music shop, and a stolen database of 300,000 credit cards.

In exchange for a payment of $100,000 the hacker who had stolen the database offered to delete it all.

When CD Universe refused to pay the ransom, the credit card details were posted on a website run by the hacker which he called “Maxus Credit Card Pipeline”. It was estimated that before the website was shut down at least 25,000 people downloaded credit card data necessary to make fraudulent payments.

These two historical computer incidents are early examples of the two primary ways that ransomware gangs still operate to this day, by either holding data to ransom on computers infected by malicious software, or by threatening to release sensitive data online unless a payment is received.

Moving into the teens

It wasn’t until 2013 when encryption based ransomware made its biggest reappearance since 1989, with the emergence of CryptoLocker.

CryptoLocker was spread via phishing emails and the exploitation of drive-by download vulnerabilities in browsers or browser plugins.

By December of 2013 it was estimated that at least 250,000 Windows PCs had been infected, with ransom demands being set at around £300, which was payable with Bitcoin or online payment platform MoneyPak.

Researchers estimated that online gangs pushing ransomware around this time could be making as much as $5 million a year through the extortion of individual victims.

The next major innovation for ransomware came in 2015, with the creation of Encryptor ransomware, one of the first ever so called “Ransomware-as-a-Service” operations.

While other ransomware operations functioned as a gang that created and distributed their malware themselves, Encryptor offered anyone willing to pay between 5% and 20% of their victim’s payments to the people maintaining the Encryptor malware and infrastructure.

People wanting to become Encryptor affiliates could decide on the payment they wanted to demand, a higher cost for late payment, and a deadline for when they wanted the payment to be received by, along with a Bitcoin address for victims to send money to.

The second last revolution in the ransomware business model arrived in 2018, championed by Russian cybercriminal gangs like Evil Corp and Ryuk, a group that were considered so advanced at the time that security researchers originally thought they might be linked directly to the North Korean government.

This brings us to the final evolution of modern ransomware, pioneered by a gang called Maze in 2019.

Maze realised that they could take the two original forms of the ransomware model that we looked at in the beginning of this article and combine them.


Recommended reading


Maze would encrypt data on organisation’s computers but not before they had stolen the data they surmised would be sensitive if leaked. Then they could extort the organisation for the encryption keys to unlock their data but also threaten to leak what they had stolen to inflict reputational, legal or regulatory damage.

This tactic was christened “double extortion” and a lot of the attacks we see today still focus on the method. However, criminals continue to increase their chances of payout by bolstering it with other techniques, such as triple and quadruple extortion.

This is the history of ransomware, which highlights that while the threat has evolved, the objectives for threat actors have remained the same.

As threat actors continue to revolutionise ransomware, it’s vital organisations prioritise their defences to keep pace with these changing techniques.

Cian Heasley

Principal Consultant, Acumen Cyber,

Latest News

Data Editor's Picks Security

NHS Transplant Data Sent Over Unencrypted Pagers, BBC Finds

AI Business Editor's Picks

Is AI Behind the UK’s Latest Economic Growth?

Cybersecurity

Cl0p Claims Massive Hack of 50 Companies

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach