The Biden administration is taking aim at the use of cryptocurrencies in automated ransomware attacks, it was revealed Thursday. Cryptocurrencies are often used because they’re harder to trace, but the administration will adopt more rigorous tracing of ransomware paid out to hackers.

The strategy also will involve bounties of up to $10 million for information that leads to cyberattackers, according to a senior administration official who spoke to Bloomberg-Mercury News.
In one recent attack, meat supplier JBS S.A. paid out an $11 million ransom to the Russia-linked ransomware gang REvil. News reports said REvil vanished from the dark web on July 13, days after President Biden pressed Russian President Vladimir Putin to shut down ransomware groups attacking American targets
Ransomware intent has changed
While ransomware attacks aren’t new, the intent behind many of them has evolved from hackers merely learning or trying to figure out systems to demands by cybercriminals for cryptocurrency in exchange for unlocking a company’s data, said Justin Estadt, head of product at SEI IT Services and a 20-plus-year veteran of IT security.
“It’s not kids in the basement anymore that are trying to learn, or that are maybe doing fairs to brag to their friends,” Estadt told Bank Automation News. “It’s enterprise. It’s organized crime. It’s nation states.”
Attacks are becoming more sophisticated, too, and automation plays a role in how these attacks are committed, Estadt said.
Automation plays key role in attacks
“One hundred percent, automation is playing a role in how things are committed most of the time, whatever the technology mechanism is, that is going to actually get the ransomware onto a machine or onto infrastructure onto a network,” Estadt said. Often the attack targets an employee, who will trigger the attack by clicking on a link or downloading something.
“It all depends on what the overall goal is and how complex the infrastructure is for whoever is being attacked,” Estadt said. “Once the actual ransomware is meant to be proliferated throughout the entire infrastructure, that is 100% automated; there’s no manual action at that point other than maybe to push the ‘go’ button.”
Sometimes, with large or more sophisticated attacks, once the attacker cracks the system, he or she may stay hidden for weeks or months while further infiltrating into an organization’s systems to steal more data.
A hallmark of their increasing sophistication are emails that take aim at a specific job function — operations at a financial or manufacturing company, for example — and offer something job-specific, like an invoice the target is supposed to pay today, Estadt added. Then, it may send the user to a duplicated site that looks completely credible.
“We see that a lot with the duplicated sites, especially in the financial industry, for community banks and credit unions — they literally copy the entire website for a given corporation and then go and host it someplace else,” he said. “They try to trick either the bank employees or their customers to try to log in to the fake site, which looks 100% identical to the real one.” The difference may be as subtle as ABCc.bank or abc.bank versus ABC.bank.
Cybercriminals aim to damage reputation
Ransomware was formerly used to hold information for ransom, so companies responded by implementing data-backup policies. Now, however, attackers are more likely to threaten the release of the data to harm an organization’s reputation.
“These folks have changed their attack metrics to include exactly what the state is going after — reputational risk or having some other topic compromise with credit card numbers or whatever may be inside of the data … that you, as a business, probably don’t want to go public,” Estadt said.






