{"id":47254,"date":"2022-06-25T10:41:06","date_gmt":"2022-06-25T10:41:06","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/"},"modified":"2022-06-25T10:41:06","modified_gmt":"2022-06-25T10:41:06","slug":"were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/","title":{"rendered":"We&#8217;re now truly in the era of ransomware as pure extortion without the encryption"},"content":{"rendered":"<p><span class=\"label\">Feature<\/span> US and European cops, prosecutors, and NGOs recently convened a two-day workshop in the Hague to discuss how to respond to the growing scourge of ransomware.<\/p>\n<p>&#8220;Only by working together with key law enforcement and prosecutorial partners in the EU can we effectively combat the threat that ransomware poses to our society,&#8221; said US assistant attorney general Kenneth Polite, Jr, in a <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.justice.gov\/opa\/pr\/united-states-and-eu-foster-cooperation-against-ransomware-attacks\">canned statement<\/a>.<\/p>\n<p>Earlier this month, at the annual <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/Tag\/RSA%20Conference\/\" rel=\"noopener\">RSA Conference<\/a>, this same topic was on cybersecurity professionals&#8217; minds \u2013 and lips.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Ransomware, and other cybercrimes in which miscreants extort organizations for money, &#8220;is still the vast majority of the threat activity that we see,&#8221; Cyber Threat Alliance CEO Michael Daniel said in an interview at the security event.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>Increasingly, however, cybercrime rings still tracked as ransomware operators are turning toward primarily data theft and extortion \u2013 and&nbsp;skipping the encryption step altogether. Rather than scramble files and demand payment for the decryption keys, and all the faff in between in facilitating that, simply exfiltrating the data and demanding a fee to not leak it all is just as effective. This shift has been ongoing for many months, and is now virtually unavoidable.<\/p>\n<p>The FBI and CISA this month <a href=\"https:\/\/www.theregister.com\/2022\/06\/03\/fbi_cisa_warn_karakurt_extortion\/\">warned<\/a> about a lesser-known extortion gang called Karakurt, which demands ransoms as high as $13 million. Karakurt doesn&#8217;t target any specific sectors or industries, and the gang&#8217;s victims haven&#8217;t had any of their documents encrypted and held to ransom.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Instead, the crooks claim to have stolen data, with screenshots or copies of exfiltrated files as proof, and they threaten to sell it or leak it publicly if they don&#8217;t receive a payment.&nbsp;<\/p>\n<h3 class=\"crosshead\"> <span>&#8216;Multi-faceted extortion&#8217;<\/span><br \/>\n<\/h3>\n<p>&#8220;That&#8217;s exactly what&#8217;s happening to a lot of the victims that we work with,&#8221; Mandiant Intelligence VP Sandra Joyce told <em>The Register<\/em>. &#8220;We call it multi-faceted extortion. It&#8217;s a fancy way of saying data theft paired with extortion.&#8221;<\/p>\n<p>Some of these thieves offer discounted ransoms to corporations to encourage them to pay sooner, with the demanded payment getting larger the longer it takes to cough up the cash (or Bitcoin, as the case may be).<\/p>\n<blockquote class=\"pullquote\" readability=\"6\">\n<p>Until it is not the lucrative business that it is today, it&#8217;s not going away<\/p>\n<\/blockquote>\n<p>Additionally, some crime groups offer &#8220;sliding-scale payment systems,&#8221; Joyce noted. &#8220;So you pay for what you get,&#8221; and depending on the amount of ransom paid &#8220;you get a control panel, you get customer support, you get all of the tools you need.&#8221;<\/p>\n<p>As criminals move deeper into extortion, they rely on other tactics to force organizations to pay up \u2013 such as leaking stolen confidential data from Tor-hidden websites, and devising other ways to publicly humiliate companies into paying a ransom for their swiped documents, Joyce added. &#8220;Until it is not the lucrative business that it is today, it&#8217;s not going away.&#8221;<\/p>\n<p>This echoes what Palo Alto Networks&#8217; Unit 42 incident responders are seeing as well. Crooks post, on average, details about sensitive information stolen from seven new victims per day on these dark-web leak sites, according to Unit 42 research released at RSA Conference.&nbsp;<\/p>\n<p>&#8220;The cyber-extortion crisis continues because cybercriminals have been relentless in their introduction of increasingly sophisticated attack tools, extortion techniques and marketing campaigns that have fueled this unprecedented, global digital crime spree,&#8221; <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2022\/06\/average-ransomware-payment-update\/\" rel=\"nofollow\">wrote<\/a> Ryan Olson, the VP of threat intelligence for Palo Alto Networks who leads Unit 42.<\/p>\n<h3 class=\"crosshead\"> <span>More sophisticated \u2026 marketing campaigns?<\/span><br \/>\n<\/h3>\n<p>Indeed, much has been made about the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2021\/10\/11\/ransomware_as_a_service\/\" rel=\"noopener\">growing<\/a> ransomware-as-a-service market, whereby malware developers rent out their code to less tech-savvy fraudsters to deploy&nbsp;on victims&#8217; networks, once access has been obtained by buying stolen or leaked login credentials or paying someone else to do the intrusion, or similar.<\/p>\n<p>Indeed, the Conti internal communications <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2022\/03\/11\/conti_leaks_code\/\" rel=\"noopener\">leaked<\/a> earlier in the year highlighted how these ransomware gangs operate akin to software-as-a-service startups.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>And on top of that, the way that these crime groups use marketing and public relations campaigns points to a whole new level of sophistication, according to Ryan Kovar, who leads the Splunk Surge research team.<\/p>\n<p>In March, Kovar&#8217;s security biz published <a href=\"https:\/\/www.theregister.com\/2022\/03\/23\/ransomware_encryption_speed\/\">research<\/a> on how long it takes ten of the big ransomware families \u2013 including Lockbit, Conti, and REvil \u2013 to encrypt 100,000 files. They found Lockbit was the swiftest \u2013 indeed the reason the team undertook this analysis in the first place was because that ransomware gang claimed on its Tor website to have the &#8220;fastest ransomware.&#8221;<\/p>\n<p>&#8220;They&#8217;re to the point where someone said, &#8216;We&#8217;re losing ground to other ransomware families. And we actually have to create marketing material to better position our ransomware as the choice du jour,'&#8221; Kovar said in an interview on the sidelines of RSAC.&nbsp;<\/p>\n<p>&#8220;That&#8217;s fascinating,&#8221; he continued. &#8220;The sophistication shows there&#8217;s a competitive aspect to this beyond just &#8216;we&#8217;re good at converting ransoms to Bitcoin&#8217;.&#8221;<\/p>\n<h3 class=\"crosshead\"> <span>But still hitting the same, unpatched vulns<\/span><br \/>\n<\/h3>\n<p>Miscreants may have moved on to new extortion techniques and more sophisticated business models, but they are exploiting the same, known vulnerabilities \u2013 simply because these still work and don&#8217;t require a heavy lift from the malware operators. These are profit-seeking criminals, after all, looking to keep costs low and profit margins high.&nbsp;<\/p>\n<p>&#8220;The way the ransomware actors have success \u2026 is often through those known exploitable vulnerabilities,&#8221; NSA Cybersecurity Director Rob Joyce said, speaking during a <a href=\"https:\/\/www.theregister.com\/2022\/06\/08\/us_shields_down\/\">panel<\/a> at RSA Conference.<\/p>\n<p>Enterprises can reduce their risk by patching <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" rel=\"nofollow\">these known actively exploited bugs<\/a>, he added. &#8220;That needs to be the base,&#8221; Joyce said. &#8220;Everybody needs to get to that base level and take care of the unlocked doors that [cybercriminals] are coming in today.&#8221;<\/p>\n<p>In a separate interview at the show, Aanchal Gupta, who leads Microsoft&#8217;s Security Response Center, concurred.&nbsp;<\/p>\n<p>&#8220;Businesses sometimes think they have to do something unique about ransomware,&#8221; she told <em>The Register<\/em>. &#8220;And I would say no, you do not have to do anything unique about ransomware. All you need to do is the same protect, detect, respond.&#8221;<\/p>\n<p>Protect means patch your systems, and detection requires visibility across the network, Gupta added. &#8220;Because they all come through the known vulnerabilities that have been disclosed, and there are patches available 99 percent of the time.&#8221;<\/p>\n<p>Typically, these profit-driven crooks aren&#8217;t breaching networks through zero-day exploits, she said. &#8220;They are not going to purchase a zero-day for a half a million dollars to do a ransomware attack,&#8221; Gupta noted.<\/p>\n<p>Gupta and others encouraged organizations to run table-top exercises so they are prepared if or when an attack hits.&nbsp;<\/p>\n<h3 class=\"crosshead\"> <span>Tell the truth. Even if it hurts<\/span><br \/>\n<\/h3>\n<p>The public response to an intrusion needs to be transparent if it&#8217;s to be helpful \u2013 even if it&#8217;s embarrassing. This includes having a ransomware press release written in advance, noted Dmitri Alperovitch, chair of security-centric think tank Silverado Policy Accelerator.<\/p>\n<p>&#8220;Write a press release that you&#8217;re going to put out in the event of a data leak, or a ransomware attack,&#8221; he said. &#8220;Have that ready because oftentimes, inevitably, it takes days for people to get their arms around what they&#8217;re going to say publicly, and they involve way too many lawyers. Get that out of the way early on so that you can just fill in the details.&#8221;<\/p>\n<p>And don&#8217;t lie. Eventually, corporations do recover from ransomware attacks \u2013 especially if they have good backups.&nbsp;<\/p>\n<p>But they may not regain customers&#8217; trust if they aren&#8217;t transparent about what happened, CrowdStrike CTO Mike Sentonas told <em>The Register<\/em>. His company was hired to assist in incident response after a &#8220;well-known media company got hit with ransomware,&#8221; Sentonas said.&nbsp;<\/p>\n<p>CrowdStrike advised the corporation to tell the truth, &#8220;and they went and did the opposite, said it was a sophisticated adversary and no one could have ever stopped this,&#8221; Sentonas said. In fact, &#8220;it was a really basic attack,&#8221; he noted. &#8220;And you come out looking a little bit silly through that process.&#8221; \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2022\/06\/25\/ransomware_gangs_extortion_feature\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why screw around with cryptography and keys when just stealing the info is good enough Feature\u00a0 US and European cops, prosecutors, and NGOs recently convened a two-day workshop in the Hague to discuss how to respond to the growing scourge of ransomware.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-47254","post","type-post","status-publish","format-standard","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>We&#039;re now truly in the era of ransomware as pure extortion without the encryption 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"We&#039;re now truly in the era of ransomware as pure extortion without the encryption 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-25T10:41:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"We&#8217;re now truly in the era of ransomware as pure extortion without the encryption\",\"datePublished\":\"2022-06-25T10:41:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/\"},\"wordCount\":1332,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/\",\"name\":\"We're now truly in the era of ransomware as pure extortion without the encryption 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"datePublished\":\"2022-06-25T10:41:06+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/#primaryimage\",\"url\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"contentUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"We&#8217;re now truly in the era of ransomware as pure extortion without the encryption\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"We're now truly in the era of ransomware as pure extortion without the encryption 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/","og_locale":"en_US","og_type":"article","og_title":"We're now truly in the era of ransomware as pure extortion without the encryption 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-06-25T10:41:06+00:00","og_image":[{"url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"We&#8217;re now truly in the era of ransomware as pure extortion without the encryption","datePublished":"2022-06-25T10:41:06+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/"},"wordCount":1332,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/","url":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/","name":"We're now truly in the era of ransomware as pure extortion without the encryption 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","datePublished":"2022-06-25T10:41:06+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/#primaryimage","url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","contentUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YrcMH@Su7zV4ZZlR0hyFswAAAFM&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/were-now-truly-in-the-era-of-ransomware-as-pure-extortion-without-the-encryption\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"We&#8217;re now truly in the era of ransomware as pure extortion without the encryption"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=47254"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/47254\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=47254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=47254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=47254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}