Quadruple Extortion  Ransomware

Quadruple extortion is based on a period of aggressive harassment of company-related actors, after the company has previously been subjected to a damaging attack. This is yet another technique with which cyber criminals seek to make as much profit as possible. 

In recent times, ransomware has become the predominant attack. Now, leading Spanish cyber security firm Entelgy Innotec Security analysed more than 7,000 cases of malware, including ransomware, Trojans, spyware across Spain over the course of 2022.

Their conclusion is that ransomware, phishing and DDoS attacks are the main cyber threats and that these exploits have become more effective, as a result of the specialization, sophistication and demand for cybercrime for hire, as a service. 

In addition, it is estimated that more than half of the companies that are attacked by ransomware agree to extortion. 

But how far can ransomware extortion go? The answer lies in quadruple extortion, which is already a reality.  
"Quadruple extortion is a technique used in ransomware cyberattacks whose objective is to maximise the monetisation capacity expected by the threat actor responsible for the campaign," explains Raquel Puebla, cyber intelligence analyst at Entelgy Innotec Security. 

With this new level of extortion, the aim is to ensure that the affected entity pays the ransom demanded by the attackers for the cyber attack, which is the ultimate goal of today's ransomware actors.

Therefore, "it is not understood as a cyber attack in itself, but as an additional layer to ransomware cyber attacks," Puebla sys. It is called quadruple extortion or fourth extortion stage because it usually takes place after three other stages that usually accompany these cyber attacks.

The Four Phases Of The Extortion Cycle

1.   Data encryption phase:   In most cases this involves a risk to the availability of the affected organisation's systems. In this case, the extortion consists of forcing the organisations to demand payment of the ransom so that they can regain access to the encrypted information. 

2.   Information leakage threat phase:   In this phase the attackers raise the level of extortion by threatening to publicly leak the information previously obtained during the compromise and encryption process, which in many cases results in the exposure of sensitive data or information that can entail all kinds of sanctions for the affected entity. This is known as Double Extortion. 

3.   Denial of Service (DDoS) campaign phase:   Which prevents users from accessing the affected organisation's resources, substantially increasing its losses by causing service unavailability. This model has come to be known as triple extortion and its use is very common in online commerce organizations. It prevents the achievement of sales. 

4.   Aggressive harassment phase:   Cyber criminals contact customers, employees and business partners of the affected organisation, as well as the media, to inform them that sensitive or confidential information associated with them has been compromised, for which they will first try to obtain data associated with users linked to the company from among the stolen information. 

"With this model, called quadruple extortion, the attackers intend that agents related to the organisation are the ones who promote that the entity agrees to pay extortion to remove the data breach that affects them," explains Puebla. 

The layers of extortion described work together to increase the losses of the organisation affected by the cyber attack, pressuring and wearing it down until it considers that the payment demanded by the cybercriminals is less costly than remedying the impact through the corresponding legal incident response channel. This is why cybercriminals are constantly trying to devise new extortion models to persuade their victims to make the demanded payment.

Early Detection 

There are several ways to prevent this type of cyber-attack and avoid irreversible damage. 

  • The detection of anomalous requests or connections from unknown or non-geolocated IP addresses in the employee's country or region of work are indications of suspicious activity, so it is highly recommended that all organisations establish monitoring activities on access to accounts, email addresses and corporate profiles.  
  • In addition, grammatical and spelling errors in e-mail messages that arrive in the user's mailbox, their origin from an unknown sender, and the inclusion of links to external websites or attachments can also be warning signs.
  • In the case of attachments, it may be advisable to scan them in anti-malware software before opening them, for example, and, if in doubt, it is always advisable not to open them. 
  • Other more obvious signs that could be observed at a later stage of the cyberattack could include unexpected changes in permissions, the appearance of blockages when accessing certain resources and even the appearance of a ransom note.

You Might Also Read: 

A New Approach To Cyber Security Helps Resist Extortion:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Severe Risks From Remote Access Exposure
US National Cyber Security Strategy Moves On »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Qualys

Qualys

Qualys is a pioneer and leading provider of cloud security and compliance solutions.

Certes

Certes

Certes is a pioneer in delivering cutting-edge security technology solutions, with a specific focus on Data Protection Risk Mitigation (DPRM).

International Telecommunication Union (ITU)

International Telecommunication Union (ITU)

ITU is the United Nations specialized agency for information and communication technologies – ICTs. Areas of activity include cybersecurity.

Towergate Insurance

Towergate Insurance

Towergate Insurance is a leading UK specialist insurance broker. Business products include Cyber Liability Insurance.

Athena Dynamics

Athena Dynamics

Athena Dynamics focuses on Cyber Security, especially in Critical Information Infra-structure Protection and Enterprise IT Operation Management products and Services.

Radiflow

Radiflow

Radiflow is a leading provider of cyber security solutions for critical infrastructure networks (i.e. SCADA), such as power utilities, oil & gas, water and others.

Living Security

Living Security

Living Security specializes in metric driven and engaging security awareness solutions that reduce risk by increasing security culture and changing employee behaviour.

Sopher Networks

Sopher Networks

Sopher is a secure communication and collaboration platform for business and personal use.

Cybertonica

Cybertonica

Cybertonica is a FinTech company which detects and prevents fraudulent transactions and reduces risk for financial services organisations.

CyberSwarm

CyberSwarm

CyberSwarm is developing a neuromorphic System-on-a-Chip dedicated to cybersecurity which helps organizations secure communication between connected devices and protect critical business assets.

iTechArt Group

iTechArt Group

iTechArt is a top-tier custom software development company offering Cybersecurity Consulting, Application Security Testing, Risk Management and Compliance, and Infrastructure Security services.

FiVerity

FiVerity

FiVerity provides financial institutions with cyber fraud defense to combat a dangerous and growing threat - the convergence of fraud-related theft with sophisticated, high-volume cyber attacks.

Cyber Bytes Foundation

Cyber Bytes Foundation

Cyber Bytes Foundation exists to establish and sustain a unique Cyber Ecosystem to accelerate the development of a strong Cyber workforce and support community outreach programs.

Crayon

Crayon

Crayon is a customer-centric innovation and IT services company. We provide guidance on the best solutions for our clients’ business needs and budget with software, cloud, AI and big data.

Gomboc.ai

Gomboc.ai

Gomboc solve cloud infrastructure security policy deviations by providing tailored remediations to the IaC (Infrastructure as Code).

CloudGuard

CloudGuard

CloudGuard is an AI-driven XDR platform that helps organisations to proactively detect and automatically remediate threats in real-time.