Intelligent CISO Issue 30 | Page 19

cyber trends credentials for the likes of Microsoft 365 accounts as high-value targets . However , many – if not most – phishing emails today are sent by cybercriminals as a launchpad for the latest cyberattack trend : double-extortion ransomware .
The rise of doubleextortion ransomware
Ransomware is a form of cyberattack usually carried out by cybercriminal groups for financial gain . In a typical ransomware attack , a target organisation ’ s network is penetrated by cybercriminals often by sending a phishing email to individuals in the organisation that contains malware , or sometimes through exploiting a vulnerability in the organisation ’ s network .
The malware enters the network and the attackers conduct reconnaissance and further activity to achieve the right access they need to execute the ransomware . Once this is done , the target organisation ’ s network is encrypted and effectively unusable until either a ransom is paid or the organisation reverts to backups to bring the network back online .
This may all be fairly familiar so far , but what is relatively new is the trend for double-extortion ransomware attacks . Double-extortion first became a prominent tactic as a further method to make money from late-2019 onwards . As part of the ransom demands to the www . intelligentciso . com | Issue 30
19