How Does the Ransomware Payment Ecosystem Work?

296 views
•
June 7, 2023
by
RSAC Cybersecurity
YouTube video player
How Does the Ransomware Payment Ecosystem Work?

TL;DR

Ransomware profits can be disrupted by adding friction where victims acquire cryptocurrency, criminals obscure payments, and proceeds return to fiat currency. Mapping the money flow, the information created at each stage, and the entities able to see that information helps defenders, financial institutions, cryptocurrency companies, insurers, incident responders, and law enforcement identify practical intervention points.

Transcript

Thanks so much for coming out. I know you had like a hundred thousand other options, um, for right now, so we're happy to see everyone here. Um, my name is Zoe Brammer. I'm an associate at the Institute for Security and Technology. I do cyber and information operations, and I'm really excited to talk to you about some research we published last fal... Read More

Key Insights

  • The ransomware payment ecosystem begins when a victim decides to pay and usually needs to acquire cryptocurrency, because the vast majority of ransom demands described in the presentation request payment in cryptocurrency rather than fiat currency.
  • A victim can obtain cryptocurrency by transferring fiat currency from a depository institution to a virtual asset service provider, using mechanisms such as wire transfers, automated clearing houses, or credit cards before establishing a funded cryptocurrency wallet.
  • A victim that already holds enough cryptocurrency can bypass the initial acquisition process and proceed directly to payment, although the presentation says that most victims do not possess enough cryptocurrency to cover a ransom demand.
  • Cryptocurrency is pseudonymous rather than fully anonymous, because a wallet user may not provide identifying details while transactions and wallet activity remain traceable on the blockchain, creating potential visibility for investigators and blockchain intelligence companies.
  • Obfuscation works by making the chain of activity and identity on the blockchain harder to follow. Ransomware actors may use cryptocurrency exchanges, peer-to-peer exchanges, centralized exchanges, mixers, darknet markets, and transfers among wallets during this process.
  • Mixers obscure cryptocurrency flows by combining illicit proceeds with cryptocurrency from other users and assigning funds to different wallets on the other side, complicating efforts to trace a payment from its source to its later destination.
  • Ransomware actors can retain cryptocurrency in wallets for later spending or convert it back into fiat currency. Cash-out reverses the victim's acquisition process by moving cryptocurrency through a virtual asset service provider and off the blockchain into fiat currency.
  • The ecosystem map connects money movements with the information produced at each stage and the entities capable of obtaining technical visibility into that information, helping stakeholders locate opportunities to add friction and make ransomware less profitable.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How does a ransomware payment move from a victim to an attacker?

A victim typically begins by acquiring the cryptocurrency requested in the ransom demand. The victim, or an organization acting for it, transfers fiat currency from a depository institution to a virtual asset service provider and places the acquired cryptocurrency in a wallet. The victim then sends payment to one or more wallets controlled by the ransomware actor, who generally moves quickly to obscure the funds.

Q: How do ransomware victims acquire cryptocurrency for payment?

Most victims described in the presentation do not already hold enough cryptocurrency to satisfy a ransom demand. The victim or a representative, such as a digital forensics and incident response firm, contacts a depository institution and transfers money to a virtual asset service provider. The transaction can use a wire transfer, an automated clearing house, or a credit card, resulting in a funded cryptocurrency wallet.

Q: What is a virtual asset service provider in the payment cycle?

A virtual asset service provider serves as a connection between fiat currency and cryptocurrency in the mapped ransomware payment process. On the victim side, fiat currency moves through the provider so the victim can acquire cryptocurrency. During cash-out, the criminal process runs in the opposite direction, with cryptocurrency moving through a virtual asset service provider and being converted into fiat currency.

Q: Why are cryptocurrency ransomware payments traceable?

Cryptocurrency is described as pseudonymous, meaning a wallet user does not necessarily need to supply a full name, address, or similar identifying information to use the wallet. However, transactions remain traceable on the blockchain. The user's identity can therefore exist through observable activity and associations, which is why ransomware actors attempt to complicate the chain before holding or cashing out their proceeds.

Q: How do ransomware actors obscure cryptocurrency payments?

Ransomware actors try to make blockchain activity and associated identity harder to follow after receiving a payment. Available techniques include moving assets through cryptocurrency exchanges, peer-to-peer exchanges, centralized exchanges, mixers, darknet markets, and additional wallets. These movements can place more steps between the ransom payment and the proceeds that an actor eventually stores, spends, or converts into fiat currency.

Q: What role do cryptocurrency mixers play in ransomware laundering?

Mixers combine illicit proceeds with cryptocurrency belonging to other users and then assign cryptocurrency to different wallets on the other side. Within the mapped ecosystem, this is one technique ransomware actors can use to obscure the path of their proceeds. The objective is to make it more difficult for investigators and other observers to follow the payment chain across blockchain transactions.

Q: Where can defenders add friction to ransomware payments?

Potential friction points appear throughout the payment cycle, including the conversion of fiat currency into cryptocurrency, the transfer to actor-controlled wallets, the obfuscation process, and the eventual cash-out into fiat currency. The map supports intervention analysis by identifying what information each stage generates and which regulated, unregulated, or under-resourced entities may have technical visibility into that information.

Q: Why not simply ban all ransomware payments?

A payment ban could directly target the profitability that encourages ransomware, and the discussion notes arguments that continued payment may weaken incentives to improve basic cyber hygiene. However, the panel also identifies a competing concern: organizations may need payment as an option to restore operations. Removing that option could compound the harm to victims that cannot otherwise return to normal operations.

Summary & Key Takeaways

  • The Institute for Security and Technology created a detailed map of the ransomware payment ecosystem after finding that no comprehensive picture was available. The map follows funds from an attack through cryptocurrency acquisition, ransom payment, obfuscation, storage, and cash-out, while distinguishing regulated entities from unregulated or under-resourced avenues.

  • Most victims must acquire cryptocurrency before paying a ransom. A victim or an organization acting on its behalf transfers fiat currency from a depository institution to a virtual asset service provider through a wire transfer, automated clearing house, or credit card. The acquired cryptocurrency is then placed in a victim-controlled wallet.

  • After receiving payment, ransomware actors attempt to obscure the movement of funds through exchanges, peer-to-peer services, mixers, darknet markets, and multiple wallets. The map also identifies information produced during each transaction and the organizations with technical visibility into it, creating a foundation for coordinated efforts to reduce profitable cash-outs.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚