Ransomware Negotiation Is Now a Business Process

▼ Summary
– Dave Ross from Intel 471 explains the behind-the-scenes tactics used by ransomware groups during negotiations.
– Attackers conduct research on victim revenue and insurance coverage while using test decryptions to prove they possess a working key.
– Ransom demands typically range from 1% to 5% of annual revenue, with deadlines adjusted based on victim response behavior.
– Criminal operations often split labor among researchers, negotiators, and staff applying public pressure, supported by a service economy for language and legal skills.
– Multi-extortion methods include data theft, DDoS attacks, and contacting customers or journalists, highlighting the need for pre-incident preparation.
Ransomware negotiation has evolved into a structured business process, characterized by sophisticated operational workflows and specialized roles within criminal organizations. According to Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, these groups employ systematic tactics that mirror corporate strategies once an attack is initiated. The process begins with extensive reconnaissance, where attackers analyze a victim’s financial health, specifically targeting annual revenue figures and insurance policy details to determine leverage points.
A critical early step involves proving the efficacy of their encryption tools. Attackers often perform test decryptions on small samples of data to demonstrate that they possess a working key, thereby establishing credibility before making formal demands. These financial requests are typically calculated to represent approximately 1% to 5% of the victim’s annual revenue. However, the timeline for payment is not static; deadlines shift dynamically based on how quickly and effectively the victim responds to initial communications.
The operational structure of modern ransomware gangs is highly compartmentalized. Work is divided among distinct teams, including researchers who gather intelligence, negotiators who handle direct communication, and staff members tasked with applying public pressure. This division of labor allows them to operate efficiently and reduce the risk of detection. Furthermore, these groups benefit from a broader criminal service economy that provides essential support services, such as language translation, data review, and legal analysis, enabling them to target international victims with greater ease.
Beyond simple encryption, many groups utilize multi-extortion methods to increase coercion. This includes stealing sensitive data prior to encryption, launching distributed denial-of-service (DDoS) attacks to disrupt operations, and directly contacting customers or journalists to damage the victim’s reputation. To counter these threats, organizations must prepare thoroughly before an incident occurs. This preparation involves defining clear authorization protocols for who is permitted to speak during negotiations and identifying which internal stakeholders need to be involved in the response strategy. Understanding these mechanics is crucial for developing effective defense and response plans.
(Source: Help Net Security)




