Ransomware Evolution: From the AIDS Trojan to Quadruple Extortion

โ–ถ Watch (2:02)

1989 saw the AIDS Trojan encrypt data and demand payment through a Panama mailbox. The 2017 NHS attack by Wakry cancelled 90,000 appointments and impacted MIR devices. Contiโ€™s attack forced Costa Rica to declare a national emergency. LockBit added four extortion vectors: encryption, data leak, DDoS, and customer harassment. Professionalized RaaS operations provide 24/7 victim support and structured negotiations. Between 2020 and 2025, cyber criminals collected $600 million to $1 billion annually.

The Ransomware Business Model: Affiliates, Panels, and Revenue Splits

โ–ถ Watch (13:57)

Leaked Conti chat logs revealed a threat group with executive, strategic, and operational levels managing affiliates, tool development, and money laundering. Contiโ€™s 2021 revenue reached $108 million. LockBitโ€™s leaked panel showed a $777 affiliate access fee and an 80/20 revenue split favoring affiliates. LockBit moved 52 bitcoins through specific wallets. Threat groups offer discounts of 40-60% during negotiations or escalate with DDoS attacks.

A $10 Credential Leads to a $30 Million Demand

โ–ถ Watch (18:59)

A threat actor purchased a privileged credential for $10 on the dark web. The credential was harvested months earlier by a Hakon info stealer. The actor accessed the environment and exfiltrated 4TB of data. He demanded $30 million with a daily price increase. The actor leaked a script containing an API key, which accelerated forensic analysis. The company did not pay the ransom despite four extortion attempts.

Incident Response for Multi-Vector Extortion

โ–ถ Watch (25:25)

Matos mapped three work streams for extortion response. The technical stream handles forensic analysis and containment. The executive stream prepares media statements and board-level decisions on ransom payments. The communication stream manages internal blackout and external messaging. Legal counsel, law enforcement, and cyber insurance activate immediately. The playbook covers single through quadruple extortion scenarios. The threat actor may escalate from data leaks to DDoS and customer harassment within 24 hours.

Q&A

How should companies handle liability when threat actors demand ransom? Get law enforcement, legal counsel, and cyber insurance involved immediately to avoid executive liability. โ–ถ 33:18

Notable Quotes

if you donโ€™t pay me uh or if you donโ€™t evolve on the negotiations very quickly with me Iโ€™m going to increase the price uh and Iโ€™m going to increase the price per day uh until we reach uh 30 million Diego Matos ยท โ–ถ 23:23

the threat actor has used a credential that was exposed on the dark web uh and thatโ€™s uh was sold on the dark web uh by for for $10 Diego Matos ยท โ–ถ 21:23

he was using a specific API key thatโ€™s um we use it for the investigation it was very quick for us to based on that um proceed on uh doing the containment Diego Matos ยท โ–ถ 20:41

they would stay with 80% of the revenue and the administrators of the lock beat portal uh would stay with 20% Diego Matos ยท โ–ถ 15:24

Key Takeaways

  • Ransomware attacks evolved from single-vector encryption to quadruple extortion including DDoS and harassment.
  • LockBitโ€™s leaked panel revealed $777 affiliate fees and 80/20 revenue splits.
  • A single $10 credential on the dark web led to a $30 million extortion demand.
  • Effective incident response synchronizes technical, executive, and communication work streams.