{"id":5109,"date":"2024-09-01T20:00:00","date_gmt":"2024-09-02T01:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/ransomware-gangs-pummel-southeast-asia"},"modified":"2024-09-01T20:00:00","modified_gmt":"2024-09-02T01:00:00","slug":"ransomware-gangs-pummel-southeast-asia","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/01\/ransomware-gangs-pummel-southeast-asia\/","title":{"rendered":"Ransomware Gangs Pummel Southeast Asia"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltbc2a64cc01dc7aa5\/66ce28926a9001c898de4b0a\/PabloLagarto-world-as-code-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A spate of major ransomware attacks in Southeast Asia in the first half of this year was just the beginning.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies and government agencies in Southeast Asia \u2014 especially Thailand, Japan, South Korea, Singapore, Taiwan, and Indonesia \u2014 have experienced a significant increase in attacks, outpacing the rate of ransomware growth in European nations, according to telemetry data from Trend Micro. Major incidents such as the June ransomware attack by a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/ransomware-group-behind-major-indonesian-attack-wears-many-masks\" rel=\"noopener\">gang known as Brain Cipher<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/indonesia-refuses-to-pay-8m-ransom-after-cyberattack\" rel=\"noopener\">disrupted more than 160 Indonesian government agencies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, are likely to multiply as the economies in the region grow.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many companies and organizations in Asia are rushing to digitize their infrastructure, but often at the sacrifice of security, says Ryan Flores, senior manager of forward-looking threat research at Trend Micro.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There is a lot of digitization initiatives happening in the region, with governments supporting and encouraging the adoption of online services and payments,&#8221; he says. &#8220;Because of the rush to infrastructure and services, security is most often relegated to a lower-level priority, as priority number one is to get the service or platform to market as soon as possible.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Already, companies and organizations in the Asia-Pacific region have suffered serious cyberattacks, confirming <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ransomware-attacks-strike-south-africa-decline-in-uae\" rel=\"noopener\">signs that threat groups<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have focused on the region. In March, a major brokerage in Vietnam had to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/ransomware-junk-bank-accounts-cyberthreats-proliferates-in-vietnam\" rel=\"noopener\">shut down securities trading for eight days<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, following a ransomware attack that encrypted critical data. The same month, Japanese officials called out North Korean hackers for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/japan-blames-north-korea-for-pypi-supply-chain-cyberattack\" rel=\"noopener\">polluting the Python Package Index (PyPI)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with malicious code capable of dropping ransomware on victims&#8217; computers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While more than three-quarters of ransomware attacks continue to target organizations in North America and Europe, the share of successful cyberattacks that impact other regions \u2014 especially Asia \u2014 has spiked. In 2023, the number of publicly reported ransomware attacks grew 85% in Asia, according to data from cybersecurity information services firm Comparitech.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other threat trackers show similar trends: India and Singapore are both in the top six most-targeted countries tracked by cybersecurity firm Sophos, according to the firm&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sophos.com\/en-us\/content\/state-of-ransomware\" rel=\"noopener\">&#8220;State of Ransomware 2024&#8221; report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"APAC a Ripe Field for Ransomware\">APAC a Ripe Field for Ransomware<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ransomware groups are targeting the most critical and vulnerable industrial sectors in the Asia-Pacific region. The manufacturing sector saw a significant increase in attacks, with 21 confirmed ransomware events in 2023, followed by 16 for the government sector and 11 in healthcare, according to data compiled from public reports by Comparitech.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One major factor is that many countries do not have a breach notification law in place, leading to a significant underreporting of breaches and less focus on cybersecurity in Asia. The popularity of cryptocurrency in many Asian countries also has resulted in a greater likelihood of companies paying ransoms, says Rebecca Moody, head of data research at Comparitech.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In a lot of cases, the only time you find out if [an attack has] been confirmed or not is because of system disruptions or websites going down &#8230; whereas &#8230; if they managed to get the systems back online and nobody&#8217;s none the wiser &#8230; then they can kind of skirt over it,&#8221; she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ransomware, along with cybercriminal fraud, is endemic in the Asia-Pacific region. North Korean groups <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/north-korea-linked-group-level-multistage-cyberattack-on-south-korea\" rel=\"noopener\">use ransomware, cryptojacking attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and other schemes to siphon cash from the global economy, as well as conduct espionage. Large fraud centers in Cambodia, Laos, and Myanmar \u2014 essentially forced-labor camps \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/forced-labor-camps-fuel-billions-of-dollars-in-cyber-scams\" rel=\"noopener\">run by criminal syndicates<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from China and other Asia nations conduct massive industrial-scale romance scams and &#8220;pig butchering&#8221; to generate tens of billions of dollars a year in revenue.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Big Money, Minimal Effort\">Big Money, Minimal Effort<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the end, however, the increase in ransomware attacks is likely less about specific targeting and more about the increase in potential victims, as companies implement digital transformations but fail to update their security as quickly, Trend Micro&#8217;s Flores says. The relative immaturity of the region&#8217;s cybersecurity ecosystem, along with increasing regional tensions, are more likely behind the rise in attacks rather than specific targeting.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Ransomware groups and cybercriminals in general are opportunistic, so I don&#8217;t think they are really focused on one region over another,&#8221; he says. &#8220;What they focus on instead are big payouts with minimal effort, so if there are infrastructure that are vulnerable, open, or misconfigured, those are easy targets for them and it does not matter if that is in Asia, Europe, or Africa.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">National governments in the Asia-Pacific region have already started to update their regulations to improve security. In May, Singapore updated it Cybersecurity Act to account for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/singapore-cybersecurity-update-puts-cloud-providers-on-notice\" rel=\"noopener\">its critical infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> sector&#8217;s reliance on third parties who use cloud services, while Malaysia passed legislation in April that requires <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros\" rel=\"noopener\">cybersecurity service providers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to be licensed to do business in the country, although the details still need to be ironed out.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies in those regions should focus on covering their bases and implement foundational defenses, says Matt Hull, global head for strategic threat intelligence for the NCC Group, a cybersecurity consultancy.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Organizations must prioritize regular patch management to close known vulnerabilities, enforce strong password policies to prevent easy exploitation, and implement multifactor authentication (MFA) to add an additional layer of security beyond passwords,&#8221; he says. &#8220;Additionally, it\u2019&#8217; essential to establish robust detection and monitoring systems that can swiftly identify and respond to potential threats.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/ransomware-gangs-pummel-southeast-asia\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A spate of major ransomware attacks in Southeast Asia in<\/p>\n","protected":false},"author":12,"featured_media":5110,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/ransomware-gangs-pummel-southeast-asia.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5109"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5109\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5110"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}