In 2021, we saw a 29% increase in ransomware-related CVEs and a 26% increase in ransomware families compared to the previous year
Ivanti Inc., provider of the Neurons automation platform that discovers, manages, protects and supports IT assets from the cloud to the edge, presents the results of the Ransomware 2021 Year End Report, conducted together with Cyber Security Works, a CNA (Certifying Numbering Authority), and Cyware, a leading provider of Cyber Fusion, next-generation SOAR and threat intelligence solutions. In 2021, the report identified 32 new ransomware families, bringing the total to 157 and a 26% increase from the previous year.
The report also highlights how these ransomware groups manage, in record time, to identify zero-day vulnerabilities and target those without patches, finalizing extremely harmful attacks. At the same time, cybercriminals are expanding their reach, identifying new ways to compromise corporate networks.
Below are the main trends that emerged in the report:
- Unpatched vulnerabilities are still the most exploited attack vectors by cybercriminals. In the past year alone, 65 new ransomware-related vulnerabilities were discovered, representing a growth of 29% compared to the previous year, bringing the total number of vulnerabilities associated with this type of attack to 288. The alarming fact is that more than a third (37%) of these were present on the dark web and repeatedly exploited. 56% of the 223 older vulnerabilities, identified before 2021, were also actively exploited by hackers. In this scenario, companies must prioritize vulnerabilities and apply patches.
- Cybercriminals continue to detect and exploit zero-day vulnerabilities, anticipating the inclusion of CVEs in the National Vulnerability Database and the release of patches. The QNAP (CVE-2021-28799), Sonic Wall (CVE-2021-20016), Kaseya (CVE-2021-30116), and most recently Apache Log4j (CVE-2021-44228) vulnerabilities were exploited before being entered into the National Vulnerability Database (NVD). In this unreassuring scenario, vendors must disclose vulnerabilities and release patches based on priorities. Additionally, it is important for organizations to constantly monitor vulnerability trends, exploitation cases, vendor advisories, and security agency advisories.
- Attacks on supply chain networks are increasing with the aim of causing serious damage to businesses. A single supply chain breach can open multiple avenues for cybercriminals, hijacking entire system deployments through victim networks. In 2021, hackers compromised multiple supply chain networks, leveraging third-party applications, vendor-specific products, and open-source libraries. Among the latest examples, the REvil group attacked CVE-2021-30116 in the Kaseya VSA remote management service, launching a malicious update package that affected all users using onsite and remote versions of the VSA platform.
- Cybercriminals are sharing their services with third parties, following the model of legitimate SaaS solutions. Ransomware-as-a-service is a business model in which ransomware developers offer their services, variants, kits, or code to other criminals in exchange for payment. Exploit-as-a-service solutions allow cybercriminals to rent zero-day exploits from developers, while droppers-as-a-service allow inexperienced attackers to distribute programs that, if launched, can execute a malicious payload on the victim's computer. Trojan-as-a-service, on the other hand, also called malware-as-a-service, allows anyone with an Internet connection to obtain and distribute customized malware in the cloud, without requiring installations.
With 157 ransomware families exploiting 288 vulnerabilities, hackers will be able to conduct increasingly sophisticated attacks in the coming years. Furthermore, according to Coveware, companies pay on average $220,298 and suffer 23 days of downtime following a ransomware attack. All this demonstrates how greater attention to IT hygiene is necessary, through the implementation of automated solutions to manage the growing complexity of environments.
Srinivas Mukkamala, Senior Vice President of Security Products at Ivanti states: "Cybercriminals are becoming increasingly sophisticated and their attacks increasingly effective. The most used tools are automated kits capable of exploiting vulnerabilities and penetrating deeply into compromised networks. There is also a notable expansion in terms of targets that involves different sectors, causing unprecedented damage. Companies must therefore assign a risk-based priority to vulnerabilities, implement automated patches and accelerate the remediation process."
Anuj Goel, CEO di Cyware, says: "The most notable change in today's ransomware attack landscape is attackers attempting to penetrate patch deployment processes and system loophole discovery. Vulnerability discovery requires careful handling of vulnerability data to respond quickly. As cybercriminals implement and develop tools, methods and objectives, it is essential for SecOps teams to automate the processes of self-healing vulnerable assets and systems, mitigating risk through real-time actionable intelligence."
Aaron Sandeen, CEO di Cyber Security Works, states that "Ransomware poses a major threat to customers and employees in every industry. In 2022, we will continue to detect old and new vulnerabilities, exploit types, APT groups, ransomware families, and CWE categories. Leaders require an innovative, predictive solution to remediate threats in a timely manner."
The Ransomware Index Spotlight report is based on data collected from multiple sources, including data owned by Ivanti and CSW, public threat databases, cyberattack researchers, and penetration testing teams. To read the complete report go to the following link.






