It Looks Like Chinese Cybercriminal Group APT27 May Be Shifting to Ransomware Attacks

Stu Sjouwerman | Jan 5, 2021

Ransomware AttacksThe perceived change in cyberattack tactics for this well-known group of hackers may mean more trouble as APT27’s talents usually reserved for espionage are focused on ransomware.

APT27 is a China-based hacking group that has historically been known for engaging in cyberattacks with the goal of stealing intellectual property, targeting business services, high tech, government, and energy sectors. They’ve traditionally used spear phishing as their initial attack vector, using exploits that have been made public.

The shift to focusing on ransomware makes sense from an execution standpoint; they already know phishing and they already know how to take advantage of other people’s code. So, why not skip the long drawn out process of navigating a victim network, finding valuable data, exfiltrating it, and then (presumably) selling it? Instead, focus on the attack and let ransomware be the money-making method!

And that’s exactly what it appears APT27 have done. According to analysis of the attacks by cybersecurity firms Profero and Security Joes, malware samples from attacks throughout 2020 tie the attacks on multiple organizations back to APT27.

APT27’s shift to using ransomware may indicate they are simply taking the easiest route to making money. And given they’ve already proven to be extremely talented at gaining entry into victim’s networks, this doesn’t bode well for organizations already concerned about ransomware in general.

Since APT27 is known for using spear phishing tactics, it’s imperative that organizations heighten their employee’s sense of cyber vigilance with Security Awareness Training. Without proper training, it’s far more likely potential victims will fall prey to attacks by groups like APT27.

Topics: Ransomware

Test Your Network’s Defenses with our Free Ransomware Simulator

When employees bypass guidance and fall for social engineering, your network security is the last line of defense. Run our 100% harmless RanSim tool on Windows 10+ workstations to safely simulate 25 ransomware and cryptomining infection scenarios, pinpoint technical vulnerabilities, and get your results in minutes.

Launch Your Free Ransomware Simulation

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.