This page was machine-translated and may differ from the original. View original
AhnLab Announces Q1 2019 Ransomware Trends: "GandCrab Rampant, Attack Methods Diversifying"
| New ransomware samples up 48% year-over-year
| Gandcrab, WannaCry, and Venus Locker make up the majority
| Ransomware Attack Methods Become More Diverse, User Caution Needed
On the 10th, AhnLab announced ransomware trends for the first quarter of 2019.

During the first quarter of this year, the number of new ransomware samples collected increased by 48% compared to the same period last year, and the number of ransomware detections was highest for 'GandCrab' ransomware (57%).
AhnLab collected a total of approximately 340,000 new ransomware samples, including variants of existing ransomware, in the first quarter of 2019. This represents an increase of about 48% compared to the approximately 230,000 samples collected during the same period of the previous year, but a 21% decrease compared to the fourth quarter of 2018.
Among the new ransomware samples, GandCrab (66%) and WannaCryptor (27%) accounted for 93% of the total. GandCrab increased by 400% from 22,000 cases in the fourth quarter of 2018 to 111,000 cases this quarter, and WannaCrypt increased by 117% from 20,000 cases in the previous quarter to 45,000 cases this quarter.
The number of ransomware detections in the first quarter of this year increased by 84% compared to the fourth quarter of 2018. GandCrab accounted for 57% of the total detections, making it the most detected ransomware in the first quarter of this year. This was followed by WannaCry (20%), VenusLocker (9%), and CryptoLocker (8%). In particular, GandCrab-based ransomware saw a 77% increase in detections compared to the previous quarter, emerging as the most active ransomware in Korea.
GandCrab is a ransomware-as-a-service (RaaS) that is produced by a specific group through buyer orders and distributes the extorted profits. It has been continuously distributed through repeated version updates since it was first discovered in January 2018.
During the first quarter of this year, ransomware distribution methods became more diverse depending on the target. Cases were discovered in which ransomware was distributed disguised as document files such as resumes, purchase invoices, and warning letters targeting relevant personnel, and cases were also found in which ransomware was distributed targeting users with insufficient security updates by analyzing their PC environments and exploiting various vulnerabilities. In particular, cases of distribution have been discovered where attackers hijacked corporate server administrator accounts and infected subsystems within the organization with ransomware, potentially causing catastrophic damage to the company.
To prevent ransomware damage, you must follow security guidelines such as refraining from opening attachments from emails with unknown sources, maintaining the latest versions of the OS and programs and applying security patches, downloading genuine software and content, avoiding suspicious websites, and keeping antivirus software up to date and performing periodic scans.
An official from AhnLab stated, “The continuous increase in ransomware distribution means that attackers are generating revenue from it,” adding, “As the likelihood of continued ransomware spread is high due to the diversification of new ransomware creation and distribution methods, individual users and organizations need to exercise special caution.”
| Gandcrab, WannaCry, and Venus Locker make up the majority
| Ransomware Attack Methods Become More Diverse, User Caution Needed
On the 10th, AhnLab announced ransomware trends for the first quarter of 2019.

Top 10 Ransomware Detections in Q1 2019
During the first quarter of this year, the number of new ransomware samples collected increased by 48% compared to the same period last year, and the number of ransomware detections was highest for 'GandCrab' ransomware (57%).
AhnLab collected a total of approximately 340,000 new ransomware samples, including variants of existing ransomware, in the first quarter of 2019. This represents an increase of about 48% compared to the approximately 230,000 samples collected during the same period of the previous year, but a 21% decrease compared to the fourth quarter of 2018.
Among the new ransomware samples, GandCrab (66%) and WannaCryptor (27%) accounted for 93% of the total. GandCrab increased by 400% from 22,000 cases in the fourth quarter of 2018 to 111,000 cases this quarter, and WannaCrypt increased by 117% from 20,000 cases in the previous quarter to 45,000 cases this quarter.
The number of ransomware detections in the first quarter of this year increased by 84% compared to the fourth quarter of 2018. GandCrab accounted for 57% of the total detections, making it the most detected ransomware in the first quarter of this year. This was followed by WannaCry (20%), VenusLocker (9%), and CryptoLocker (8%). In particular, GandCrab-based ransomware saw a 77% increase in detections compared to the previous quarter, emerging as the most active ransomware in Korea.
GandCrab is a ransomware-as-a-service (RaaS) that is produced by a specific group through buyer orders and distributes the extorted profits. It has been continuously distributed through repeated version updates since it was first discovered in January 2018.
During the first quarter of this year, ransomware distribution methods became more diverse depending on the target. Cases were discovered in which ransomware was distributed disguised as document files such as resumes, purchase invoices, and warning letters targeting relevant personnel, and cases were also found in which ransomware was distributed targeting users with insufficient security updates by analyzing their PC environments and exploiting various vulnerabilities. In particular, cases of distribution have been discovered where attackers hijacked corporate server administrator accounts and infected subsystems within the organization with ransomware, potentially causing catastrophic damage to the company.
To prevent ransomware damage, you must follow security guidelines such as refraining from opening attachments from emails with unknown sources, maintaining the latest versions of the OS and programs and applying security patches, downloading genuine software and content, avoiding suspicious websites, and keeping antivirus software up to date and performing periodic scans.
An official from AhnLab stated, “The continuous increase in ransomware distribution means that attackers are generating revenue from it,” adding, “As the likelihood of continued ransomware spread is high due to the diversification of new ransomware creation and distribution methods, individual users and organizations need to exercise special caution.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.













