{"id":4580,"date":"2023-10-30T20:54:25","date_gmt":"2023-10-30T07:54:25","guid":{"rendered":"https:\/\/ostermanresearch.com\/2023\/10\/30\/nastiest-malware-2023\/"},"modified":"2025-03-11T06:40:24","modified_gmt":"2025-03-10T17:40:24","slug":"nastiest-malware-2023","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2023\/10\/30\/nastiest-malware-2023\/","title":{"rendered":"Nastiest malware 2023"},"content":{"rendered":"\n<p>OpenText Cybersecurity published the 2023 version of its Nastiest Malware report (sixth year). There&#8217;s a <a href=\"https:\/\/www.opentext.com\/about\/press-releases\/opentext-cybersecurity-nastiest-malware-of-2023-shows-ransomware-as-a-service-now-primary-business-model\" target=\"_blank\" rel=\"noreferrer noopener\">press release<\/a> and <a href=\"https:\/\/community.webroot.com\/threat-reports-176\/nastiest-malware-2023-355907\" target=\"_blank\" rel=\"noreferrer noopener\">report<\/a>.<\/p>\n\n\n\n<p>Key findings:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ransomware (as a category of malware) tops the nastiest list in 2023, driven by ransomware-as-a-service (RaaS) business models. This aligns with our <a href=\"https:\/\/ostermanresearch.com\/portfolio\/orwp_0355-ransomware\/\" data-type=\"jetpack-portfolio\" data-id=\"4204\">2022 report on ransomware<\/a>, in which we profiled the growing prevalence of RaaS as driving increases in ransomware attackers, attacks, and variants. In 2023, Cl0p has been particularly active.<\/li>\n\n\n\n<li>Double \/ triple extortion designs are highly devastating to organizations, because even if there is a backup to restore data, the threat of the ransomware gang publishing stolen data forces many organizations to pay the ransom.<\/li>\n\n\n\n<li>The press release says that &#8220;only 34% of businesses pay ransom, an all-time low.&#8221; In light of the double \/ triple extortion comment above, we had to think this one through. For it to be so low, the 71% of organizations that are not paying the ransom must do two things very well &#8211; firstly, have data backups to enable rapid and error-free restoration, and secondly, use strong data protection methods such as encryption so that any exfiltrated data is unreadable and won&#8217;t trigger &#8220;crisis communications and data compliance fines&#8221; (see the report for that line). With the way ransomware is going, organizations not doing both are asking for trouble.<\/li>\n\n\n\n<li>The average ransom payment, when one is made, skyrocketed to $740K (in Q2 2023). In late 2021, the average was $167K. That&#8217;s a big change, and one that OpenText attributes to the wild success of Cl0p&#8217;s exploitation of customers using MOVEit Transfer.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>OpenText Cybersecurity published the 2023 version of its Nastiest Malware report (sixth year). There&#8217;s a press release and report. Key findings:<\/p>\n","protected":false},"author":384585,"featured_media":4206,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027491,712027499,712027179],"tags":[712027520],"class_list":["post-4580","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-reports","category-malware","category-ransomware","tag-research-findings"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/01\/ransomware2022.jpg?fit=1100%2C360&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1bS","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4580","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4580"}],"version-history":[{"count":3,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4580\/revisions"}],"predecessor-version":[{"id":4763,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4580\/revisions\/4763"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4206"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4580"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4580"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4580"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}