In March of this year, Boeing was hit by a WannaCry ransomware attack, nearly a year after the virus first broke out on a large scale. This incident made the cybersecurity industry feel as if it had fallen into a time warp. Although the 'resurrection' of ransomware surprised some, security researchers have been tracking its evolution since WannaCry was released.

"Things haven't gotten better," Alexander Heid, Chief Research and Development Officer at SecurityScorecard, told CIO Dive in an interview.

According to Heid, WannaCry exploited the EternalBlue vulnerability from the Shadow Brokers toolkit and targeted specific versions of Windows systems. But since last year's attack, multiple variants have emerged, such as weaponized EternalBlue and EternalRed targeting Linux systems.

Today, attackers bundle the vulnerabilities used in WannaCry with common system flaws, such as those in Apache Struts and Oracle WebLogic. Instead of deploying ransomware, they use exploit kits and shift to a more lucrative activity: cryptocurrency mining.

Ransomware's 'Close Relative': Cryptocurrency Mining

Cybercriminals are known for 'working smart' rather than 'working hard.' Automating more attacks and targeting vulnerable targets can yield quick returns. Attackers have also followed the cryptocurrency boom, but rather than trading or short-selling, they have turned to malicious mining.

"We are clearly observing attackers shifting from ransomware to cryptocurrency mining, especially toward ASIC-resistant cryptocurrencies," said Craig Williams, Senior Threat Researcher and Global Outreach Manager at Cisco Talos.

ASICs are computer hardware designed to execute specific tasks quickly, often used in cryptocurrency mining. Mining with a home computer is not profitable, especially considering the cost of specialized hardware. But according to Williams, cryptocurrencies like Monero are designed to be ASIC-resistant and offer anonymity and untraceability.


Cryptocurrency mining offers "a steady return of about a quarter dollar per compromised machine, so if attackers have a large enough botnet, they can earn hundreds of thousands of dollars a year with almost no real risk."

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Craig Williams

Senior Threat Researcher and Global Outreach Manager at Cisco Talos


Williams said: "The clear trend we see is that adversaries are turning to cryptocurrencies like Monero because it offers a steady return. As long as the cryptocurrency market remains high, they will continue to pursue this steady return, because it is almost imperceptible to end users, meaning the risk from law enforcement is almost zero."

Cryptocurrency mining also has a bigger advantage: minimal disruption to end users and it is largely unnoticed. Mining programs are designed to consume only a small fraction of a system's total power to remain stealthy. Users can still operate their machines normally and hardly notice that malicious actors are stealing a small amount of computing power.

According to Heid, a virus called MassMiner is a more covert way to generate revenue, and some organizations have profited up to $2.4 million by attacking web servers and enterprises.

Williams said: "From an attacker's perspective, there is no risk. Each compromised machine brings a steady return of about a quarter dollar, so if they have a large enough botnet, they can earn hundreds of thousands of dollars a year with almost no real risk."

In contrast, ransomware offers smaller one-time gains but carries greater risk because attackers hinder victims' ability to operate. However, industries that tend to pay ransoms—such as healthcare and manufacturing—may still be targeted because of the higher rate of ransom payment.

Although using viruses for mining may seem harmless, the risk is latent when cryptocurrencies are highly profitable and prices are high. Heid said: "Once mining becomes unprofitable and it is more lucrative to return to traditional cybercrime vectors, such as DDoS attacks, we are likely to see these infections used for more destructive purposes."

From WannaCry to NotPetya to... What's Next?

Cybersecurity researchers and threat analysts are quick to admit that their work becomes quite interesting during global cyber incidents. Finding the root cause of an incident and helping organizations respond quickly is like a game of cat and mouse.

But at first glance, the industry seems due for another global incident. Heid said: "In reality, there is more malicious activity happening now, and whenever there is any type of global social unrest or major decision, there is also a huge spike in malicious activity."

Although Olympic Destroyer is less well-known than WannaCry and NotPetya, its attack on the Winter Olympics in February makes it another successor to last year's incidents. Williams said that while it may not necessarily come from the same group, its method of operation is "a type of malware designed to destroy data."


"In reality, there is more malicious activity happening now, and whenever there is any type of global social unrest or major decision, there is also a huge spike in malicious activity."

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Alexander Heid

Chief Research and Development Officer at SecurityScorecard


What makes Olympic Destroyer special is that it carried multiple false flags designed to blur attribution and confuse researchers. This should serve as a warning to organizations.

Williams said that from a business perspective, "our adversaries are very openly and deliberately framing each other, making software-based attribution impossible."

Putting state politics aside, malicious actors examine the cybercriminal underground economy and pursue the best return on investment. While cryptocurrency mining is currently the trend, the market could shift again.

For enterprises, the only hope is faster and better patch management. Otherwise, they will continue to suffer destructive and preventable cyberattacks.