勒索软件团伙不再针对首席执行官,而是直接锁定四十多岁的IT经理。
Ransomware gangs skip the CEO, head straight for the 40-something IT manager

原始链接: https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the-ceo-head-straight-for-the-40-something-it-manager/5284499

Zscaler ThreatLabz 近期的一份报告显示,勒索软件攻击者已不再进行无差别的攻击,而是利用针对性的“业务特权”来勒索赎金。研究人员通过分析 351 名受害者发现,攻击者将目标锁定在平均年龄 46 岁的中层管理人员,而非公司高管。 这些攻击者会进行广泛的侦察,以识别出有权影响财务和运营决策的人员,例如会计、人力资源和 IT 部门的员工。通过入侵这些中层管理人员,网络犯罪分子得以获取预算、供应商合同和支付审批系统的权限,从而有效地向公司施压,迫使其支付赎金。 该策略将“业务特权”——即授权交易或管理敏感数据的权力——置于传统的管理或技术访问权限之上。研究结果凸显了勒索软件生态系统中一个令人担忧的趋势:攻击者正日益专注于数据窃取和战略性勒索,而非单纯的加密。当勒索要求发出时,黑客往往已经摸清了组织的报告架构,以确保他们拥有足够的筹码来迫使受害者支付赎金。

Hacker News 最新 | 往期 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 勒索软件团伙不再针对首席执行官,转而直接攻击四十多岁的IT经理 (theregister.com) 11分 由 joebuckwilliams 43分钟前发布 | 隐藏 | 往期 | 收藏 | 讨论 帮助 准则 | 常见问题 | 列表 | API | 安全 | 法律 | 加入YC | 联系 搜索:
相关文章

原文

security

Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops

Turns out the fastest way to get a company to consider paying a ransom isn't calling the CEO – it's targeting the 46-year-old IT manager.

That's according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month.

The data suggests today's ransomware crews have become oddly specific about their preferred victim profile: nearly two-thirds of victims held manager-level titles or above, the average victim was a 46-year-old Gen Xer, and three-quarters worked in accounting and finance, sales, operations, HR, or marketing. Half worked in the industrial or IT sectors.

Rather than blasting the same extortion email across an organization, attackers are doing their homework first. Zscaler says they combine information from compromised systems with publicly available data to map reporting lines and identify the employees most likely to influence a company's response.

"The ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns," the security outfit wrote. "Rather than targeting executives directly, attackers are increasingly focusing on managers and other key personnel with the authority or influence to accelerate payment decisions."

That shift reflects what Zscaler calls "business privilege" rather than technical privilege. Security teams have traditionally focused on privileged users with administrator rights. Attackers, meanwhile, are after employees whose day jobs give them access to invoices, payment approvals, budgets, supplier contracts, customer accounts, HR records, or other sensitive business processes.

"The value of a compromised managerial account lies in the breadth of business access associated with the position," the researchers wrote. "Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units."

The Gen X skew is probably no coincidence either. Zscaler says many workers in their forties and fifties have reached established management positions, giving attackers access to valuable systems, sensitive information, and people with decision-making authority without needing to compromise the executive suite.

It also found more than a dozen organizations said multiple employees were  compromised during the campaign, suggesting attackers weren't content with a single foothold once inside a network. Instead, they appeared to work their way through different business functions to increase the chances of reaching valuable data and the people capable of influencing a ransom payment.

The wider report points to a ransomware ecosystem that is becoming increasingly focused on extortion rather than encryption alone. Zscaler said ransomware attempts blocked across its cloud platform increased 146 percent over the past year, while public extortion cases rose 70 percent and the volume of data stolen from victims climbed 92 percent.

By the time the ransom note lands, the crooks may already know who approves invoices, who signs contracts, who runs HR, and who reports to whom. The encryption is just the bit that victims notice. ®

联系我们 contact @ memedata.com