Report: CryptoWall Creators Earned $325 Million in Bitcoin Ransoms

A new report looks at the CryptoWall ransomware and its components in an attempt to analyze its success.

Oct 30, 2015 at 9:00 p.m. UTC
Updated Sep 11, 2021 at 11:58 a.m. UTC

A cyber-security industry group has published new research on the CryptoWall ransomware campaign, finding that the attacks have generated more than $300m in ransom income and stem from a single source or entity.

The report was published earlier this week by the Cyber Threat Alliance, founded by Intel Security, Symantec, Palo Alto Networks and Fortinet. Major takeaways from the organization’s research include evidence of as much as $325m worth of ransomware victim payments and more than 400,000 attempts to infect computers with the third variant of CryptoWall (CW3), many of which appear to have focused on targets in North America.

Backing the idea that the ransomware is sourced to a single entity is evidence found in both the code as well as the web of bitcoin payments trackable on the public blockchain. The report notes that Armenia, Belarus, Iran, Kazakhstan, Russia, Serbia and Ukraine are blacklisted, meaning the malware won’t operate in those regions and suggesting possible points of origin.

The report’s authors add that an analysis of bitcoin transactions tied to known ransom campaigns points to the common use of bitcoin wallets across those campaigns, stating:

"As a result of examining this financial network, it was discovered that a number of primary wallets were shared between campaigns, further supporting the notion that all of the campaigns, regardless of the campaign ID, are being operated by the same entity."

The bitcoins accrued – known ransom demands range from the hundreds to thousands of dollars, according to the report – are then washed through multiple addresses and known bitcoin services, though none are named directly in the report. Some of the funds are essentially reinvested in new exploit kits or rent payments for botnets.

Revenue-wise, the report’s authors note that, for its backers, CryptoWall "is extremely successful and continues to provide significant income".

"One variant alone involved with the 'crypt100' campaign identifier resulted in over 15,000 victims across the globe," the report states. "These 15,000 victims alone would account for, at minimum, roughly $5m in profit for the CW3 group."

Read the full report below:

Image via Shutterstock

The Festival for the Decentralized World
Thursday - Sunday, June 9-12, 2022
Austin, Texas
Save a Seat Now

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.

Trending

1
CoinDesk - Unknown
5 Key Takeaways From a16z's State of Crypto Report

The venture firm is extremely bullish on Web 3.

The venture firm is extremely bullish on Web 3.

CoinDesk - Unknown
2
CoinDesk - Unknown
Regulators Are Paying Attention to UST

The collapse of terraUSD (UST) is algorithmic stablecoins’ Libra moment.

The collapse of terraUSD (UST) is algorithmic stablecoins’ Libra moment.

CoinDesk - Unknown
3
CoinDesk - Unknown
San Francisco NFL Player Alex Barrett Taking His Salary in Bitcoin

The most valuable crypto stories for Thursday, May 20, 2022.

The most valuable crypto stories for Thursday, May 20, 2022.

CoinDesk - Unknown
4
CoinDesk - Unknown
Justin Sun Still Thinks Algorithmic Stablecoins Are a Good Idea

The crypto mogul also said LUNA and UST might make good "meme coins," he said on CoinDesk TV’s “First Mover.”

The crypto mogul also said LUNA and UST might make good "meme coins," he said on CoinDesk TV’s “First Mover.”

CoinDesk - Unknown