You are here
Hunting down the cyber mafia
You are the author of an article1 that considers ransomware to be a key cyber threat for individuals, enterprises, organisations, and governments. How does it work?
Jean-Yves Marion2: Ransomware is a malicious software program (or malware) designed to extort money by blocking access to systems or data, generally in exchange for payment in cryptocurrency. In concrete terms, an attack begins with an intrusion, and then spreads inside the computer system via computers, servers, telephones, routers, and other connected objects.
Attackers attempt to expand their access, and to gather and exfiltrate sensitive data; they can then encrypt all or part of systems, although some attacks are exclusively based on the threat of disclosure. The goal is not just to disrupt, but to put pressure on the victim by combining the unavailability of data with the risk of information leaks.
The world of ransomware has changed considerably in recent years. Can you explain today’s dominant model, known as Ransomware-as-a-Service (RaaS)?
J.-Y. M.: Today ransomware functions as a genuinely structured criminal ecosystem. The actors communicate and recruit through different channels, especially specialised forums or messaging services such as Telegram. We use various sources to study these environments, such as leaks within certain criminal groups, in addition to data collected on the dark web, representing dozens of millions of messages.
The Ransomware-as-a-Service model is based on extensive task specialisation. Some groups develop malicious tools, others sell compromised access to computer systems, or provide ransom negotiation. This modular structure makes these groups particularly resilient. When a service is dismantled, the rest of the ecosystem continues to function. For that matter, ransomware groups do not always carry out the attacks themselves, often relying on affiliates who are compensated according to the success of operations.
This ecosystem is also based on specialised technical services, such as Crypters-as-a-Service, whose goal is to make malware programs difficult to detect by anti-virus software and defence systems. These services use advanced obfuscation techniques to quickly generate new malware variants that can bypass defences. To follow these evolutions, we are developing Binomics, a platform that ‘sequences’ malware with a view to analysing its transformations.
Yet ransomware models are rife and extend beyond such organisations
J.-Y. M.: True, and that’s precisely what makes such phenomena difficult to analyse. Today we are seeing a diversification of actors and goals. More isolated and opportunistic actors have reappeared alongside major structured ecosystems, notably in some recent cases involving theft and data leaks.
The boundaries between cybercrime, espionage, and destabilisation have also become more porous. Some groups can act with the direct or indirect support of states. North Korea is often cited as an example of using cybercrime for financing or strategic pressure.
Finally, it has become important to no longer consider ransomware, cyber espionage, and disinformation separately from one another, as a data leak from an attack can subsequently drive campaigns of manipulation, destabilisation, and loss of confidence.
What tactics are used by ransomware operators?
J.-Y. M.: Ransomware functions quite like malware. The process begins with a reconnaissance phase to identify victims and, say, their income. Fraudsters can obtain personal information before sending a personalised phishing email to the target.
Next comes the crucial phase of entering the system. The first method involves using social engineering3 or password leaks. The second relies on vulnerability. Computer systems sometimes contain design errors that can be exploited to gain access. An advanced technique consists in accessing a software component in advance through its suppliers4. Once inside a system, the hackers launch the final phase by disactivating security, all while remaining discreet and installing backdoors to escape if needed. This allows them to push the attack even further.
Once the misdeed is done, how do organisations divide the gains?
J.-Y. M.: In the case of a well-structured group, it either receives the ransom and pays its affiliates, or vice versa. This sharing is sometimes established through contracts, which are adhered to in varying degrees. These mechanisms are always extremely difficult to analyse, for everything generally happens remotely within secret ecosystems where the absence of a framework facilitates asymmetries of information, as well as risks of fraud5.
The laundering stage seeks to reduce the traceability of transactions by using intermediaries to fragment flows and complicate their attribution.
How to protect against such organisations?
J.-Y. M.: The first line of defence is simple: keep software updated and adopt best practices, such as using a password manager. At the same time, law enforcement and the courts are working to dismantle these groups, for example through international operations targeting criminal infrastructure, their affiliates, and solitary actors.
At the Lorraine Research Laboratory in Computer Science and its Applications (LORIA), we are contributing to this effort by collaborating with law enforcement, the Ministry of Justice, and Europol. Our work is based on a systemic approach, as we develop methods for analysing, detecting, and investigating malware. We also study offensive capacities, for it is crucial to understand and anticipate the operating procedures of attackers in order to better defend against them.
However, these attacks are also connected to economic, social, and legal dynamics, which is why we are conducting interdisciplinary research with sociologists, lawyers, and criminologists to more clearly comprehend the structure and functioning of these organisations. To this end, we have set up an international school of cybercriminology6. Our observations are also based on exchanges with police services, which allows us to compare academic analyses with reality on the ground.
Could artificial intelligence transform the model for ransomware ?
J.-Y. M.: Artificial intelligence is already being used, especially in social engineering, to automate and personalise attacks such as phishing. It also helps to lower the level of technical expertise required, by facilitating some of the preparatory stages of attacks. Still, the most far-reaching transformation could come from the emergence of capable autonomous agents, which could gradually replace some of the roles performed by human affiliates today.
This evolution also represents a major research issue, and we are working on an observatory for malicious uses of AI to more firmly grasp how these technologies transform attack chains, and destabilisation strategies more generally. Today, cyberattacks no longer seek exclusively to disrupt a computer system, as a compromised system and stolen data can be exploited in influence and manipulation operations. Understanding such phenomena therefore calls for combining multiple approaches – computing, social, informational, and geopolitical – to analyse the entire chain, from computer intrusion to cognitive exploitation within the informational space.
Further reading
Ransomware: research strikes back
One software, billions of possibilities
- 1. Jean-Yves Marion, “Ransomware: Extortion Is My Business,” Communications of the ACM, 2025: https://doi.org/10.1145/3697829
- 2. Professor at Université de Lorraine and member of the Lorraine Research Laboratory in Computer Science and its Applications (LORIA – CNRS / Université de Lorraine).
- 3. With regard to ransomware, social engineering involves psychologically manipulating a user to have that person execute the action that triggers the infection.
- 4. When an attack is conducted on the software supply chain, a pirated application running on a computer or telephone can carry along with it a series of other software programs known as “libraries”. When the application starts up on a device, all of the data is exfiltrated. This subject is currently being addressed by the Cyber Resilience Act, a European regulation that calls on enterprises to identify everything running in their system – both software and hardware – with a view to strengthening the cybersecurity of digital products marketed within the European Union.
- 5. Observations show that Crypter-as-a-Service markets are characterised by high risks of fraud, leading to the implementation of informal regulation mechanisms. More specifically, sellers must provide a security deposit to access transactions, in order to compensate buyers in the event of non-compliant service.
- 6. See: https://cybercriminology-nancy.fr
Explore more
Author
Specializing in themes related to religions, spirituality and history, Matthieu Sricot works with various media, including Le Monde des Religions, La Vie, Sciences Humaines and even Inrees.












