Connect with us

Published

on

As the ransomware industry evolves, experts are predicting hackers will only continue to find more and more ways of using the technology to exploit businesses and individuals.

Seksan Mongkhonkhamsao | Moment | Getty Images

Ransomware is now a billion-dollar industry. But it wasn’t always that large — nor was it a prevalent cybersecurity risk like it is today.

Dating back to the 1980s, ransomware is a form of malware used by cybercriminals to lock files on a person’s computer and demand payment to unlock them.

The technology — which officially turned 35 on Dec. 12 — has come a long way, with criminals now able to spin up ransomware much faster and deploy it across multiple targets.

Cybercriminals raked in $1 billion of extorted cryptocurrency payments from ransomware victims in 2023 — a record high, according to data from blockchain analysis firm Chainalysis.

Experts expect ransomware to continue evolving, with modern-day cloud computing tech, artificial intelligence and geopolitics shaping the future.

How did ransomware come about?

The first event considered to be a ransomware attack happened in 1989.

A hacker physically mailed floppy disks claiming to contain software that could help determine whether someone was at risk of developing AIDs.

However, when installed, the software would hide directories and encrypt file names on people’s computers after they’d rebooted 90 times.

It would then display a ransom note requesting a cashier’s check to be sent to an address in Panama for a license to restore the files and directories.

The program became known by the cybersecurity community as the “AIDs Trojan.” 

“It was the first ransomware and it came from someone’s imagination. It wasn’t something that they’d read about or that had been researched,” Martin Lee, EMEA lead for Talos, the cyber threat intelligence division of IT equipment giant Cisco, told CNBC in an interview.

“Prior to that, it was just never discussed. There wasn’t even the theoretical concept of ransomware.”

The perpetrator, a Harvard-taught biologist named Joseph Popp, was caught and arrested. However, after displaying erratic behavior, he was found unfit to stand trial and returned to the United States.

How ransomware has developed

Since the AIDs Trojan emerged, ransomware has evolved a great deal. In 2004, a threat actor targeted Russian citizens with a criminal ransomware program known today as “GPCode.”

The program was delivered to people via email — an attack method today commonly known as “phishing.” Users, tempted with the promise of an attractive career offer, would download an attachment which contained malware disguising itself as a job application form.

Once opened, the attachment downloaded and installed malware on the victim’s computer, scanning the file system and encrypting files and demanding payment via wire transfer.

Then, in the early 2010s, ransomware hackers turned to crypto as a method of payment.

Ransomware attacks could get worse next year, says TrustedSec's David Kennedy

In 2013, only a few years after the creation of bitcoin, the CryptoLocker ransomware emerged.

Hackers targeting people with this program demanded payment in either bitcoin or prepaid cash vouchers — but it was an early example of how crypto became the currency of choice for ransomware attackers.

Later, more prominent examples of ransomware attacks that selected crypto as the ransom payment method of choice included the likes of WannaCry and Petya.

“Cryptocurrencies provide many advantages for the bad guys, precisely because it is a way of transferring value and money outside of the regulated banking system in a way that is anonymous and immutable,” Lee told CNBC. “If somebody’s paid you, that payment can’t be rolled back.”

CryptoLocker also became notorious in the cybersecurity community as one of the earliest examples of a “ransomware-as-a-service” operation — that is, a ransomware service sold by developers to more novice hackers for a fee to allow them to carry out attacks.

“In the early 2010s, we have this increase in professionalization,” Lee said, adding that the gang behind CryptoLocker were “very successful in operating the crime.”

What’s next for ransomware?

'Fully acceptable' now that you have to use AI in your cyber defense, Darktrace's Mike Beck says

Some experts worry AI has lowered the barrier to entry for criminals looking to create and use ransomware. Generative AI tools like OpenAI’s ChatGPT allow everyday internet users to insert text-based queries and requests and get sophisticated, humanlike answers in response — and many programmers are even using it to help them write code.

Mike Beck, chief information security officer of Darktrace, told CNBC’s “Squawk Box Europe” there’s a “huge opportunity” for AI — both in arming the cybercriminals and improving productivity and operations within cybersecurity companies.

“We have to arm ourselves with the same tools that the bad guys are using,” Beck said. “The bad guys are going to be using the same tooling that is being used alongside all that kind of change today.”

But Lee doesn’t think AI poses as severe a ransomware risk as many would think.

“There’s a lot of hypothesis about AI being very good for social engineering,” Lee told CNBC. “However, when you look at the attacks that are out there and clearly working, it tends to be the simplest ones that are so successful.”

Targeting cloud systems

A serious threat to watch out for in future could be hackers targeting cloud systems, which enable businesses to store data and host websites and apps remotely from far-flung data centers.

“We haven’t seen an awful lot of ransomware hitting cloud systems, and I think that’s likely to be the future as it progresses,” Lee said.

We could eventually see ransomware attacks that encrypt cloud assets or withhold access to them by changing credentials or using identity-based attacks to deny users access, according to Lee.

Geopolitics is also expected to play a key role in the way ransomware evolves in the years to come.

“Over the last 10 years, the distinction between criminal ransomware and nation-state attacks is becoming increasingly blurred, and ransomware is becoming a geopolitical weapon that can be used as a tool of geopolitics to disrupt organizations in countries perceived as hostile,” Lee said.

“I think we’re probably going to see more of that,” he added. “It’s fascinating to see how the criminal world could be co-opted by a nation state to do its bidding.”

Another risk Lee sees gaining traction is autonomously distributed ransomware.

“There is still scope for there to be more ransomwares out there that spread autonomously — perhaps not hitting everything in their path but limiting themselves to a specific domain or a specific organization,” he told CNBC.

Lee also expects ransomware-as-a-service to expand rapidly.

“I think we will increasingly see the ransomware ecosystem becoming increasingly professionalized, moving almost exclusively towards that ransomware-as-a-service model,” he said.

But even as the ways criminals use ransomware are set to evolve, the actual makeup of the technology isn’t expected to change too drastically in the coming years.

“Outside of RaaS providers and those leveraging stolen or procured toolchains, credentials and system access have proven to be effective,” Jake King, security lead at internet search firm Elastic, told CNBC.

“Until further roadblocks appear for adversaries, we will likely continue to observe the same patterns.”

Continue Reading

Technology

Amazon considers displaying tariff surcharge on low-cost Haul products

Published

on

By

Amazon considers displaying tariff surcharge on low-cost Haul products

Packages with the logo of Amazon are transported at a packing station of a redistribution center of Amazon in Horn-Bad Meinberg, western Germany, on Dec. 9, 2024.

Ina Fassbender | Afp | Getty Images

Amazon is considering showing a tariff surcharge on items sold via its site for ultra-low-price items, called Haul, the company confirmed to CNBC.

“The team that runs our ultra low cost Amazon Haul store has considered listing import charges on certain products,” an Amazon spokesperson said in a statement. “This was never a consideration for the main Amazon site and nothing has been implemented on any Amazon properties.”

Punchbowl News reported earlier on Tuesday that Amazon would “soon” begin displaying the cost of tariffs alongside the price of each product, citing a source familiar with the company’s plans.

The report drew the ire of the White House, which called Amazon’s reported plans a “hostile and political act.”

This is breaking news. Please refresh for updates.

Continue Reading

Technology

Alibaba launches new Qwen LLMs in China’s latest open-source AI breakthrough

Published

on

By

Alibaba launches new Qwen LLMs in China’s latest open-source AI breakthrough

Qwen3 is Alibaba’s debut into so-called “hybrid reasoning models,” which it says combines traditional LLM capabilities with “advanced, dynamic reasoning.”

Sopa Images | Lightrocket | Getty Images

Alibaba released the next generation of its open-sourced large language models, Qwen3, on Tuesday — and experts are calling it yet another breakthrough in China’s booming open-source artificial intelligence space.

In a blog post, the Chinese tech giant said Qwen3 promises improvements in reasoning, instruction following, tool usage and multilingual tasks, rivaling other top-tier models such as DeepSeek’s R1 in several industry benchmarks. 

The LLM series includes eight variations that span a range of architectures and sizes, offering developers flexibility when using Qwen to build AI applications for edge devices like mobile phones.

Qwen3 is also Alibaba’s debut into so-called “hybrid reasoning models,” which it says combines traditional LLM capabilities with “advanced, dynamic reasoning.”

According to Alibaba, such models can seamlessly transition between a “thinking mode” for complex tasks such as coding and a “non-thinking mode” for faster, general-purpose responses. 

“Notably, the Qwen3-235B-A22B MoE model significantly lowers deployment costs compared to other state-of-the-art models, reinforcing Alibaba’s commitment to accessible, high-performance AI,” Alibaba said. 

The new models are already freely available for individual users on platforms like Hugging Face and GitHub, as well as Alibaba Cloud’s web interface. Qwen3 is also being used to power Alibaba’s AI assistant, Quark.

China’s AI advancement

AI analysts told CNBC that the Qwen3 represents a serious challenge to Alibaba’s counterparts in China, as well as industry leaders in the U.S.  

In a statement to CNBC, Wei Sun, principal analyst of artificial intelligence at Counterpoint Research, said the Qwen3 series is a “significant breakthrough—not just for its best-in-class performance” but also for several features that point to the “application potential of the models.” 

Those features include Qwen3’s hybrid thinking mode, its multilingual support covering 119 languages and dialects and its open-source availability, Sun added.

Open-source software generally refers to software in which the source code is made freely available on the web for possible modification and redistribution. At the start of this year, DeepSeek’s open-sourced R1 model rocked the AI world and quickly became a catalyst for China’s AI space and open-source model adoption.  

“Alibaba’s release of the Qwen 3 series further underscores the strong capabilities of Chinese labs to develop highly competitive, innovative, and open-source models, despite mounting pressure from tightened U.S. export controls,” said Ray Wang, a Washington-based analyst focusing on U.S.-China economic and technology competition.

According to Alibaba, Qwen has already become one of the world’s most widely adopted open-source AI model series, attracting over 300 million downloads worldwide and more than 100,000 derivative models on Hugging Face. 

Wang said that this adoption could continue with Qwen3, adding that its performance claims may make it the best open-source model globally — though still behind the world’s most cutting-edge models like OpenAI’s o3 and o4-mini.  

Chinese competitors like Baidu have also rushed to release new AI models after the emergence of DeepSeek, including making plans to shift toward a more open-source business model. 

Meanwhile, Reuters reported in February that DeepSeek is accelerating the launch of its successor to its R1, citing anonymous sources.

“In the broader context of the U.S.-China AI race, the gap between American and Chinese labs has narrowed—likely to a few months, and some might argue, even to just weeks,” Wang said. 

“With the latest release of Qwen 3 and the upcoming launch of DeepSeek’s R2, this gap is unlikely to widen—and may even continue to shrink.”

Continue Reading

Technology

Uber raises in-office requirement to 3 days, claws back remote workers

Published

on

By

Uber raises in-office requirement to 3 days, claws back remote workers

Uber on Monday informed employees, including some who had been previously approved for remote work, that it will require them to come to the office three days a week, CNBC has learned. 

“Even as the external environment remains dynamic, we’re on solid footing, with a clear strategy and big plans,” CEO Dara Khosrowshahi told employees in the memo, which was viewed by CNBC. “As we head into this next chapter, I want to emphasize that ‘good’ is not going to be good enough — we need to be great.”

Khosrowshahi goes on to say employees need to push themselves so the company “can move faster and take smarter risks” and outlined several changes to Uber’s work policy.

Uber in 2022 established Tuesdays and Thursdays as “anchor days” where most employees must spend at least half of their work time in the company’s office. Starting in June, employees will be required in the office Tuesday through Thursday, according to the memo.

That includes some employees who were previously approved to work remotely. The company said it had already informed impacted remote employees.

“After a thorough review of our existing remote approvals, we’re asking many remote employees to come into an office,” Khosrowshahi wrote. “In addition, we’ll hire new remote roles only very sparingly.”

The company also changed its one-month paid sabbatical program, according to the memo. Previously, employees were eligible for the sabbatical after five years at the company. That’s now been raised to eight years, according to the memo. 

“This program was created when Uber was a much younger company, and when reaching 5 years of tenure was a rare feat,” Khosrowshahi wrote. “Back then, we were in the office five (sometimes more!) days of a week and hadn’t instituted our Work from Anywhere benefit.”

Khosrowshahi said the changes will help Uber move faster. 

“Our collective view as a leadership team is that while remote work has some benefits, being in the office fuels collaboration, sparks creativity, and increases velocity,” Khosrowshahi wrote.

The changes come as more companies in the tech industry cut costs to appease investors after over-hiring during the Covid-19 pandemic. Google recently began demanding that employees who were previously-approved for remote work also return to the office if they want to keep their jobs, CNBC reported last week.  

Last year, Khosrowshahi blamed remote work for the loss of its most loyal customers, who would take ride-sharing as their commute to work. 

“Going forward, we’re further raising this bar,” Khosrowshahi’s Monday memo said. “After a thorough review of our existing remote approvals, we’re asking many remote employees to come into an office. In addition, we’ll hire new remote roles only very sparingly.”

Uber’s leadership team will monitor attendance “at both team and individual levels to ensure expectations are being met,” Khosrowshahi wrote. 

Following the memo, Uber employees immediately swarmed the company’s internal question-and-answer forum, according to correspondence viewed by CNBC. Khosrowshahi said he and Nikki Krishnamurthy, the company’s chief people officer, will hold an all-hands meeting on Tuesday to discuss the changes.

Many employees asked leadership to reconsider the sabbatical change, arguing that the company should honor the original eligibility policy.

“This isn’t ‘doing the right thing’ for your employees,” one employee commented.

Uber did not immediately respond to a request for comment.

WATCH: Lightning Round: Uber goes higher from here, says Jim Cramer

Continue Reading

Trending