Typically:
* Password spraying from previous data leaks
* Good old-fashioned fishing
* Bugs in anything that's common in enterprises, exposed to the Internet and not patched fast enough, including MS Exchange, various security/VPN products, vcenter, you name it. All of these had pretty critical pre-auth bugs exposed just this year
* malicious browser plugins
* malicious O365 apps
... and so on.
- ActiveX for legacy ad-hoc software
There is much confusion and many bad analogies surrounding this issue.
Some claim - without evidence - that nation states are behind it. Which, with a moments reflection, is absurd; nation states may have an interest in disabling certain systems for military purposes (at the appropriate time), but no nation state needs ransom money. Easier ways for a government to get money; namely, just print some.
Others liken it to the mafia or cartel or other well-organized criminal organizations. This too misses the mark.
Like most business crimes, the culprit is almost always an insider. Period. As the tools to pull this off are trivial to come by on the internet, the obvious suspect would be some disgruntled IT person within the company.
It’s as if — after a bank robbery — everyone claims it must have been some crack team of Russians flown in under radar in helicopters. Instead, they should be looking at the numerous employees who have access to the security system and the safe.
But, it’s much more exciting to pretend that Putin is sponsoring hackers to get trivial amounts of money from companies across the globe. Ha.
I’m not even an IT guy, but at my last job, even I had access sufficient to destroy or corrupt all the data. That was before cryptocurrency and the like... I assume assembling a ransomware set of tools off the internet is no more or less difficult than it was to assemble a set of tools to make pirated copies of AdobePhotshop back in the day.
What is money? If a government wants more domestic resources, it can get it by printing money. If a state is so limited in domestic resources that it fundamentally needs resources from outside, printing money doesn't help. Printing money can help a state devote more of its country's resources to trade, but if no one wants to trade with you at any cost, it doesn't matter what parts of the local economy the state controls.
North Korea has incentives compatible with these kinds of acts, and relatively few interesting ways of deploying software engineers locally.
Sure, this is obvious, makes intuitive sense, except...it explains why something like Iran-Contra or the equivalent in other countries can't happen.