Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

April 02, 2022

Ransomware is Pressuring Public Services

 

The FBI and CISA has indicated that ransomware attacks are becoming a safety risk to public services as they are attractive targets to cybercriminals due to their critical nature. Public services such as utility companies, emergency services, safety operations, healthcare and the education sector are being increasingly targeted and sensitive personal data is being stolen which is putting local residents at risk of fraud.

Local governments will see no decline in these attacks as the deployment of malware continues to evolve. The FBI explained a ransomware attack in January of this year forced a US county to take down their computer systems and enact an emergency response through their backup procedures. The county jail was targeted which meant surveillance cameras were deactivated along with the jail’s data collection capabilities, automated doors, and internet access. This obviously caused alarm amongst employees and resulted in significant safety concerns for the facility.

There are plenty of other examples too, including an attack in September 2021 that closed a county courthouse and the attackers subsequently leaked personal details of employees and residents online after the ransom wasn’t paid. And in May 2021, several local governments were infected with a ‘PayOrGrief’ ransomware attack that led to servers and online services becoming inaccessible.

Union County Government Center, North Carolina

According to the report, only academia and higher education facilities were attacked more frequently than local government services in 2021. The FBI has restated several times that victims should not pay any ransom demands because it may encourage further attacks. However, some targets decide to pay so they are able to quickly restore their services.

After paying the ransom though, restoring a network can be a complicated and long task to complete, and there is no certainty that the decryption key provided by the hackers will work or that they won’t return later. The FBI encourages all victims to report any ransomware incident to help prevent future attacks.

They have also recommended numerous cybersecurity measures [PDF] that businesses can enact to help prevent becoming a victim, including keeping software and operating systems up to date with the latest security patches, and requiring strong passwords for online accounts. This makes it harder for criminals to exploit network and system vulnerabilities and guess user passwords.

In addition, organisations should keep offline backups of their data that are regularly tested and updated so networks can be restored without decryption keys. Employees should require the use of multi-factor authentication for their webmail, accounts, and VPNs to add an additional layer of protection against such attacks.

March 30, 2022

Cybersecurity Lessons from 2021

 

SecureWorks, an incident response service provider, covered over 450 incidents last year and recently published its feedback. 85% of the incidents they responded to were financially motivated and a further 5% were seemingly government-sponsored attacks. The remaining attacks were accidental or deliberate actions of employees.

43% of the initial access gained was through threat actors exploiting vulnerabilities in internet-connected devices and credentials theft represented another 18% of initial system access. These credentials can be obtained through the dark web, brokers, credential stealing, brute-force attacks, or password spraying. In previous years, credentials theft was the number one approach to compromising a target, so the focus for security professionals needs to shift to patching vulnerabilities.

The rise in multi-factor authentication may mean that attackers are focusing on exploiting vulnerabilities that do not require authentication. Alternatively, it can be easy for an attacker to exploit proof-of-concept code that is published shortly after a vulnerability is publicly disclosed. This can lead to wide scale exploitation of any vulnerable devices in multiple targets simultaneously.

Despite ransomware attackers being increasingly imprisoned for their actions and the US government prioritising ransomware the same with it does terrorism, SecureWorks has not seen a reduction in ransomware attacks in 2021.

Many of the attacks that relied on credential theft and abuse occurred because the target organisation failed to implement multi-factor authentication mechanisms at all or properly. However, attackers have been able to bypass MFA by exploiting legacy authentication protocols (e.g. IMAP and SMTP) which are either still in use or haven’t been disabled. These protocols cannot enforce MFA and pose a significant security risk to businesses.

Security Vulnerability Exploit

Even when MFA is implemented correctly, users may still eventually decide to approve an MFA request if attackers continuously send them due to “notification fatigue”. To mitigate this issue, consider implementing MFA that request a code from the user rather than a one-click solution.

If an enterprise is using cloud solutions, carefully investigate all of the security components and controls offered by the cloud provider to ensure logging and controlled access is offered by the cloud service. It may be attractive for businesses to implement these cloud solutions, but there are security considerations that must be accounted for before moving resources online.

To prevent cyberattacks going forward, SecureWorks recommends that IT and security professional regularly perform vulnerability scans, control access carefully and make use of IP lists, monitor newly registered domains that spoof or impersonate your company, improve your backup strategies and procedures to mitigate ransomware attacks, implement MFA properly, and implement DKIM and SPF authentication for email clients to avoid fake emails being sent by attackers.

Of course, you should also ensure your systems and software and kept up to date, use the principle of least privilege for account access, and ensure you implement an endpoint detection and response solution.

March 29, 2022

Ransomware Attacker Gets Prison Sentence

 

Maksim Berezan, an Estonian national, has received a 5-year prison sentence for being involved in over 13 ransomware attacks costing victims over $53 million in losses. Berezan was part of a Russian cybercriminal forum where tools and services were regularly exchanged. He was arrested in Latvia back in 2020 and later extradited to the US where he pleaded guilty to conspiracy to commit wire fraud and conspiracy to commit access device fraud. It is believed he targeted at least 7 American businesses.

Police found Berezan had cryptocurrency wallets containing $11 million from ransom payments he had demanded during the attacks along with $200,000 in cash. Living a lavish lifestyle, the criminal had bought luxury cars, sport motorbikes, and jewellery, but he has now been court ordered to repay $36 million in restitution. 

US Department of Justice (DoJ)

The US Secret Service states this is a lesson to ransomware criminals that they are not safe and cannot easily hide from law enforcement and cybercriminal investigators no matter where they are in the world. The US DoJ partnered with the Latvian and Estonian police to help obtain the conviction.

The US Attorney for the Eastern District of Virginia stated “Ransomware attacks are devastating to people and organizations alike, and we have honed our strategies and techniques to target both the individual actors who perpetrate these attacks and the networks that support them”.