Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

26 February 2026

Another Medical System Ransomware Attack

I'm old enough to remember when Obama told us that computerizing all of our medical records would make everything better. It may have had that impact overall, but it also introduced some side effects. Mississippi hospital system closes all clinics after ransomware attack

I haven't written about ransomware in some time. Not really a conscious decision, it just hasn't been bubbling to the top of my news feed. And for the most part, corporate C-suites have been sufficiently hit over the head to take security at least a bit seriously. But you apparently still can't tell doctors how to do they jobs, not even the part that are information technology related.

Ransomware attacks against public schools and agencies have proliferated in recent years. They have shutdown 911 dispatch functions and exposed sensitive student data, among other harms.

Doctors and lawyers don't take too well to being told what to do, though to be fair, I've never worked with or for doctors. Public schools are typically spending money on things that don't matter, and there is little to no fallout for the people who run them. (Can you fire a public school administrator? Probably easier than firing a public school teacher, but not easy.)

And this kind of ransomware attack has real world impacts.

Richard Bell, 55, drove three hours from his home in Oxford the medical center’s main campus in Jackson on Friday only to learn that he wouldn’t be able to get his bloodwork or chemotherapy treatment.

“It was all shut down,” Bell said. “It gets pretty frustrating.”

The FBI is involved, and the medical system is restoring (trying?) to restore.

The one thing I've noticed is that the press, even the tech press, almost never reports on how the system in question was compromised. Was it a phishing attack that someone fell for, or a technical defect in their security that was penetrated? Inquiring minds...

05 October 2023

Google Ads Still a Vector for Malware

In this case ransomware. ‘Snatch’ Ransom Group Exposes Visitor IP Addresses

And you should never install software that you find via an ad. Certainly not by clicking on the ad. Because how do you know if it is legit? If you want a piece of software, go and search for it, and install it from a recognized place.

And remember: "There ain't no such thing as a free lunch."

The victim shaming site operated by the Snatch ransomware group is leaking data about its true online location and internal operations, as well as the Internet addresses of its visitors, KrebsOnSecurity has found. The leaked data suggest that Snatch is one of several ransomware groups using paid ads on Google.com to trick people into installing malware disguised as popular free software, such as Microsoft Teams, Adobe Reader, Mozilla Thunderbird, and Discord.
First spotted in 2018, the Snatch ransomware group has published data stolen from hundreds of organizations that refused to pay a ransom demand. Snatch publishes its stolen data at a website on the open Internet, and that content is mirrored on the Snatch team’s darknet site, which is only reachable using the global anonymity network Tor.

Be safe out there. Me? I use a couple of ad-blockers, so that this kind of thing mostly isn't an issue.

03 September 2021

Ransomware and Holidays

When people are out of the office, for extended periods, bad guys have more time to encrypt PCs. FBI, CISA: Ransomware attack risk increases on holidays, weekends

The two federal agencies said they "observed an increase in highly impactful ransomware attacks occurring on holidays and weekends—when offices are normally closed—in the United States, as recently as the Fourth of July holiday in 2021."

Aside from that, enjoy the 3-day weekend!

08 August 2021

Got Disgruntled Employees? Ransomware Gang Recruiting Insiders

This is an interesting escalation, though I doubt people will be able to keep their involvement secret. LockBit ransomware recruiting insiders to breach corporate networks

With LockBit 2.0, the ransomware gang is trying to remove the middle-man and instead recruit insiders to provide them access to a corporate network.

People are not good at operational security on any level. If they suddenly got a million-dollar payoff I think someone might notice. And that is the kind of payday they are apparently offering.

While this tactic may sound far-fetched, it is not the first time threat actors attempted to recruit an employee to encrypt their company's network.

Click thru for the details.

01 August 2021

DarkSide Ransomware Returns as BlackMatter

Did anyone (aside from some bureaucrats in Washington, DC) really think that the people behind DarkSide were going to go sit on a beach? DarkSide ransomware gang returns as new BlackMatter operation

DarkSide disappeared in May, after the very visible attack on Colonial Pipeline which caused fuel shortages, and brought all kinds of heat. Now they are back.

Encryption algorithms found in a decryptor show that the notorious DarkSide ransomware gang has rebranded as a new BlackMatter ransomware operation and is actively performing attacks on corporate entities.

Click thru for the details on how that determination was made.

But again, are we surprised? Bleeping computer has found one incident where DarkMatter was paid $4 million this week. Did we think a group of determined bad guys was going to walk away from that kind of payday? Especially after that is about the amount the FBI managed to confiscate after the Colonial Pipeline hack.

Ransomware is going to get worse, before it gets better. PrintNightmare, Serious SAM, an attack on the Security Account Manager, and an attack on the NT LAN Manager. All that makes it somewhat easy to get into a system, or escalate privleges once you are in. That doesn't even touch on WordPress, and its plugin ecosystem. There are problems there.

11 July 2021

Governments Not Taking Security Seriously - German Edition

It sounds as if they are just throwing in the towel. Rural German district declares disaster after cyberattack

Why do I get the feeling that in some meeting, a manager said (in German), "We're so small; no one will attack us." Right before he denied some expenditure on security.

Local officials confirmed the crime on Friday, saying, "This attack directly affects the entire range of the district's services, including the business of its citizens, which cannot be processed at the moment."

On Saturday, a spokesman for the district told Reuters news agency, "We are almost completely paralyzed."

Officials say the attack occurred on Tuesday and that the district will likely be forced to remain offline for at least a week, leaving it unable to pay out welfare benefits to recipients or finance youth programs.

No mention of backups, or other mitigations. And they didn't identify who the attackers were.

This isn't the 1st German disctrict to be attacked; they are just the first to declare a disaster. (Let's them get a payout from the federal government.)

And it is worth repeating. If your backups are accessible via the network, then they are not backups. Not for the purposes of ransomware. Look up Offline.

06 July 2021

A Day May Come When Companies Take Security Seriously

But today is not that day. Kaseya: Roughly 1,500 businesses hit by REvil ransomware attack

Kaseya makes remote management software for Managed Service Providers, companies hired to manage systems and servers who can't be bothered to manage their own. (How's that working out?)

Now that isn't a problem, as long as the MSPs and their customers and the software vendors all get things right.

Things are not as bad as they could have been.

Of the approximately 800,000 to 1,000,000 local and small businesses that are managed by Kaseya’s customers, only about 800 to 1,500 have been compromised.

Though the REvil group is claiming that a great many more businesses have been encrypted.

And the FBI and The Cybersecurity and Infrastructure Security Agency (CISA) have provided guidance. CISA, FBI share guidance for victims of Kaseya ransomware attack .

This is the bit that caught my attention.

  • Enable and enforce multi-factor authentication (MFA) on every single account that is under the control of the organization, and—to the maximum extent possible—enable and enforce MFA for customer-facing services.
  • Implement allowlisting to limit communication with remote monitoring and management (RMM) capabilities to known IP address pairs

There are more recommendations, but I can't quote the whole thing.

If you are not following these guidelines - like Multifactor Authentication - already, start. What's that you say? It is "inconvenient?" Really? How inconvenienced do you think these victims of ransomware feel right now?

26 June 2021

A Day My Come When Governments Take Security Seriously

But today is not that day. Tulsa warns of data breach after Conti ransomware leaks police citations

In early May, Tulsa suffered a ransomware attack that led to the City shutting down its network to prevent the spread of the malware. [SNIP]

However, yesterday the Conti Ransomware gang claimed responsibility and published 18,938 of the City's files, mainly police citations and internal Word [documents].

They are telling people to be aware of scams and to "monitor their credit," but they are offering no help. They are not offering the standard 1-year of a credit-monitoring service.

17 May 2021

Colonial Pipeline - It's Not My Fault!

On a topic dear to my heart, American Conservative takes executives to task for being idiots. Why is a Billion Dollar Pipeline Incapable of Defending Itself Against Ransomware?

In the aftermath of the pipeline shutdown, the whole emphasis has been on obfuscation.

When reading a story like this a telltale sign of spy handiwork is the noticeable use of the word “sophisticated.” That is, the victims were on the receiving end of “the most sophisticated cyber weapon ever deployed.” Gasp!

The unspoken benefit of this hyperbole is that it offers a degree of cover for decision makers. They can sanctimoniously hold their heads up high and claim “What could we possibly have done? The attackers were nation-state actors who were so skillful and crafty that no one could possibly expect to defend against them.” Pointing at themselves: “Especially me.”

In other words: not my fault.

Ransomware is not a new threat. It has become so commonplace, that in the absence of large scale fallout, as happened in this case, Steve Gibson, of Security Now has stopped covering it. It is a common background element of the world we live in. Or as American Conservative points out...

Ransomware is a pervasive threat. Any chief information officer worth his salt will have the foresight to deploy the controls necessary to sufficiently raise the cost of attacks as well as limit the damage that they incur—particularly when it comes to protecting the American infrastructure.

But there are 2 problems.

  1. Executives don't understand Information Technology, Cryptography, Hacking, Ransomware, etc.
  2. Executives don't like to spend money on stuff they don't understand.

And so they don't spend money to make sure that networks are protected, to update software in a timely fashion, whatever. And so we get Colonial Pipeline and a bunch of spin-doctoring. Anyway, click thru and read the whole thing.

04 December 2020

Your Tax Dollars at Work: Pennsylvania Edition

Because after ALL of this time, they haven't gotten security controls in place. Pennsylvania county pays 500K ransom to DoppelPaymer ransomware.

"The County of Delaware recently discovered a disruption to portions of its computer network. We commenced an immediate investigation that included taking certain systems offline and working with computer forensic specialists to determine the nature and scope of the event. We are working diligently to restore the functionality of our systems," the Delaware County alert stated.

And the attack was somewhat insane.

BleepingComputer was also told that the ransomware gang advised Delaware County to change all of their passwords and modify their Windows domain configuration to include safeguards from the Mimikatz program.

Mimikatz has been around for a couple of years, and instructions on how to defend against it can be found around the net. There is a link at the bottom of the article linked above.

So, if you aren't defending against KNOWN attacks, that are available for download from Github, exactly WHAT are you defending against?

There is no mention of insurance, and I would not underwrite this mess, but then I'm not in the insurance industry. Surely they can't underwrite every bad practice everywhere. That would be like making payments to people who purposefully destroy their own homes or cars.

So do you think that the county in question will be asking for a tax increase?

02 December 2020

Baltimore County Schools Hit with Ransomware

It causes a week's interruption to classes. Baltimore County Students, Staff Rush To Make Sure There Are No Lingering Ransomware Issues On Devices After Cyberattack

All Baltimore County Public Schools closed last Wednesday after the school system was hit with a ransomware cyber attack. The district said its entire network system was inaccessible after an unknown actor took over and demanded ransom.

I checked several sources and it does NOT appear that BCPS paid the ransom. If they did, they are being surprisingly tight-lipped about it.

The usual platitudes by bureaucrats who know next to nothing about tech. One said "that system appears to be fine." Of course it probably looked fine on Tuesday afternoon and on Wednesday morning. It wasn't fine.