Showing posts with label Emotet. Show all posts
Showing posts with label Emotet. Show all posts

Friday, March 22, 2019

Woesnotgone Meadow; March 21, 2019


All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Most towns of a certain size have some form of a Chamber of Commerce. Although the Meadow does not have a vast number of businesses, there are quite a few. Jerry is the president and keeps everything running smoothly. Our little municipality has not been targeted for an attack, thankfully. Other Chamber of Commerce departments have not been that lucky. The Ann Arbor/Ypsilanti Regional Chamber of Commerce is located in the southeastern section of the lower peninsula of Michigan. They manage all of the usual tasks a chamber of commerce would.

On January 8, 2019, their computer system was successfully attacked. The attackers used well-known Emotet malware. This iteration allowed the attackers access to customer names, mailing addresses, and emails. The attackers, fortunately, did not have access to banking information, accounts, credit cards, security codes, or passwords.

 Emotet is a curious piece of malware. This is coded to especially evade detection, embed itself into the system and multiply. If the malware detects it is in a sandbox, it is coded to remain dormant. This is also polymorphic, meaning each time it is downloaded, the malware changes slightly, to evade a standard anti-virus signature. As this was designed so well, it is no wonder this is still in use over the last five years.

To remediate the issue, and get the Chamber back up and running, they had to start somewhere. The Chamber began researching what happened with this and on January 24, 2019 sent a notice to its members regarding the successful attack and compromise. In the least, this is an opportunity to learn from this and improve training for the staff. As a reminder, any training does not need to be bland, and not encourage the users to become bored.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Afana, D. (2019, January 24). Malware hits ann arbor/ypsilanti chamber, member information safe, officials say. Retrieved from https://www.mlive.com/news/ann-arbor/2019/01/malware-hits-ann-arborypsilanti-chamber-member-information-safe-officials-say.html

Stockley, M. (2019, January 25). Fighting emotet: Lessons from the front line. Retrieved from https://nakedsecuriyt.sophos.com/2019/01/25/fighting-emotet-lessons-from-the-front-line/


Tuesday, February 12, 2019

Woesnotgone Meadow; December 20, 2018


All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

In the Meadow, the one service we don’t have on-ground is a University. The Meadow does have an extension office where we can take certain classes and there’s always the online option. These institutions have a plethora of data on the students, which could be targeted. The colleges also hold a significant amount of money from the student’s tuition and other sources. There is a college in the northeast which experienced a successful attack.

Cape Cod Community College is located in West Barnstable, Massachusetts. There are approximately 4,900 students, 68 full-time faculty, and 159 full-time staff. The college offers associate degrees.

The college did experience a breach. The attackers used for their tool a phishing campaign. With this mode of attack, the human element continues to be the greatest vulnerability. As noted previously, phishing continues to be a very effective method to attack an organization, especially the medium- and large-sized organizations. The phishing emails contained malware. This was coded to avoid their anti-virus (AV) and anti-malware programs. This was coded to exploit their banking relationships. With this incident, the funds were transferred from their account at TD Bank to other banks.

Mechanically, the attackers “allegedly” set up a phishing site which appeared to be the college’s bank by overwriting the bank’s URL. The attackers also social engineered the bank workers to get the transfers to clear in a timely manner. The attackers were able to have nine separate validated transfers. Three others were blocked.

Altogether, $807,130 was stolen from the college. This was a significant amount as their operating budget was approximately $35M. On a positive note, they were able to recover $278,887. With the attackers, the target was money, not personally identifiable information (PII). There was no evidence that PII or any employee records were compromised. Other operation centers were not affected.

When the attack was discovered, the college identified the malware and replaced the infected hard drives. The malware used for this attack was believed to be the Emotet banking Trojan. The college is continuing on with their plan to install the next-generation endpoint protection software (AppGuard). The college is also continuing with cybersecurity training for their staff. Due to the nature of the attack, the college did contact the state and federal authorities to assist with the investigation. While doing forensic work, other attacks were detected.

This should be another example of the potential effects from a simple click on a link or file.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Cape Cod Today Staff. (2018, December 7). Breaking-Data breach at cape cod community college. Retrieved from https://www.capecodtoday.com/article/2018/12/07/243699-Breaking=data-Breach-Cape-Cod-Community-College

Cyware. (2018, December 11). Cape cod community college was hit by hackers who stole over $800,000. Retrieved from https://cyware.com/news/cape-cod-community-college-was-hit-by-hackers-who-stole-over-800000-aef6345c

Dissent. (2018, December 8). Hackers steal $800,000 from cape cod community college. Retrieved from https://www.databreaches.net/hackers-steal-800000-from-cape-cod-community-college/

Gatlan, S. (2018, December 10). $807,130 stolen by hackers after cape cod community college phishing attack. Retrieved from https://news.softpedia.com/news/807-130-stoeln-by-hackers-after-cape-cod-community-college-phishing-attack-524208.shtml

Gurubaran, S. (2018, December 12). Hackers steal over $800,00 by dropping malware on cape cod community college computer systems. Retrieved from https://gbhackers.com/hackers-steal-cape-cod-community/

Krantz, L. (2018, December 7). Hackers steal $800,000 from cape cod community college. Retrieved from https://www.bostonglobe.com/metro/2018/12/07/hackers-steal-from-cape-cod-community-college/

MCormick, C. (2018, December 8). More than $800k stolen in data breach at cape cod community college. Retrieved from https://www.capecodtimes.com/news/20181208/more-than-800k-stolen-in-data-breach-at-cape-code-community-college

Nation, J. (2018, December 11). Sophisticated phishing attack costs cape cod community college over $800,000. Retrieved from https://medium.com/metacert/sophisticated-phishing-attack-costs-cape-cod-community-college-over-800-000-33717f502cd

Panettieri, J. (2018, December 11). Ernst & young investigates cape cod community college hack. Retrieved from https://www.msspalent.com/cybersecurity-news/ey-investigates-cape-cod-community-college-hack/

Radolec, M. (2018, December 11). Hackers steal $800,000 from cape cod community college through phishing. Retrieved from https://www.informationsecuritybuzz.com/expert-comments/hackers-steal-800000/




Tuesday, January 8, 2019

Woesnotgone Meadow; December 14, 2018


Woesnotgone Meadow
December 14, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

Here in the Meadow, we haven’t had too many cybersecurity incidents. Possibly we just aren’t on anyone’s radar...yet. Two towns in Alaska have not been this lucky lately though. These attacks crippled the operations of the towns. Having your PC or smartphone infected, and not functioning is disruptive enough. Having two town’s infrastructure down is certainly not a pleasant experience.

Matanuska-Susitna, Alaska
The incident occurred on July 23, 2018. The compromise caused the town’s operations to shut down. This disrupted the city services and slowed any productivity to a snail’s pace. This also affected Valdez, also in Alaska. The affected systems shut down were for the libraries, swimming pools, e-commerce, the local landfill, animal care, and collections. In addition, the phone systems and door lock card swipe systems were partially disabled. These were located in 73 different buildings.

A devastating effect from the attack involved the email system. After a careful review, it appeared this was not completely recoverable. The attack affected 60 of the Windows 7 PCs initially. When IT began to try and remove the malware, it spread to nearly all of the 500 workstations and 120 of the 150 servers. Although not specifically addressed, it appears this was set to spread once the remediation activity started.

The servers were a victim of ransomware. All of the Windows-based production servers were encrypted. The attackers appear to have done the appropriate level of reconnaissance, as this even affected the back-up and Disaster Recovery (DR) servers. In theory, these should have not been affected as these were engineered and configured to not be vulnerable to the known attacks and exploits. The attackers used the BitPaymer ransomware tool and Emotet Trojan. These leveraged the zero-day attacks. These had apparently been on the system since at least May 3, 2018, with an exploit date of July 23, 2018.

The staff was forced to use a pen, paper, and typewriters. It sounds as though they had a very bad day. The end goal for the attack may not have been totally financial. Due to the robust and well-thought-out nature of the attack, there may have been more involved. To remediate the issue, the borough began to reimage from the back-ups. A portion of these were a year old.

Financially, this attack was rather serious. The total estimated cost was $1.4M to restore the systems and servers. For a town, this is a massive amount. Thankfully, the borough did have $1M of insurance.

Valdez, Alaska
The Alaskan municipalities appear to be viable and continued targets. The city of Valdez was successfully attacked. The Valdez attack was so thorough, the staff was reduced to working with pen and paper. The initial symptom was a few glitches in the system, ranging from not being able to login to accounts to other issues. A few viruses were found at this point, as the attack began on July 25-26, 2019. The issue became significantly worse on Friday with a Police Department website outage. This blossomed until nearly all of the systems had to be shut down, including the phone, email, finance, and payroll. This infected 27 of their servers and 170 computers.

The underlying issue was ransomware. The attack was indeed robust, however, the resident’s personal information did not appear to be compromised. The city contracted with a firm from Virginia for a forensic review. To be proactive, the city is working to have a better method for upgrades and tracking changes. In the short-term, the city did pay the ransom (4 bitcoin, or $26,623.07 at the time) for the decrypt key.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.


Resources
Cimpanu, C. (2018, July 31). BitPaymer ransomware infection forces alaskan town to use typewriters for a week.Retrieved from https://www.bleepingcomputer.com/news/security/bitpayment-ransomware-infection-forces-alaskan-town-to-use-typewriters-for-a-week/

Cimpanu, C. (2018, November 21). City of valdez, alaska admits to paying off ransomware infection. Retrieved from https://www.zdnet.com/article/city-of-valdez-alaska-admits-to-paying-off-ransomeware-infection/

Crawley, K. (2018, September 18). Ransomware cripples an alaskan town. Retrieved from https://blog.comodo.com/comodo-news/ransomware-cripples-an-alaskan-town/

Dunn, J.E. (2018, August 3). Alaskan borough dusts off their typewriters after ransomware crims pwn entire network. Retrieved from https://www.theregister.co.uk/2018/08/03/alaskan-town-has-entire-network-owned-by-ransomware-crims/

Kirby, D. (2018, November 18). Four bitcoin for your data: How a roll of the dice by the city of valdez paid off after a cyber attack. Retrieved from https://www.ktuu.com/content/news/City-of-Valdez-paid-four-bitcoin-ransom-to-recover-data-after-July-cyber-attack-500564211.html

Rogers, J. (2018, August 1). Alaskan borough dusts off typewriters after ransomware attack. Retrieved from https://www.foxnews.com/tech/alaskan-borough-dusts-off-typewriters-after-ransomware-attack

Schroeder, S. (2018, August 2). Ransomware attack forces town’s employees to go back to typewriters. Retrieved from https://mashable.com/article/malware-alaska-town/#edAoW3zC80zX

Sowells, J. (2018, November 25). Valdez city, alaska, the newest victim of ransomware to pay for decryption. Retrieved from https://hackercombat.com/valdez-city-alaska-the-newest-victim-of-ransomware-to-pay-fordecryption/

The Associated Press. (2018, July 28). Virus shuts down city computers in valdez. Retrieved from https://www.usnews.com/news/best-states/alaskan/articles/2018-07-28/virus-shuts-down-city-computers-in-valdez

VanWagenen, J. (2018, August). An alaskan municipality suffers a devastating ransomware attack. Retrieved from https://statetechmagazine.com/article/2018/08/alaska-municipality-suffers-devaststing-ransomeware-attack


Weber, S. (2018, August 1). The valdez star-Serving prince william sound and copper river basin. Retrieved from https://www.valdezstar.net/story/2018/08/01/main-news/hacked-by-cybercriminals-city-website-downed-by-ransomware/1987.html