Showing posts with label back-ups. Show all posts
Showing posts with label back-ups. Show all posts

Tuesday, June 1, 2021

Free software bi-products

 

We all like free software. We find what we want on the internet and download it. Generally, there isn’t an issue. You can download Nmap, Kali Linux, and others with no issue. There is, however, always the anomaly or edge case when there is a problem. A recent issue occurred at a medical institute.

In this instance, a student was working at a biomolecular institute in Europe. The institute happed to allow personal computers on their network. You can guess what happened next. The facility, which was not named, allowed the student on their network with the student’s personal computer. The student happened to have downloaded free software (data visualization software). A little bit of malware piggy backed its way onto the personal computer and then into the network. The student attempted to download the software, which was blocked by Windows Defender. Not taking the hint, the student disabled the service, and then downloaded the software.

Fortunately, the institute had back-ups to use. These were not fully up-to-date, but viable. Recreating a week’s worth of data is painful, but workable. As a wrinkle, the institute also had to rebuild the entity of the computer and server files prior to the data being uploaded.

This attack is a lesson in allowing unknown or tested equipment on the network. Without a NAC or other tools in place, anyone’s personal computer and all the issues associated with it are also invited into the network. There are several tools available to assist with securing this portion of network control along with policies to be implemented.

Tuesday, October 1, 2019

Bridport pwned!


Sir John Colfox Academy is a secondary school in Bridport, Dorset in the UK. The school has 828 students, aged between 11 and 18.
Attack
On a fateful work day, much like any other, a staff member received an email. This was one of the hundreds of emails received on a weekly basis. This however claimed to be a colleague at another Dorset school. Not thinking a malicious person would have sent this, the staff member opened the email and clicked on the content on February 28, 2019. While this may have seem innocent enough, the email actually appears to have been sent from China and forwarded from a server in Germany.
The click opened the door for the systems infection. The network had an issue. The malware was reported as ransomware and, as expected, immediately began to encrypt the files. The attackers, as with the next step of the ransomware playbook, demanded money to be paid to them for the decrypt key.  The school consulted with a police expert regarding the substantial issue. After a review, it was noted the attack did not likely exfiltrate any school data, and staff, student and parent data were not on the system that was breached. The research into this indicated the attack may have been part of a much larger international operation.
Data
In particular, for this case, Year 11 students submitted their coursework. This coursework was saved on the school’s network. Due to the issue, the coursework in the subject was lost. While the description is short, the devastation is significant. The hope is the student’s had this backed-up somewhere.
Mitigation
The school is working with a particular exam board to resolve the issue. They are also working with the Dorset Police cybercrime unit. Although there was a demand for funds, no payment was made. This is generally the policy to take due to the secondary potential issues with just making the payment. The school had to notify the parents and sent a letter explaining the issue.
Discussion
Targets are generally attacked to compromise their systems to gain access to data for exfiltration or to extort funds from them. In the early days, these may have been more of an exercise, however, the attackers have operationalized the model. Ransomware has proven itself to be a completely popular, viable, and successful attack tool. Over the last four years, this has been very profitable for the attackers.
Lessons Learned
Ransomware is used so often, it is becoming redundant. The frequency is mostly due to the simplicity of the attack, the financial awards, and this tends to shut down operations until the fee is paid (not advised) or the issue is remediated through installing back-ups, and a thorough review to ensure nothing was left behind by the attackers they could use later for re-entry.
There needs to be continued training for the staff. This removed a significant portion of the opportunity for an issue. If the staff know what the usual forms of the attack are, these are less likely to be clicked on, and fewer systems would be infected. There also needs to be back-ups, which are regularly checked to ensure they are viable.

Resources
Hussain, D. (2019, March 14). Secondary school is being held to ransom after a ‘chinese cyber attack’ caused the loss of year 11 student’s GCSE coursework Retrieved from https://www.dailymail.co.uk/news/article-6808845/Secondary-school-held-ransom-cyber-attack-caused-loss-students-GCSE-coursework.html

Sjouwerman, S. (2019, March 14). GSCE coursework lost in ransomware attack on UK bridport school. Retrieved from https://blog.knowbe4.com/gcse-coursework-lost-in-cyber-attack-on-uk-bridport-school

Speck, D. (2019, March 15). GCSE coursework lost in ransomware attack. Retrieved from https://www.tes.com/news/gcse-coursework-lost-ransomware-attack

Wakefield, J. (2019, March 13). GCSE coursework lost in cyber attack in bridport school. Retrieved from https://www.bbc.com/news/uk-england-dorset-47551331

Saturday, August 17, 2019

Newspaper attacked!

Although print newspapers are having issues due to the online outlets, these are still present and noticeable throughout the communities and provide a valuable service. The newspapers have not been targetted over the last few years, as frequently as others. These organizations don’t have PII or PHI to the extent others, e.g. doctor’s officed or hospitals. These also don’t have a mass amount of money laying about. While there are other more viable targets, the newspapers certainly may have their systems focussed on by the attackers. 
Incident 
When the attack was first noticed, the management termed the issue as a “glitch”. The attack ended up being detected on Saturday. Due to the attack, the organization was not able to print and deliver the Sunday paper. The attack itself was detected by the IT staff, as it affected the servers and computers had been breached by malware. This acted by encrypting the files. The malware also was infecting the systems for Tribune Publishing. 
Ransomware 
The paper was a victim of ransomware. The systems and data were encrypted. The attackers used the Ryuk ransomware. This particular version was largely successful in late 2018. Generally, the attack operates such that the files are encrypted, and a ransom is paid for the decrypt key. 
Thoughts
Ransomware can be a real nightmare for the direct victims and indirect persons affected by the organization’s lack of operations. This has the ability to encrypt an entire system and data sets. If there are no viable back-ups in place, the situation has the unfortunate ability to be very interesting for the target. This highlights the need for a properly trained incident response team. 


Resources
Hand, L. (2019, April 28). Watertown newspaper hacked, cannot print sunday edition. Retrieved from https://cnycentral.com/news/local/watertown-newspaper-hacked-cannot-print-sunday-editions 

WWNY. (2019, April 28). Watertown times attacked by malware; Sunday paper not printed. Retrieved from https://www.wwnytv.com/story/40279959/watertown-times-attacked-by-malware-sunday-paper-not-printed 

Wednesday, June 26, 2019

Genesee County Pwned!


Genesee County under attack!
-Charles Parker, II

There are vast numbers of municipalities of various sizes adjacent to each other throughout each state in the nation. Each of these obviously has a computer network, of varying sizes, in place for the day to day operations. One of these counties, in Michigan, also recently had an interesting issue. Genesee County has had much written about it, as the city of Flint is at the center of the media storm. In this county, there was recently a successful ransomware attack, unfortunately.
Attack
Ransomware has been over the last few years been exceptionally successful as an attack. The trend continues, as published repeatedly across many industries. One of these was the municipal offices of Genesee County, located in Michigan. The successful attack used one of the ransomware tools. The Genesee County Clerk stated the county servers were shut down due to this. The ransomware followed its standard protocol and encrypted the files. There naturally was a demand for money with this. Once received the attackers would provide the decrypt key. The initial forensic work indicated no files were exfiltrated, which was a good thing.

What to do?
This was a rather significant issue for the county. There were a few options for the county to follow, given the parameters of the attack. They could pay the fee and hope they would provide the decrypt key. The county would also have to hope the attackers did not leave any malware or back doors in the network. As an alternative, they could not pay the fee and use back-ups, which would require time and accurate and viable back-ups being in place prior to the attack. As the third option, do nothing and hope for the best.

The county ended up not paying the ransom. This was the safest bet as long as the county had up to date recent back-ups, which had been tested, in place. Fortunately for the county and their general fund, and their insurance company, there were adequate back-ups in place. The back-ups had been done the evening before at midnight. This indicated the data replication would be minimal. There would still be al mass amount of time, as the back-ups needed to be used to replace the encrypted data and files.

Affected
The attacks can vary in depth and width across the network, depending on the network itself and the form of ransomware. This could affect one system or the complete set of servers. In this case, nearly all of the networks in the system were affected. The county had signs in the window of the offices that the computer system was down, they were using manual systems, and the computer systems had been down for several days. The one relatively pertinent system for payroll was not, however, affected.

Forensic Work
This was a rather large project. The county contacted and had been working with the Michigan State Police and the FBI for their expertise. They may have been other third-party contractors involved.

Lessons Learned
Ransomware is a curious tool. While very devastating, it may also be viewed as being modular, in that the malicious tool may be adjusted according to the end result needed. All it takes is one employee in the wrong department to click on the wrong link. This issue did, however, show the importance of back-ups and testing them to ensure these really are backing up. This also shows there still is the distinct need for the employees to be trained.

Resources
Acosta, R. (2019, April 4). Ransomware computer virus hits county network. The Flint Journal, A1.

Ciak, M. (2019, April 4). Genesee county hacking incident ‘more extensive than initially thought’. Retrieved from Genesee County hacking incident 'more extensive than initially thought'

Dissent. (2019, April 3). Genesee county’s email system not functional after ransomware attack. Retrieved from https://www.databreaches.net/genesee-countys-email-system-not-funcitonal-after-ransomware-hack/

Olenick, D. (2019, April 5). Genesee county ransomware attack more severe than originally thought. Retrieved from Genesee County ransomware attack more severe than originally thought | SC Media

Pierret, A. (2019, April 3). Genesee county’s email system not functional after ransomware attack. Retrieved from Genesee County's email system not functional after ransomware hack

Winant, D. (2019, April 4). Servers in genesee county were hacked. Retrieved from https://www.wnem.com/news/breaking-servers-hacked-in-gen-co/


Thursday, October 18, 2018

Village Ransomwared!

Day after day, Jefferson village simply operated as they did the day before, the day before that, etc. Each day passed without anything exciting occurring. The existence was rather uneventful, which is perfectly acceptable.

Ransomware
On a fateful day, the last thing on the administration's mind was the system potentially being encrypted and a ransom requested for a decrypt key.

In late May 2018, this is what happened (http://www.starbeacon.com/news/locla-news/hackers-try-t0-hold-jefferson-computers-at-ransom/). The Village of Jefferson found themselves as victims of ransomware. The ransom request was for approximately $4,900 of bitcoin to be paid or the systems would be wiped. Curiously, two additional entities were hit at nearly the same time. All three contracted services from Steve Schoneman of Ashtabula’s Schoneman Inc.

Target
The focal point of the attack, among other areas, was a computer used for finances. Fortunately, the village actively used back-ups. These back-ups were used to re-image the systems. This sounds easy enough, however, the project did take a few days.

Lessons
This is a fantastic example of what makes back-ups, tested and verified, so very important. Granted, the fix for the situation took a bit of time, however, compared to losing the data forever or paying the ransom, this was a completely viable solution. Without the back-ups in place and verified, the village would have been in a very difficult position.