Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Tuesday, June 29, 2021

Sturdy Memorial Hospital-Not so much

 

Hospitals continue to be targeted at an inappropriate rate over the last five years. Other industries have just as valuable data as the medical field, however, hospitals are in the news at a higher rate. One aspect of this driving the attacks is the criticality of the services. The hospitals require access to the data (e.g., patient charts) and networks to perform the operations, both planned and emergency, procedures, and simply to see patients. The high-level data flow for this is quite simple. In the alternative, the system may be breached, and patient data exfiltrated. The ransom may be demanded as a promise to not distribute or sell this data to other unauthorized parties.

Therefore ransomware, in this circumstance is so potent. Also, the patient data is very important to both parties, the hospital and patient. The hospital must report the breach in most instances. The patient, depending on the data itself, may have the pleasure of monitoring their accounts and credit report for decades.

With the exfiltrated data, the hospital generally has two options. They may or may not pay the ransom to keep the data from being sold to other unauthorized parties. Paying the ransom usually is not recommended. The thought, in this case, after the money is received, they would release it anyway. While this has occurred in a limited number of times over the last few years, this is a detriment to the business model and the malware industry. If the organization is reasonably certain the data will be published anyway, there is absolutely no reason to pay a penny. In this instance Sturdy Memorial Hospital did pay the ransom or fee. The amount was not disclosed. As a result of the breach, the hospital mailed letters to the effected parties. As part of the response, the incident was reported to the FBI.

While the attack vector was not noted, the incident is representative of the reach ransomware has. Dependent on the malware strain, all it can take is one person clicking the wrong link. We still need additional training to limit the potential for this to happen elsewhere.

That was an expensive click

 

Everyone needs or is required to have insurance. This may take the form of auto, health, dental, short- or long-term disability care, or any of the other types of insurance. It seems as though if there is a need, you can find insurance for it. One of the largest commercial insurance carriers in the US is CAN. While being one of the largest insurance carriers in the nation certainly is a success to be applauded, this also has the tendency to put a target on you. After all, when a company is this huge, there is a literal mountain of data to target, and the company certainly has deep pockets to pay a ransom, if they so choose.

Recently CNA had the pleasure of working through an incident much like this. Ironically, CNA sells cyber insurance. In this case, the attackers were able to compromise CNA’s system. Post-breach, they were able to encrypt over 15K of the company’s devices using Phoenix Crypto Locker, a variant of Hades. This variant is engineered to encrypt the files on the compromised machines and demand a ransom for the decrypt key. The group, Evil Corp, was paid the ransom by CNA.

For everyone and organizations that believe “This can’t happen to me!”, yes it can. If CNA who has a vast number of resources and even sells the insurance for this type of incident can be successfully attacked, you certainly can also.

Friday, June 25, 2021

Police Departments Continue to be Targeted

 

Police departments are interesting. In business operations, you have business data, customer data, and other points to secure. Police departments do have their operational information but these places also hold a treasure trove of data on the crimes in their area (i.e. evidence). This can be on the persons arrested, the crime, crime scene, and associated data. In addition, the police provide critical service for the area they serve.

Due to these factors, police departments have and continue to be targeted. If simply breaking in isn’t enough of an effort, encrypting or exfiltrating their data can be costly to the department. The Azusa police department recently felt the ransomware sting as the department fell victim to this.

The department announced on May 28, 2021 the issue as being compromised by the ransomware attack. The attackers gained access to the data located in the department’s systems. The department did not pay any ransom or fee. The details have not been provided. From the published information, the ransom was based on releasing information versus encrypting the systems.

The data accessed does appear to be PII, unfortunately. In this case, the attackers appear to have access the social security numbers, driver license numbers, California identification numbers on financial accounts or health insurance. The police department recommended to the parties effected to monitor their credit reports, statements for their accounts, and other information for any unusual or suspicious activity.

This is another example of the far-reaching effects of ransomware. Granted the police department was not affected much, however, the persons permanent and long-term information was. If the data was used for unauthorized purposes, correcting this can be difficult and time consuming, not to mention frustrating.

 

Thursday, June 24, 2021

Here we go again; another ransomware pwnage

 

I remember the days of cameras, purchasing color film or if you wanted to be artsy, using the black & white film. There were several different manufacturers to choose from for the film. With time and technology, there has been a shift from the physical medium to digital. One firm still in the industry is FujiFilm. FujiFilm is probably the best known for its photography equipment. Curiously the company also manufactures a range of medical products. As a large firm, there is ample data gathered everyday from customer interactions, business operations, and other aspects of the business cycle. This provides for a substantial target.

It appears that FujiFilm was targeted and successfully attacked. This was evidenced by the company shutting down a portion of the network and disconnecting this from any external contact. It appears this was de to a ransomware attack.

This continues to be an issue across many industries. With the ease of use for ransomware tools and simply using encryption to accomplish the successful attack, this will likely continue and grow.

 

 

Tuesday, June 1, 2021

Ransomware around the world

 

Everyone needs insurance. This takes various forms, from life, health, disability, and other forms. One firm in this industry is AXA S.A. This is a global firm with vast reach. A huge company of this size certainly has ample data to target. A portion of the network had been attacked with ransomware.

One May 9, 2021 AXA S.A. announced the company policy was not to pay the ransom when there would be a successful ransomware attack. At that point, the company may have created a bit more attention than intended for itself. The company, interestingly enough, was a victim of ransomware right after this. The target was one of its Asia Assistance Divisions. In this case, the division’s information technology services were adversely impacted for Thailand, Malaysia, Hong Kong, and the Philippines and their data accessed. Allegedly, the Avaddon ransomware group was responsible for the successful attack. During the attack, apparently 3TB of data were exfiltrated. This included ID cards, passport, copies, customer claims, reserved agreements, denied reimbursements, payments to customers, contract and reports, customer IDs, bank account scanned papers, hospital and doctor reserved material (private investigation for fraud, and customer medical reports, including HIV, hepatitis, STD, and other illness reports).

Sometimes it is better to just remain in obscurity.

Sunday, November 29, 2020

UK flooring firm pwned

 


Attackers are always looking for new targets to attack. With the vast expanse of the internet, the field is ripe with people and businesses with data or operations to leverage for a fee. A company acknowledged its issue in late November 2020. Headlam Group, a UK flooring group distributor based in Birmingham, experienced a successful attack, acknowledged on November 24. The attackers were able to exfiltrate data as part of the attack. The attackers were able to access the system’s back end, including their email system. The company was able to restore its email system for usage. Fortunately, the company’s customer and supplier information was accessed. The company did not disclose the method the attackers used, however, this was effective. We can learn from their unfortunate issue. All the attackers need is one vulnerability or user to click on one link or picture, while the blue defensive team has to work to patch everywhere possible, monitor the threat feeds for the latest attacks, think through various attacks that could occur, and secure the data at rest.

 

 

PLEASE contact us when we may be of assistance with embedded systems cybersecurity architecture, validation, and penetration testing. We have a full lab ready to perform.

Charles Parker, II; Principal Scientist; MBA/MSA/JD/LLM/PhD/DCS (IP)

charlesparkerii@gmail.com

810-701-5511

Sunday, June 14, 2020

Municipalities targeted: City of Florence pwned!


Municipalities have a very distinct problem. They are frequently targeted for ransomware and other attacks, as the attackers know their systems generally are not fully secure unless they been recently successfully attacked and have corrected and mitigated the issues. This is driven by budgetary constraints, not allowing the city, county, etc. to be able to hire exceptional talent, purchase the tools needed in a timely manner, and other requisite uses for cybersecurity. While this is a Catch-22, it leaves these organizations in the wind, hoping to be obscure enough so that they are not noticed and attacked. Even a failed attack can have negative effects on the operations for many reasons.

 

One of these targeted was the city of Florence, located in Alabama. Florence, much like the city in Italy, sounds like an amazing place to live, located on the banks of the Tennessee River with many festivals and other attractions. This is not a massive metropolis, with nearly 40k residents. Of all the places to target, you have to wonder why Florence?

 

Attack

As you can guess, the city’s computer system had been successfully attacked. The entry points were through the email system. Specifically, this was a phishing attack, and the unfortunate phishee was Steve Price, the IT Manager. His credentials were acquired as part of the attack. The phishing email was one of the many samples of the DHL email, where there are dozens of email recipients, all receiving the same package with the same tracking number on the same day. These emails are pretty obvious as to what they really are there for.

 

The illustrious, yet distinguished Brian Krebs notified the mayor’s office of their system’s compromise on May 26. From the published accounts, the city somehow did not know of the breach prior to this. This is odd, as seemingly someone in the IT Department maybe should have noticed a strange IP address accessing the system and pulling data from the network. The following day the System Administrator did contact Mr. Krebs to let him know the computer and network account affected has been isolated and is not in service. It appears the SysAdmin did not quite understand the capabilities of the attackers at this point. On June 5, 2020, the attackers finished deploying the ransomware and began their demand for the ransom payment. The city has 12 days to fully defend against the attack, however, unfortunately only did a part of the work required to address the issue.

 

When the city began to review the situation, it did not appear any of the affected system’s data had been deleted or exfiltrated. This was probably a little too optimistic for the city.

 

On a side note, the attack occurred while the IT department was attempting to have the City Council approved the expense for a third party to do a penetration test of the IT systems.

 

Ransom

The attackers are not going to work through the attack cycle for practice and their mental gymnastics in an attack. The system has been operationalized into a business, and a rather profitable one measured by the return on investment (ROI). In this case, the attackers were DoppelPaymer. The attackers have demanded the ransom $378k in bitcoin. The amount was negotiated down to $330k by a third-party firm, still in bitcoin. This does seem like a rather large sum, given the size of the city. The attackers, however, have realized the power of their leverage on the systems.

 

Post-Attack

Once the city had the opportunity for a quick review, the city’s IT department and a third-party, contracted by the city (Arete Advisors), began to adequately investigate the issue. As time had passed and more effort was placed into the investigation, the city realized the attackers may have at least a portion of the data on the affected systems. The city noted they just don’t know. One would presume they had sufficient access, such that if they wanted, they could have taken the data they wanted to. On this note, the investigation noted the attackers had access beginning in early May 2020 and continued this for nearly the remainder of the month. During this time, the attackers had free access to roam about and check out the network. They did borrow without authorization the personal information on the city’s employees and customers.

 

As the city saw the writing on the wall, the city council voted unanimously to pay the ransom. The funds were to be paid from the insurance fund available for these types of issues.

 

A curious point with this is the city required the attackers, DoppelPaymer, to provide proof they will delete the stolen information they have. The curiosity is, other than promising or a pinky-swear, there really isn’t a way to prove they will delete the data. This is one of the many problems with paying the ransom. The organization is depending on the attackers to follow through and not leave a back-door or recurring malware on the system. Historically, the attackers have followed through and have not left any surprises behind for later easier attacks. They say there is honor among thieves, however, I would not bet on it. The city naturally is also working with law enforcement in the matter.

 

Update

As of June 13, 2020 (10:46 EST), the online network was down. While the website did note an apology, no reason was given.

 

Afterthought

If you are management, SysAdmin, or on the cybersecurity team, please consider this occurrence or any of the thousands of other successful ransomware attacks as examples of why training and an adequate SIEM is so important. While cybersecurity is the focus of the cybersecurity department or team, it is still everyone’s job to be vigilant and not be click-happy. If they aren’t expecting an email, don’t know the person or organization it is from, or it simply leaves them wondering if the link or attachment is appropriate, don’t do it. This will save so much time, energy, frustration, etc. for the staff and budget.

 

Resources

Associated Press. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://www.newsobserver.com/news/business/article243452091.html

 

Associated Press. (2020, June 12). Alabama city to pay $30,000 ransom in computer system hack. Retrieved from https://www.securityweek.com/alabama-city-pay-300000-ransom-computer-system-hack

 

Brown, M., & Delinski, B. (2020, June 11). City of Florence out nearly $300,000 after ransomware hack. Retrieved from https://www.waff.com/2020/06/11/city-florence-out-nearly-after-ransomware-hack/

 

City of Florence. (n.d.). Florence, alabama. Retrieved from https://florenceal.org/

 

Delinski, B. (2020, June 11). Florence pays nearly $300,000 in bitcoin ransom. Retrieved from https://www.timesdaily.com/news/local/florence-pays-nearly-300-000-in-bitcoin-ransom/article_5dd1200e-58f6-53a5-a3e1-5d7b90edf179.html

 

Erazo, F. (2020, June 10). Alabama city plans to pay ransomware group despite warnings. Retrieved from https://cointelegraph.com/news/alabama-city-plans-to-pay-ransomware-group-despite-warnings

 

Freedman, L. (2020, June 12). Alabama city hit with ransomware. Retrieved from https://www.jdsupra.com/legalnews/alabama-city-hit-with-ransomware-40970/

 

Goud, N. (2020, June). Ransomware attackers demanding $300,000 from florence city of alabama. Retrieved from https://www.cybersecurity-insiders.com/ransomware-attackers-demanding-300000-from-florence-city-of-alabama/

 

Jackson, J. (2020, June 10). City of Florence agrees to pay nearly $300,000 ransom after cyberattack. Retrieved from  https://whnt.com/news/shoals/city-of-florence-agrees-to-pay-nearly-300000-ransom-after-cyberattack/

 

Krebs, B. (2020, June 9). Florence, Ala. Hit by ransomware 12 days after being alerted by KrebsOnSecurity. Retrieved from https://krebsonsecurity.com/2020/06/florence-ala-hit-by-ransomware-12-days-after-being-alerted-by-krebsonsecurity/

 

Lincoln Journal Star. (2020, June 11). Alabama city to pay $300,000 ransom in computer system hack. Retrieved from https://journalstar.com/business/alabama-city-to-pay-300-000-ransom-in-computer-system-hack/article_70114db5-92bd-5ecb-9a5e-edf5f3cf3b24.html

 

Paganini, P. (2020, June 12). City of Florence to pay $300,000 ransom after ransomware attack. Retrieved from  https://securityaffairs.co/wordpress/104666/breaking-news/city-of-florence-ransomware.html

 

SANS. (2020, June 12). Newsletters: Newsbites. Retrieved from https://www.sans.org/newsletters/newsbites/xxii/47

 

Schwartz, M.J. (2020, June 12). City pays ransom despite pre-ransomware outbreak hack alert. Retrieved from https://www.bankinfosecurity.com/city-pays-ransom-despite-pre-ransomware-outbreak-hack-alert-a-14427

 

 

 


Thursday, May 28, 2020

Spartans compromised: MSU breached


Michigan State University (MSU), located in East Lansing, Michigan, is one of the premier institutions in the Midwest. This is a 5,300-acre campus with 563 buildings, with nearly 20,000 cares throughout Michigan used for agricultural and natural resources research and education. In Fall 2019, there were 49,809 students. With such a large number of students, the amount of data generated by the students and administration staff is massive year after year. This data, including the confidential data from the students, provided a significant target for the attackers. This proved to draw these persons to the University’s servers and data.

Attack
Ransomware has been a nasty part of our environment from the last few years. This is a good attack tool due to its low operational overhead and potential large payoff. With this mode, it simply takes the right person in the right department to click on the malware or link. Unfortunately for MSU, the tool was used against the university successfully. The attackers were able to breach the network, access the targeted data, and exfiltrate this. The attackers have demanded a ransom to be paid within a week of the successful attack or they will publish the stolen files. If the university happens not to pay the ransom, the attackers are willing to leak the documents.

Data
The university believes, but is not certain, that the breach and subsequent intrusion was to one (1) isolated unit on the campus. While this is a good thing, the breach itself is still an issue. The files included student, e.g. passport scans, and other private, confidential data, along with university financial documents.

Attackers
The attackers apparently used Netwalker, sometimes referred to as Mailto, ransomware. The ransomware variant was coded to attack the enterprise, in comparison to individual user stations. With this ransomware variant, once the clock runs down to zero, the data and the decrypt key are automatically published.

Mitigation

This is a rather significant issue. There is a prominent university pwned, and their data is being held for ransom. After this was detected, the IT Department took offline the affected systems and servers. This was done to prevent further exposure. MSU’s IT Department notified law enforcement, including the MSU Police Department and Michigan State Police, of the successful attack and threats to begin the investigation.

The latest successful attack is yet another clear indication that we need more cybersecurity training that is relevant. Without this, these attacks will continue to be successful and cause an abundance of harm to the organization, staff, and other parties as part of the collateral damage.

Resources
Cimpanu, C. (2020, May 28). Michigan state university hit by ransomware gang. Retrieved from https://www.zdnet.com/article/michigan-state-university-hit-by-ransomware-gang/

Dissent. (2020, May 28). Michigan state hit by ransomware threatening leak of student and financial data. Retrieved from https://www.databreaches.net/michigan-state-hit-by-ransomware-threatening-leak-of-student-and-financial-data/

Freed, B. (2020, May 27). Michigan state hit by ransomware threatening leak of student and financial data. Retrieved from https://edscoop.com/michigan-state-hit-by-ransomware-threatening-leak-of-student-and-financial-data/

Guzman, W. (2020, May 28). Michigan state target of ransomware attack threatening to release university data. Retrieved from https://statenews.com/article/2020/05/michigan-state-target-of-ransomware-attack-threatening-to-release-university-data?ct=content_open&cv=cbox_latest

Marowski, S. (2020, May 28). Ransomware attack threatens to release stolen Michigan state university files. Retrieved from https://www.mlive.com/news/jackson/2020/05/ransomware-attack-threatens-to-release-stolen-michigan-state-university-files.html

Michigan State University. (n.d.). MSU facts. Retrieved from https://msu.edu/about/thisismsu/facts.php

Friday, February 7, 2020

Attacked down under: Hospitals pwned!


In our lifetimes, we may visit the hospital two or three times, or more. With the medical facilities, they require data and information to operate. This is presently in the form of EHR and EMR (electronic health records and electronic medical records). These allow the doctors to complete their tasks, nurses to pass medications, physical therapists to provide therapy, etc. Without the services being available, there is a mortal danger. There were a number of hospitals attacked in 3Q2019 whose operations were affected.
Targets
For this set of attacks, the medical facilities were located in the Australian state of Victoria. In particular, this affected two large health systems. These were the Gippsland Health Alliance and South West Rural Health Alliance (SWARH). SWARH provides health care services for approximately 23k square miles. This range is from West Melbourne to the border of south Australia. While this is substantial, this also affected Barwon Health, a regional network in the Geelong region, and West Gippsland Healthcare Group. Overall, at least seven major hospitals were breached. There were also unfortunately, other servers across the state compromised during this set of attacks. The hospitals needed to segregate and disconnect systems to stop the wave of compromised systems. In effect, the hospitals quarantined the systems from the internet.
Attack
The hospitals were already prepped to some extent for cyber-attacks. While this is the case, the attackers were able to bypass the security controls which were already in place. The means for this was ransomware. This has become an epidemic in the industry. Through the attack, they were able to gain unauthorized access. The ransomware was used, as with the myriad of other attacks, to encrypt the hospital’s respective files. The attacks focused on patient booking and financial systems. The attack was designed to bring down their operations. With any patient booking system that is down, unless you have the next few days or weeks printed, you can’t know for certain what appointments are in the future, or the types of procedures. Due to this, the hospitals were not able to plan for the operations. Without the financial system able to be used, the hospital could not pay salaries or bills. Their budgeting processes would not work, and the finance department also would not be able to ensure the departments are within their spending limits. As of 10/2/2019, there was no specific ransom demanded.
Effects
At least one hospital was forced to resort to using pen and paper systems for booking appointments and procedures. During the outage, the hospitals were not able to access patient histories, charts, images, and other data. This did not affect every department and bypassed the emergency departments.
Data
The press release stated there was no evidence the personal patient information had been accessed. The data, however, is timeless. This could be used for years to come by the unauthorized parties.
Remediation
While this successful attack is significant, the hospitals and other affected systems were assisted by the Victorian Cyber Incident Response Service and the Australian Cyber Security Center. The management for the Victorian Government Cyber Incident Response Service recommended not paying the ransom. This is generally the best route for the breached organizations.

Resources
Australian Associated Press. (2019, September 30). Systems shut down in victorian hospitals after suspected cyber attack. Retrieved from https://www.theguardian.com/australia-news/2019/oct/01/systems-shut-down-in-victorian-hospitals-after-suspected-cyber-attack

Department of Premier and Cabinet. (2019, September 30). Cyber health incident. Retrieved from https://www.vic.gov/au/cyber-health-incident

Gatlan, S. (2019, October 1). U.S. and Australian hospitals targeted by new ransomware attacks. Retrieved from https://www.bleepingcomputer.com/news/security/us-and-australian-hospitals-targeted-by-new-ransomware-attacks/

Goodin, D. (2019, October 1). Ransomware forces three hospitals to turn away all but the most critical patients. Retrieved from https://arstechnica.com/information-technology/2019/10/hamstrung-by-ransomware-10-hospitals-are-turning-away-some-patients/

Hattersley-Gray, R. (2019, October 1). New ransomware attacks hit U.S., Australian hospitals. Retrieved from https://www.campussafetymagazine.com/news/new-ransomware-attacks-hit-u-s-australian-hospitals/

Kirk, J. (2019, October 2). Australian medical facilities hit by ransomware. Retrieved from https://www.govinfosecurity.com/australian-medical-facilities-hit-by-ransomware-a-13167


Thursday, January 23, 2020

Ransomware in Canada-Olympia Pwned


Olympia Financial Group is a publicly-traded corporation in Canada under OLY. The Olympia Financial Group Inc. does most of the business operations through Olympia Trust Company. The Olympia Trust Company manages self-directed registered accounts, works with foreign currency exchanges, and various corporate shareholder services. Olympia Financial Group sells private health care plans through its wholly-owned subsidiary Olympia Benefits Inc. Clearly, there is much activity in the office individually and in total with all of the entities. With all of this activity with the entities, there certainly is a mass amount of data that the companies would need to operate. This activity made the entities a fair target.
Attack
The businesses were a victim of a successful ransomware attack. This was announced on 2/2/2019. The attackers were able to gain access and encrypt the data on Olympia’s network. This only affected a part of the network, fortunately. Once the issue was detected, Olympia addressed the issue. This manifested itself with preventing any additional infection into the network. They contacted the Royal Canadian Mounted Police (RCMP) Cybercrime Division and contracted with malware response and recovery industry specialists.
Post-Attack
Through the dedicated efforts of the staff, the business did recover. As of 2/3/2019, all of the businesses were up and running. Nearly all of the IT systems affected by the attack were operating. The investigation into the attack continues. There was no evidence their client’s personal information was compromised. They will continue to explore and implement ways to protect the business and its client’s personal data.
Thoughts
Ransomware continues to be a rather significant issue. This has the potential for devastating effects. Luckily for Olympia Financial, the spread of the infection was contained. This continues the need for employee training for ransomware and other attacks. With the level of devastation, ransomware has the ability to do, businesses need this training. This training cannot just be the annual security training, where people get the deer in the headlights looks or start playing on their phones. This needs to be through the year and interactive to be effective.

Resources
Bloomberg. (2019, February 20). OLY-Toronto stock quote. Retrieved from https://www.bloomberg.com/quote/OLY:CN
Olympia Financial Group Inc. (2019, February 11). Olympia financial group inc. announces recovery from ransomware cyber attack. Retrieved from https://globenewswire.com/news-release/2019/02/11/1716817/0/en/Olympia-Financial-Group-Inc-announces-Recovery-from-Ransomware-Cyber-Attack.html
Reuters. (2019, February). Brief-Olympia financial group inc. announces recovery from ransomware cyber attack. Retrieved from https://ca.investing.com/news/stock-market-news/briefolympia-financial-group-inc-announces-recovery-from-ransomware-cyber-attack-1396461


Sunday, January 5, 2020

Ransomware paid in Jackson County!

Ransomware is a nightmare for business. All it takes is one user in the targeted department and the workday becomes very interesting, very quickly. One set of targets are the government units throughout the states. This includes massive cities, towns, counties, and other units. These entities have limited resources, which seem to be diminishing relatively every year. A recent successful attack occurred against Jackson County in Georgia. Jackson County is located in southeast Georgia, approximately 60 miles from Atlanta.
Ransomware
Ransomware, unfortunately, is everywhere. This is executed at different levels with the basic variants and much more advanced with many more functions. Clearly, there was a breach. The staff began to notice an issue when computers, services, websites, and email addresses ceased operating on March 1st. The county let the public know on March 5 there was an issue. On March 6, the county posted their email system was down with a Facebook post. It took them a few days to understand what had happened. In particular, this attack was rather advanced, using the Ryuk ransomware strain. This was coded to sever their online communications in addition to the usual symptoms. This shut down their entire computer and internet network. The county in the interim had to do everything with paper. The attackers are estimated to have been in the system for a couple of weeks prior to the ransomware being executed. The attack's focus was to gain access to the police and county records. In effect, every device connected to the internet was shut down. Fortunately, the 911 system was not affected.
Help!
The county contacted the FBI and other cybersecurity experts. After the review, they found they could not correct the attack’s effects. They did attempt to decrypt the files and systems for a week with no luck. The county decided to pay the ransom. They could have continued to try and decrypt this for months with no luck. The county hired a cybersecurity response consultant to negotiate the ransom. The ransom requested was 100 Bitcoins. At that time, this amount was approximately $400k. Unfortunately, the ransom payment was paid. They needed to do this. Without the decrypt key, all the equipment would be bricks and files not accessible. The county would need to replace all the equipment and start all over. The payment was more of a business decision. The status of backups was not published. It’s presumed there was an issue with this, as this normally would be a viable alternative.
This is not the first-time successful ransomware attack had occurred in Georgia. There was the Atlanta attack in 2018. In this instance, the city did not pay the ransom. They replaced all the equipment. The immediate cost was $2.6M. The total cost was nearly $17M.
Thoughts
Prevention…prevention…prevention. The issue may be alleviated somewhat with pertinent, sustained training. Training staff with what to look up for with these is the focus. Also, with the Ryuk strain, the attack vector may be weak RDP passwords. There may be training for this along with updating the password conventions.

Resources
Dark Reading. (2019, March 11). Georgia’s Jackson county pays $400k to ransomware attackers. Retrieved from https://www.darkreading.com/attacks-breaches/georgias-jackson-county-pays-$400k-to-ransomware-attackers/d/d-id/1334124
Ford, W. (2019, March 8). Cyber attack forces Jackson county to pay $400k ransom. Retrieved from https://www.onlineathens.com/news/20190308/cyber-attack-forces-jackson-county-to-pay-400k-ransom
Forsythe, K. (2019, March 14). Ryuk saga: County government pays nearly $400k to hackers. Retrieved from https://medium.com/@newworldoptimist/county-government-pays-nearly-400k-to-hackers-ef95ea889159
Townsend, K. (2019, March 11). Georgia county criticized over $400k ransomware payment. Retrieved from https://www.securityboulevard.com/2019/03/jackson-county-criticized-over-400k-ransomware-payment
Truta, F. (2019, March 11). Jackson county pays ransomware operators $400k to regain access to computers. Retrieved from https://securityboulevard.com/2019/03/jackson-county-pays-ransomware-operators-400k-to-regain-access-to-computers/

Thursday, December 26, 2019

Vehicle repair shops: Likely target


Vehicles are throughout society. People may have multiple vehicles at a residence for their children, spouse, or collectibles. These are also used in multiple ways for an increasing number of years.  The vehicles begin to age, they tend to need more repairs. The establishments repairing vehicles do much of the work manually. The backbone of the operations are still run with computers. Where there is an issue with the system, the garage does not operate well. This can especially be a problem when malware is introduced into the system for a chain of garages.

Kwik Fit is one of these organizations. This is a chain of garages focused on repairing vehicles. The organization had the unfortunate opportunity to be targeted, and successfully attacked. The issue became apparent when their clients began to complain on Twitter. The symptom which brought this on was their clients could not reach the business when calling. The complaints began to pick up, as it appeared the call center was down. Naturally, this was a significant issue for the business. While they began the investigation, management acknowledged via a tweet they were having technical difficulties. This was from the malware being introduced into the system. It does appear this was a ransomware attack, however, the details were not reported.

The effect of this was rather quick and direct. The business was not able to accept and schedule work, or process orders. The system was down from January 26 to at least February 1, 2019. They don’t believe any of their client’s records had been breached. On a positive note, they did state the customer’s financial information was not stored there.

It would have been much more helpful to the industry if a bit of the attack information would have been shared. Given this is not the optimal situation, however, once the damage was done and issue remediated, others could have learned from this.
Resources
Corfield, G. (2019, January 31). Kwik-fit hit by MOT fail, that’s malware on target. Retrieved from https://www.theregister.co.uk/2019/01/31/kwik_fit_malware_it_systems_down/
IT Pro. (2019). Kwik fit hit by malware, knocking out IT systems. Retrieved from https://www.itpro.co.uk/security/32880/kwik-fit-hit-by-malware-knocking-out-it-systems
Rumney, S. (2019, January 30). Kwik fit garages hit by computer virus. Retrieved from https://www.bbc.com/news/technology-47062480
Winant, D. (2019, February 1). Kwik fit hit by malware knocking out IT systems. Retrieved from https://seclists.org/dataloss/2019/q1/105

Tuesday, December 24, 2019

The kids are alright! But the network isn't!


K-12 schools are throughout our landscape in small towns and large cities. The number of students varies per region, requiring small buildings or one large enough for a medium-sized business. They may be located on short, two-lane roads or primary thorough-fares. When we drive by these, we know they are educational facilities teaching the next generation. While the primary focus is the same for these institutions, there is another commonality. These have some form, be it rudimentary or complex, of a network holding a mass amount of data, managing operations where needed and facilitating email communications. One issue with these networks has been cybersecurity. With constricting budgets, it has become tough to get everything done as planned. 

Attack
One such school is Wolcott Public Schools. The school system, located in Connecticut was attacked successfully. The attackers naturally had a full array of tools available to use. They chose an all familiar one, which has proven to be very effective. Their system was compromised with ransomware. The use of ransomware has proven itself over the last two years to be an epidemic. The attack started in May 2019, at the end of the school year. They, in vain, attempted to manage this issue internally. Ransomware, with select tools, may be able to be removed by the target. This is with very few cases with the early variants, which may still be in use. This issue came to a tipping point and needed to be brought in front of the town officials when they were not able to correct the issue.

Effects
The successful attack had deep-rooted effects on the school. If this affected one user’s station, there would be a much different case. They were forced to lock down several servers. While these were locked down, they were not able to access or work with any of the data secured on these. Fortunately, a portion of the files was located in other locations as back-ups. While this sounds unpleasant, analyze through all of the learning activities that could not occur as the files were encrypted. On the bright side, no student data was compromised.

Remediation
This was a rather significant issue. Having data tied up and not usable is problematic for anyone. With the school district, there are timelines involved with reporting data to the state and possibly federal agencies. Post-detection, the school district did contact the FBI after the ransomware. The focus with this, naturally, was who was behind the ransomware attack.

As noted, the affected systems were shut down for all purposes. Once the school IT workgroup decided they were not going to be able to fix the issue, they consulted with the Wolcott Board of Education. The risks and benefits of paying the ransom were discussed and debated. The Board of Education approved the ransomware payment by a vote of 6 to 1. The hope was to secure the decrypt key. The amount noted for the payment was up to the amount the town charter would allow, or $9,999. This was the ceiling amount. An amount greater than this would require a bidding process, and an extended amount of time, which is something they did not have. Without the ransom being paid and the decrypt key is provided, a portion of the middle and high school files would not be usable in any form. In this incident, of the schools in the district, the high school, middle school, and central office only had a back-up server.

Comments & Concerns
Ransomware has become an epidemic. This has become a massive issue across many industries. Any business connected to the internet is susceptible to this. One fact not covered in the publications is the method of infiltration. This may have been an employee clicking on a link or file, inviting the malware in through the front door, and allowing it to scurry about in the network. Ransomware training is a necessity in this day. The employees need to know what to look for as a constant reminder. In the case of an individual oversight, which generally is a detriment to such a significant level, the employees need to know what to do.

Resources
Backus, L. (2019, August 30). FBI probes hacking of CT school’s computer. Retrieved from https://www.ctpost.com/local/article/FBI-probles-hacking-of-CT-school-s-scomputers-14401437.php
Data Breaches. (2019, August 30). Cyber attack affects Wolcott public schools. Retrieved from https://www.wfsb.com/news/cyber-attack-affects-colcott-public-schools/
WFSB. (2019, August 30). Cyber attack affects Wolcott public schools. Retrieved from https://www.wfsb.com/news/cyber-attack-affects-wolcott-public-schools/
Johnson, K. (2019, August 28). Ransomware attack targets Wolcott public schools. Retrieved from https://www.nbcconnectictu.com/news/local/Ransomware-attack-targets-wolcott-public-schools-558610611.html
Passmore, S. (2019, August 30). Board passes motion to allow Wolcott superintendent to pay ransom after cyber attack. Retrieved from https://www.weny.com/story/40985421/board-passes-motion-to-allow-wolcott-superintendent-to-pay-ransom-after-cyber-attack

Tuesday, November 12, 2019

Oh, the irony: Anti-ransomware firm pwned with ransomware


PerCSoft is a Wisconsin business. The organization provides online data backup services for dental offices. This operates by placing data in the cloud. They had hundreds of dental offices as clients. The focus was to secure the patient medical records and other data from the various attacks, including ransomware.
Irony
The irony of this pwnage has not fallen on deaf ears. In this industry, it’s not often the irony though has this much depth. The firm’s function was to secure backups for their clients. In certain instances where there would be an issue with the client’s data, such as with a natural disaster or a successful ransomware attack. In their marketing materials, the safety of ransomware is emblazoned. The organization, whose function was to secure data from ransomware had their files encrypted with ransomware, making them not accessible.
Ransomware
PerCSoft, the online data backup service, was successfully attacked with ransomware. This attack encrypted files for approximately 400 US dental offices. It appears the tool used was Sodinokibi, a ransomware variant aka Sodin or REvil malware. This was addressed as a critical vulnerability with Oracle WebLogic Servers, and with CVE-2019-2725 with a severity score of 9.8/10. This operates as a deserialization remote code execution vulnerability. This was designed to encrypt files and delete the shadow copy backups. This prevents the victim from recovering the data from other sources and puts the victim in a very difficult situation.
Attack
The ransomware was detected on August 26. This was, relatively, a very successful attack, and apparently profitable for the attackers, as they were paid. There were over 400 dental practices affected. To appreciate the full extent of just this aspect, imagine the number of patients seen every day, multiplied by two weeks, and then multiply this by 400, to be conservative. This attack did not merely affect a few offices, but also all the people that work there and the patients. The practices were not able to access patient history, charts, schedules, x-rays, or patient balances. I can only imagine how difficult this was to work through for the affected staff members and patients.
Remediation
PerCSoft ended up paying the attackers. While not published, this course may have been required as their primary files and all of their backups being encrypted or deleted, and they simply had no choice. It was not reported who was paid or how much. As of 8/29/2019, 80-100 of the 400 dental office files had not been decrypted. In these instances, the decrypt key did not work, which is an issue. The restoration of the other offices was a bit slow. On a positive note, the organization did communicate on a regular basis with their clients and interested parties through, among other means, Facebook from their postings.
Defenses
Perhaps PerCSoft should have followed a few of the basic industry standards and processes to reduce the potential for an epic fail. The practices include:
·        Backing up your data. This can be done on- or off-site. Dedup is an option, dependent on the circumstances and budget.
·        System inventory. Over time, we tend to become complacent with the network. Periodically we should take an inventory of the assets on the network. This reduces the opportunity for missed patches and also detects any unknown or shadow assets using your equipment and network.
·        Conduct cybersecurity training throughout the year and make it relevant. The once a year cybersecurity mandatory training to check the box simply still does not work. This needs to be done through the year with relevant, current training. Granted, your task is not to entertain the staff during these, however, you still need to attract and retain their attention. This will assist with them internalizing the message and applying it, as some level, to their work, when the need presents itself. The alternative is to play the same VHS tape from the 1990s and having your staff in an infinite loop of mass password resets, patching vulnerabilities, scanning for issues, and headaches.
·        Patch cycle. While this may not directly impact the ransomware attack, it is still prudent and an industry-standard to address this with regularity, in addition to the critical and time-sensitive patches requiring immediate attention.
Lessons Learned?
PerCSoft paid the ransom, as noted previously. This may have been their only option given the germane circumstances. The organization may not have backups of their client’s data. The organization having to pay the ransomware fee to operate is bad enough. This, however, should ask you, in a researcher role, to wonder why they had to pay the attackers only to operate. There generally are so many issues with this avenue, it is hardly recommended.

Resources
Kobialka, D. (2019, August 29). Ransomware attack hits backup provider, US dental offices. Retrieved from https://www.msspalert.com/cybersecurity-breaches-and-attacks/ransomware/dental-offices-hit/

Krebs, B. (2019, August 29). Ransomware bites dental data backup firm. Retrieved from https://krebsonsecurity.com/2019/08/ransomware-bites-dental-data-backup-firm/

Kumar, M. (2019, May 1). Hackers found exploiting oracle WebLogic RCE flaw to spread ransomware. Retrieved from https://thehackernews.com/2019/05/ransomware-oracle-weblogic.html

Percsoft Dental Technology Consulting. (2019). Facebook posts. Retrieved from https://www.facebook.om/pg/percsoft/posts

Wei, W. (2019, August 30). Ransomware hits dental data backup service offering ransomware protection. Retrieved from https://thehackernews.com/2019/08/dds-safe-dental-ransomware-attack.html

Tuesday, October 1, 2019

Bridport pwned!


Sir John Colfox Academy is a secondary school in Bridport, Dorset in the UK. The school has 828 students, aged between 11 and 18.
Attack
On a fateful work day, much like any other, a staff member received an email. This was one of the hundreds of emails received on a weekly basis. This however claimed to be a colleague at another Dorset school. Not thinking a malicious person would have sent this, the staff member opened the email and clicked on the content on February 28, 2019. While this may have seem innocent enough, the email actually appears to have been sent from China and forwarded from a server in Germany.
The click opened the door for the systems infection. The network had an issue. The malware was reported as ransomware and, as expected, immediately began to encrypt the files. The attackers, as with the next step of the ransomware playbook, demanded money to be paid to them for the decrypt key.  The school consulted with a police expert regarding the substantial issue. After a review, it was noted the attack did not likely exfiltrate any school data, and staff, student and parent data were not on the system that was breached. The research into this indicated the attack may have been part of a much larger international operation.
Data
In particular, for this case, Year 11 students submitted their coursework. This coursework was saved on the school’s network. Due to the issue, the coursework in the subject was lost. While the description is short, the devastation is significant. The hope is the student’s had this backed-up somewhere.
Mitigation
The school is working with a particular exam board to resolve the issue. They are also working with the Dorset Police cybercrime unit. Although there was a demand for funds, no payment was made. This is generally the policy to take due to the secondary potential issues with just making the payment. The school had to notify the parents and sent a letter explaining the issue.
Discussion
Targets are generally attacked to compromise their systems to gain access to data for exfiltration or to extort funds from them. In the early days, these may have been more of an exercise, however, the attackers have operationalized the model. Ransomware has proven itself to be a completely popular, viable, and successful attack tool. Over the last four years, this has been very profitable for the attackers.
Lessons Learned
Ransomware is used so often, it is becoming redundant. The frequency is mostly due to the simplicity of the attack, the financial awards, and this tends to shut down operations until the fee is paid (not advised) or the issue is remediated through installing back-ups, and a thorough review to ensure nothing was left behind by the attackers they could use later for re-entry.
There needs to be continued training for the staff. This removed a significant portion of the opportunity for an issue. If the staff know what the usual forms of the attack are, these are less likely to be clicked on, and fewer systems would be infected. There also needs to be back-ups, which are regularly checked to ensure they are viable.

Resources
Hussain, D. (2019, March 14). Secondary school is being held to ransom after a ‘chinese cyber attack’ caused the loss of year 11 student’s GCSE coursework Retrieved from https://www.dailymail.co.uk/news/article-6808845/Secondary-school-held-ransom-cyber-attack-caused-loss-students-GCSE-coursework.html

Sjouwerman, S. (2019, March 14). GSCE coursework lost in ransomware attack on UK bridport school. Retrieved from https://blog.knowbe4.com/gcse-coursework-lost-in-cyber-attack-on-uk-bridport-school

Speck, D. (2019, March 15). GCSE coursework lost in ransomware attack. Retrieved from https://www.tes.com/news/gcse-coursework-lost-ransomware-attack

Wakefield, J. (2019, March 13). GCSE coursework lost in cyber attack in bridport school. Retrieved from https://www.bbc.com/news/uk-england-dorset-47551331

Friday, September 13, 2019

There's always a new attack tool: JungleSec

For better or worse, InfoSec researchers are seemingly always seeking new methods to attack systems. There’s always something new for targets, methods, and data on the target. This industry is not static by any means due to this and also the new publications and journals showing the techniques used. This may even be termed as being dynamic. This attribute can both be a positive, and negative. 
Tool
There is a new ransomware variant in the wild. This began to be noted in November 2018, and has been named JungleSec. The attack vector with this variant is through the unsecured intelligent platform management interface (IPMI). This began with people using Windows, Linux, and Mac systems. After an investigation, discovered the users were infected via an unsecured IPMI device. The IPMI cards allow administrators to remotely manage a computer, power cycle the system, secure system information, and gain access to a KVM. 
Installation
As a rule of thumb and best practice, the admin or user should always change the default password. In certain instances where this is not done, unauthorized access to the system may occur. There may also be other avenues into the system through these sources. Once the attackers have access, the attackers would reboot the system into a single user mode. The attacker then is able to gain root access. At this point, the encryption program was downloaded. The attacker then manually executes the encryption on the victim’s files, and the attackers would enter the passcode. The attackers also have tried to mount VM drives and encrypt them, unsuccessfully. With this ransomware piece, the attackers have included a back door on port 6432. 
For the User
The ransomware leaves the user with an empty feeling in their stomach. When the user attempts to do work on the system, they receive the infamous message (aka ransom note) instructing the user to contact the attacker an email address, and pay 0.3 bitcoins to their address for the decrypt key. 

There are numerous problems with this. After payment, they may or may not actually receive the key. The attackers may also install their own additional back doors, so they can gain access again at a later point in time. Without a tested set of back-ups, however, this may be your only avenue towards getting the systems up and running. 

It is always a good idea to properly configure the equipment and system. There are manuals, tutorials, and peers to assist with this. To not do this is equal to inviting an issue. 


Resources
Abrams, L. (2018, December 26). JungleSec rnasomware infects victims through IPMI remote consoles. Retrieved from https://www.bleepingcomputer.com/news/security/junglesec-ransomware-infects-victims-through-ipmi-remote-consoles/ 

Paganini, P. (2018, December27). Hackers infect linux servers with junglesec ransomware via IPMI remote console. Retrieved from https://securityaffairs.co/wordpress/79219/malware/junglesec-ransomware-ipmi.html 

Saturday, August 31, 2019

Augusta, ME Targeted and Successfully Pwned


Cities are being targeted at greater levels. Atlanta, Albany in New York, Baltimore, and Flint are merely a few of the recent examples. These successful attacks are not inexpensive, as the costs for the consultants, forensic cybersecurity subject matter experts, hardware, and other costs add up. While a portion or majority of the costs may be recouped by the insurance company, the direct labor to re-enter data or apply the prior back-ups affect also the operations for a varied amount of time.
Target
For this round, Augusta, Maine was targeted and successfully attacked. Specifically, the Augusta City center was targeted and pwned.
Attack
In this case, the attacker’s tool was ransomware. This has been such a successful tool to use for these attacks. All it takes is one employee. For Augusta, it appears an employee clicked on a file or link they really should not have. The attackers demanded over $100k for the decrypt key. If they did not receive the funds, the threat was the entire computer system would be shut down. One defensive measure against ransomware is the simple, yet pertinent, back-up. The city stored its data on a mass storage device. Thankfully this was not compromised as part of the attack.
Mitigations
As the attack’s symptoms were felt by the city, to mitigate the issue the IT department began pulling cables from the computer equipment. This is somewhat basic, however, this was sufficiently effective. The immediate effect was to close the offices for two days. The IT department also froze the systems responsible for the municipal financial systems (i.e. payroll, accounts payable, and accounts receivable), billing, automobile services, assessor records, and general assistance. The plan was solid, as the IT department did not want this to spread further through the system.
Payment and Beyond
The city did not pay and had no intention of paying the ransom. In general, this is the preferential plan. For this option to work, however, there have to be viable back-ups, and these had to have been tested. The total costs for this were significant. Most of these costs were for the staff of five persons in the IT department for overtime. They had to put in 80-100 hours over eight days. The staff also was tasked with entering data which was lost due to the outage. The system may have been down for 1-1.5 weeks. The city also investigated the issue in order to attempt to find the attackers. This endeavor was not successful.
What We Can Learn
The attack vector was a seemingly inconspicuous email with a happy, little attachment or link. The click-happy staff member’s action took down the city’s systems. There is always an opportunity for cybersecurity training and updates on different attacks, which may be directed at the staff.
Resources
AP Maine. (2019, April 29). Hacker wanted more than $100k to restore city computers. Retrieved from https://www.fosters.com/article/20190429/AP01/304299990

AP News. (2019, April 29). Hacker wanted more than $100k to restore city computers. Retrieved from https://www.caledonianrecord.com/news/region/hacker-wanted-more-than-k-to-restore-city-computers/article_  

Edwards, K. (2019, April 28). Augusta cyberattacker sought over $100,000 in ransom. Retrieved from https://www.pressherald.com/


Saturday, August 17, 2019

Newspaper attacked!

Although print newspapers are having issues due to the online outlets, these are still present and noticeable throughout the communities and provide a valuable service. The newspapers have not been targetted over the last few years, as frequently as others. These organizations don’t have PII or PHI to the extent others, e.g. doctor’s officed or hospitals. These also don’t have a mass amount of money laying about. While there are other more viable targets, the newspapers certainly may have their systems focussed on by the attackers. 
Incident 
When the attack was first noticed, the management termed the issue as a “glitch”. The attack ended up being detected on Saturday. Due to the attack, the organization was not able to print and deliver the Sunday paper. The attack itself was detected by the IT staff, as it affected the servers and computers had been breached by malware. This acted by encrypting the files. The malware also was infecting the systems for Tribune Publishing. 
Ransomware 
The paper was a victim of ransomware. The systems and data were encrypted. The attackers used the Ryuk ransomware. This particular version was largely successful in late 2018. Generally, the attack operates such that the files are encrypted, and a ransom is paid for the decrypt key. 
Thoughts
Ransomware can be a real nightmare for the direct victims and indirect persons affected by the organization’s lack of operations. This has the ability to encrypt an entire system and data sets. If there are no viable back-ups in place, the situation has the unfortunate ability to be very interesting for the target. This highlights the need for a properly trained incident response team. 


Resources
Hand, L. (2019, April 28). Watertown newspaper hacked, cannot print sunday edition. Retrieved from https://cnycentral.com/news/local/watertown-newspaper-hacked-cannot-print-sunday-editions 

WWNY. (2019, April 28). Watertown times attacked by malware; Sunday paper not printed. Retrieved from https://www.wwnytv.com/story/40279959/watertown-times-attacked-by-malware-sunday-paper-not-printed 

Thursday, June 27, 2019

Physician's Office Forced to Close Due to Ransomware


Ransomware’s Long-Reaching Effects: Physician’s Office Shut done
Physicians are located throughout the nation. These all have their specialties. As these practices vary in size, their budgets spent on cybersecurity vary greatly. The rule of thumb, for better or worse, has been the greater amount spent on cybersecurity the more intricate and hardened the system is. This, however, has not always been the case.

Recently Brookside ENT and Hearing Center had the pleasure of managing a successful cybersecurity attack and compromise. This doctor’s office was located in Michigan. The successful attack initially encrypted the files and complete computer system for the Brookside ENT and Hearing Center. The attacker demanded a $6,500 ransom for the decrypt key. The ransom was refused, which normally is a good route to follow if you have viable backups and/or are able to recreate the data without a significant issue. Naturally, the attackers were not exceptionally happy with this response. As a direct result from this, the entirety of the practice’s computer network was erased. This included all of the patient files and records. This was, to say the least, a bad situation.

Effect
The medical practice was owned by John Bizon, MD, and William Scalf, MD. After all the records were erased, the owners decided to retire and close the practice. Rebuilding the practice’s data and other pertinent information was simply not worth it for the owners/doctors. This adversely affected the patients.

The data affected was rather expansive. This included all the appointment schedules, payment data, and other patient information. On the bright side, it appears no patient data was accessed and the electronic health records (EHR) were encrypted. The potential issue with this is the encryption protocol in place was not published. It is presumed this an industry standard and not home-rolled or an outdated version.

Incident Response
The FBI was actively investigating the successful attack. Unfortunately, the attack vector and tools had not been published yet. The data for this could have been used as a learning tool and case study for others. The attack could have been a simple phishing attack with the right staff members clicking on an image or link.

This illustrates the need for purposeful training for the staff members on the various cybersecurity topics. It is by far too late for this practice; however, others may learn from this.

Resources
Davis, J. (2019, April 1). Michigan practice to shutter after hackers delete patient files. Retrieved from https://healthitsecurity.com/news/michigan-practice-to-shutter-after-hackers-delete-patient-files