22 ms·
US companies hit by 'colossal' cyber-attack
- rambojohnson 5y agowooptie doo
- stonepresto 5y ago“tl;dr REvil popped @KaseyaCorp. Abused Kaseya's auto update to conduct supply chain attack that DLL side loads Windows Defender binaries and ransoms the customer tl;dr tl;dr REvil just pulled off a colossal ransomware supply chain attack” @vxunderground Thread includes samples. https://twitter.com/vxunderground/status/1411058433558786049?s=21 https://twitter.com/vxunderground/status/1411058433558786049...
- junon 5y agoSamples at that link, for anyone curious.
- jiggawatts 5y agoI never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the ability of a country to respond. There's only so many recovery specialists and IT contractors available to respond in an emergency. Encrypt only a few hundred targets and they can all recover. But if you encrypt a few hundred thousand, then there wouldn't be enough warm bodies available! Thinking about it, I wonder if these attackers have set up permanent operations, with staff, payroll, and everything. Maybe they just to fly under the radar and collect a nice steady income instead of a risky but potentially huge one-time payoff...
- goatlover 5y agoYeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.
- arthurcolle 5y agoFWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic) So it's a spectrum
- covidthrow 5y agoThat's not even close to what happened. The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.) When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet clients more carefully in the future."
- astrange 5y agoDid they leave it alone for days? The FBI seized the ransom (claiming it was left in a Coinbase account) so clearly someone was doing something.
- Wolfenstein98k 5y ago"Left alone" as in publicly and geopolitically. The FBI investigated the crime as they always do. It was treated as a standard international monetary theft.
- whimsicalism 5y agoThey also accepted a ransom substantially below their typical going rate. The Darkside people were probably shitting their pants, this is not what they intended at all.
- Donald 5y agoDarkSide's business model was to professionalize ransomware attacks with a dedicated professional services IT model, finance, and helpdesk support.
- readams 5y agoYou'd need to be able to process all the orders also. Every company needs support to pay the random and unlock. Also, at some point the military gets involved.
- AnimalMuppet 5y agoYeah. If you take down 100 companies, it's crime. If you take down 100,000, it's an attack.
- raverbashing 5y agoCorrect, this won't get better until these groups are physically disbanded.
- ackbar03 5y agoIf i recall correctly solarwinds was more of an espionage operation by russia government actors. Their targets were mainly government agencies in US. The ransomware attack are from private profit-seeking groups, although I remember the head of REvil tweeted once he was neighbours with KGB's number two guy so you could argue the distinction is vague
- beermonster 5y agoAttribution is quite hard. When the 3-letter-agency tools leaked a few years ago, one of their leaked tools concerned deliberate false attribution. The solarwinds attack seemed to be about using a supply-chain attack to gain persistent access for recon and lateral movement. Pivot to Azure via Microsoft via SolarWinds software. Whomever it was tried to stay invisible for as long as possible. Once the game was up, they were not so careful about visible actions. RansomWare is more smash and grab though it's interesting/sad to see the current trends of Supply Chain attack prevalence and Ransomware attacks converge.
- beermonster 5y ago> when it could easily have been 50% or more! Was that down to slow patching cadence at 99% of companies? In which case those customers have different vulnerabilities to tend to.
- KirillPanov 5y agoAt some point you cross the threshold of "this is too much, drone them". Or send an assassin. Yes, even the United States does this occasionally. I suspect the attackers know this. Or else they aren't in it for the money. One or the other.
- rocqua 5y agoThe catchy rhyme being "warheads on foreheads".
- ahD5zae7 5y agoYeah unless they work from an office in e.g. Moscow. The US is powerful for sure but even they would think twice before droning a building in Moscow over some hacks, especially without concrete proof that's where they originated. At least I hope they would because if not then we may be closer to a world war than we thought...
- xwdv 5y agoSteady income is definitely the way to play. You don’t want to make a demand so large that there’s cheaper alternatives of dealing with you. Also you want the company to stay in business so it can continue generating revenue to extract future ransoms, and not have it lose a bunch of its customers from your repeated attacks.
- gonesilent 5y agoDidn't it only affect those who were unpatched hence the low percent? Current hack is 0-day.
- aj3 5y agoSolarwinds was distributed by a malicious patch (through legit channels). So all orgs were unpatched and in fact all got at least first stage downloaded (if they patched during that window).
- vsareto 5y agoTinfoil hat, but that Solarwinds access was way more valuable than a ransomware payoff. Made sense to keep quiet with it.
- jjk166 5y agoIt's not enough to just gain access - once you're in you need to compromise other defenses, you need to communicate your demand to the victim, you need to know how much to extort, you need to actually process the payment. Either you do this on a case by case basis or you take advantage of additional exploits that will only be viable for a subset of your potential targets, and this is all a race against time before someone notices your initial exploit. Either way, it's likely impractical for any non-nation state actor to simultaneously attack more than a few thousand targets in one go. This is combined with a business model resembling patent trolls: you want to extort just a little less than is worth fighting for. If a company gets hit on its own, it's probably not in a position to really do anything about it, but if there is some major hack affecting tons of companies, the odds of an actor with significantly more tech capability like the US government getting involved go way up, and suddenly fighting seems like a good option.
- wrycoder 5y agoMaybe you’re a state actor and a ransom demand, at least an overt one, is not your objective.
- cherryturnover 5y agoMy mind went there as well. Say I'm an affluent oligarch shorting major companies. I'd paying the ransom group to massively attack the company or various companies. Then cash out during the chaos.
- whimsicalism 5y agoYes, except for the fact that we don't hear about most of these attacks because both the attacker and attacked keep them quiet. That doesn't jive with your market manipulation hypothesis.
- deleted 5y ago[deleted]
- zaroth 5y agoBecause there are plenty of zero-days the NSA can deploy if you step out of your lane. It’s as much a political game at this point as anything. If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves. They’ll either end up hacked beyond their wildest imagination or facing literal hellfires. It’s brinkmanship. When the devs literally die, they think twice.
- Animats 5y agoAt some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism. Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker. Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters didn't pay. There were no further attacks. The Teamsters declined to comment. (For those unfamiliar with American labor history, trying to push around the Teamsters Union usually ends badly for the pushers.) [1] https://thehill.com/policy/cybersecurity/558066-teamsters-refused-to-pay-a-ransomware-attack-in-2019 https://thehill.com/policy/cybersecurity/558066-teamsters-re...
- coolspot 5y agoYou make it sound like the Teamsters Union could do something bad to the attackers, so attackers gave up, but in reality Teamsters just rebuilt from archives, which was perhaps an economical decision: “Ultimately, the union decided not to pay the ransom based on advice from its insurance company, and instead rebuilt its systems based on archived materials, NBC reported.”
- Haddaway 5y agoMaybe a nation state is already behind it? https://cryptome.org/2021/06/Peck-Barb-1974.pdf https://cryptome.org/2021/06/Peck-Barb-1974.pdf Was Edward Snowdon "https://www.youtube.com/watch?v=1GtVt6quoD8&t=78s https://www.youtube.com/watch?v=1GtVt6quoD8&t=78s" or a psychologically manipulated patsy for the good/bad guys & girls? https://en.wikipedia.org/wiki/Full-spectrum_dominance https://en.wikipedia.org/wiki/Full-spectrum_dominance isnt just about hacking a few computers, its about getting inside the brain of each and every one of us/you like a https://www.youtube.com/watch?v=lG7DGMgfOb8 https://www.youtube.com/watch?v=lG7DGMgfOb8. Or is this line of thought just a https://www.youtube.com/watch?v=wmin5WkOuPw&t=48s https://www.youtube.com/watch?v=wmin5WkOuPw&t=48s ?
- aj3 5y agoSolarWinds affected 100% of installations that updated their deployments during that 8 month window. Your 1% comes from the ratio of networks that were specifically targeted and received 2nd stage with all the goodies. The reason why 2nd stage was only given to (relatively) small number of organizations - because the attack wasn’t ransomware, attackers didn’t have economical motives (in fact they were spooks on a government payroll). EDIT: I can’t spell
- nuker 5y ago> The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If it was me (it was not), I’d use it to gain persistance in companies like Kaseya, extending my beachhead as first priority. After that is basically game over, cleaning it would take making new IT systems from scratch. And lets not forget firmware…
- ineedasername 5y agoGive it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack. No worries though, the ransom from this round should serve nicely as a Series B round of financing & enable rapid scaling of the post-hack ransom extraction process.
- aliyfarah 5y agoI wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.
- ljf 5y agoAs I understand it there is often a lot of discourse that takes place between the hacker and the hacked - agreeing prices, haggling, proof of files etc. Yes much can be automated but there is usually a human element to these deals and that costs the hackers money. They also want to be careful to limit their hacks to companies their handlers are happy for them to hack. Go too wide and you risk hitting a company directly or indirectly linked to your state/handler/patron.
- dredmorbius 5y agoYou'd think a GPT3 / GAN could be created to handle much of that. It's a percentages game anyway.
- whimsicalism 5y agoWhy would you want GPT to handle multi million dollar negotiations? Sorta playing into stereotypes about engineers here.
- 5y ago
- known 5y agoAnd I think Cloud computing is covertly 'leaking' vital data and has its role in ransom-ware attacks https://archive.is/x1Hvh https://archive.is/x1Hvh
- AtNightWeCode 5y agoI would not be surprised if there is a market for the tools and the knowledge. That the real hackers just sells it and then other people do the attacks and thereby taking the risk. Similar setups existed with botnets.
- miohtama 5y agoNote that i n the case of SolarWinds, there was no demands for ransoms. It was good old state level spying, not a job to get few bitcoins.
- deleted 5y ago[deleted]
- AtNightWeCode 5y agoI did write an answer before but now it seems like only Internet facing VSA servers are effected and some other measures may have stopped the attack. It could be all the servers they could find...
- dienw4149 5y agoI worked for an MSP that used Kaseya VSA. First used the SaaS version. Their "SSO" is not claims-based but an agent that may just run on a DC and copy NTLM hashes to the SaaS instance. Had an admin account compromised. Asked for logs from Kaseya. Attacker traffic came from a Tor exit node. They did zero ingress filtering. Much of their codebase is Classic ASP riddled with comments like "'fixed SQL injection." Beyond the bizarre HTTP traffic, the agent communication protocol is a black box with some VNC. Logging goes to SQL so you have to do custom work to parse or push that to a SIEM. Terrified. Moved to on-prem and stuck a bunch of mitigating controls (blocking known Tor exit nodes, blocking egregious injection attempts, etc.). Wrote custom scripts to ingest logs. I'd like to see a professional penetration test report against their software. It does not look good.
- aksss 5y agoThis sounds like something Computer Associates would buy and keep alive for another decade.
- jart 5y ago/r/msp is having a real "spartans what is your profession?" moment right now. https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/h3ug4ol/ https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom... See also https://youtu.be/aNa3Co83_gk?t=71 https://youtu.be/aNa3Co83_gk?t=71
- deleted 5y ago[deleted]
- mkl95 5y agoThis is like a weekly thing now.
- deleted 5y ago[deleted]
- kickling 5y agoOne of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-efter-it-attack https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...
- dadver 5y agoMost definitely, googling "Coop" "Kaseya" gives a few articles showing they've implemented it for parts of their organizaiton since at least 2009. Patients in Region Skåne were also unable to access their journals on Friday afternoon (possibly unrelated) and Coop's competitor ICA's apothecary company Apoteket Hjärtat seems to be affected by Kaseya/REvil attack also.
- deleted 5y ago[deleted]
- sschueller 5y agoA cashless society is scary. Cash should always be an option and the inventory system should be disconnected from the internet.
- jokteur 5y agoIn my country (Switzerland), while they have massively invested in cashless solutions, a lot of places are still accepting cash, and I think it is a good thing. One of the big retailer (Coop) has self-checkout machines that accept and give back cash (you can insert 200CHF~216USD at a time if you want).
- sschueller 5y agoJordan (head of SNB) is not going to let cash go and even kept the CHF 1000 bill under EU pressure. Thank God. What urks me is the obvious "never let a crisis go to waste" where we have visa etc marketing that cash might spread Corona. Yes, I've put CHF 200 in coop register before. Funny, they don't care but if I scan a tiny bottle of alcohol I need to wait for someone to approve it...
- fukd 5y agoLet me guess the hackers are from and protected by a few rogue nations which MNCs love to do business with. During obama administration companies were reluctant to go after culprits. i think they do not deserve our sympathy now
- sschueller 5y agoRussian state getting blamed for it in 3, 2, 1... I don't want world War 3 over stupid ransomware because of bad sys admin work and some stupid criminal groups. We should stop with this blaming. It is in Russia and other states interest to stop the ransom attacks even if they may be coming from some small group of people in their country. They have just as a hard time finding these criminals than we do finding them in the US.
- oohaargh 5y agoIf you think that's in the Russian government's interest you haven't been looking at what they're up to too closely. Russia isn't really that big a player globally (GDP quite a bit less than Italy's for example), but they've realised they can wield a substantial amount more power by just chaotically screwing things up for their opponents. It's the same pattern in their cyber attacks, election interference, middle east policy, online disinformation spreading, etc etc. None of it's directly for their own benefit, it's purely to harm opponents.
- konart 5y ago>GDP quite a bit less than Italy's for example Nominal. Closer to Germany if we are talking PPP and notably higher than Italy of course
- estaseuropano 5y agoWhy is it in Russia's interest to stop them? These groups have an arrangement that as long as they don't attack Russia's allies they are untouchable. They bring in money and build up real-world skills that Russia is eager to have. Its like the old-fashioned pirates, as long as there is plausible deniability and they only harm the competition they are a great asset. So yes Russia might be blamed as they consciously choose to let these guys do their thing. China and NK do the same, as do US, UK and Israel with similar stuff on the other side, done by NSA, CiA, etc
- toss1 5y agoYou have obviously failed to notice that we are already in an increasingly hot war with the Russian govt (which is in reality a transnational criminal syndicate masquerading as a govt). Any attempt to avoid conflict under the guise of avoiding current hot war actions is merely understood by these actors as weaknesses and permission to take more territories, libreties, and/or criminal actions. This will eventually lead to conflict, and the longer the delay, the larger and mor damaging the eventual conflict. If you want to avoid large war(or even "WW3"), the solution is to take serious diplomatic, financial, and kinetic (all 3) actions immediately, si that the perceived costs immediately escalate beyond any possible benefits to Vlad and his ilk. If you want more information, read people who have a deep understanding of the situation and have skin in the game, such as Garry Kasparov, former world chess champion & Russian presidential candidate currently in exile, and Bill Browder, former Russian investment fund founder & progenitor of the Magnitski sanctions being effectively deployed around the world. Both have been there, done that, and buried their friends for their efforts. Peace is a wonderful goal, but not at the expense of allowing autocrats & criminals free reign - they will stop at nothing and eventually take everything.
- noduerme 5y agoThese kinds of games, and the all-nighter / weeks long nightmares they cause, make me want to leave this industry. We set up software on a lot of machines and then we answer a million ridiculous user questions until we finally resort to installing remote access so we don't have to stay up all night telling people what to type into a command line. Then the remote access gets hacked en masse. I'm pretty much at the point of thinking people need to learn how to write on paper and whiteboards again. Without a well-trained work force, this shit isn't resilient, and no technical priesthood can keep it running in the face of constant attempts to demolish it. It's too brittle, and the knowledge of the user base is too shallow. Depth can be provided by reverting to older skill sets. Fallbacks. Businesses should not go down because their computers locked up with ransomware. I pitched and wrote some software for a company a few years ago to automate a very rigorous daily process that used to take a lot of man-hours. Occasionally, local networks would go down and people would have to revert to the old way of doing things on paper. But as turnover happened at the company, fewer and fewer people knew the "old way". Now they've reached a point where they're locally paralyzed if there's a network outage. They have to call in senior management on their day off to run the shop. I realized I didn't do them a favor. I solved one problem for them and saved them a lot of labor, but I created a whole new problem of reliance on a system that's more convenient, but much less robust than the paper system they used to have. And this doesn't even take into account the potential for security issues. I think we should try somehow to architect things with offline fallbacks and training for those scenarios. The pace of attack is unsustainable and we're losing the war. If the point is to keep business running, we will lose the war if we lose the skill base and knowledge that we had which was capable of running the economy without a screen in front of them. [edit] Come to think of it, there's a great startup idea in systematically re-paperizing businesses for failover. Take all that business logic that got written into software, and turn it back into a set of worksheets and training manuals.
- freebuju 5y agoOkay, maybe it is now time for Biden to agree to a sit down with Putin on this menace. ION We may have underestimated the depth of the solarwind attack back in late last year.
- hn_throwaway_99 5y agoHonestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the castle to some mid-tier company is just a recipe for disaster, and the bad guys know how extremely lucrative these targets are.
- gostsamo 5y ago> this should be the death knell of these "remote monitoring and management" tools Yeah, sure. We should have a person on each of hundreds of sites whose only job is to check manually every router, switch, and vending machine. Maybe in the best HN traditions you will train the necessary workforce in a weekend?
- elric 5y agoYour quote cuts off before the salient part, and you seem to be attacking an imaginary argument. > tools that have extreme low-level access to networks and systems The emphasis being on the low level access. The solution is not having hundreds of people checking things by hand (though I'm sure that could contribute to security). The solution is more privilege separation; so that when the "remote monitoring tool" is compromised, not every part of your infrastructure is also compromised by default.
- gostsamo 5y agoI'd agree partially with you. However, once a remote agent is compromised, it will be chained with some privilege escalation vulnerability and this same argument will be repeated with the twist that now every foreign executable with remote connection is an attack surface. Having hundreds of people in each location whose only task is to do a boring monitoring an very occasional management tasks is a waste of your resources and their intelligence. We do automation to escape doing stuff that we can but which are to mind numbing. The illusion that every one of those hundreds of people will do their job to the necessary level of quality and without lapses of diligence is optimistic to say the least. Doing automation badly is not a reason not to do automation at all.
- hamandcheese 5y agoI almost a fan of these attacks. At least someone is getting the bug bounty they deserve.
- yjftsjthsd-h 5y agoThe problem is that they're doing it by actually hurting people.
- hamandcheese 5y agoHurting who?
- yjftsjthsd-h 5y agoThe companies and individuals who are attacked? Would you be okay with this happening to you or your work's computers?
- hamandcheese 5y agoIt would be a great lesson of what happens when security is neglected.
- wyldfire 5y agoAttacks don't yield bug bounties, disclosures do. The only "bounty" is what the attacker exfils or ransoms.
- dehrmann 5y agoThe way bounty payouts seem so hit or miss (at least according to HN posts), the success rate and turnaround of ransoms looks a lot better.
- user3939382 5y agoThese digital networks and devices have become so complex we can’t reason about them, or in any case can’t easily reason about them given the resources available to most of the organizations running them. However, from what I’ve seen, most of these attacks are successful because these organizations are simply neglecting best practices (e.g. patch management, whitelisting, security awareness training).
- noduerme 5y agoMostly, they're neglecting training their employees to keep the business running when the software is down.
- cyanydeez 5y agolike everything else in america, #1 priority is fèeding ceo salary and shareholder value. everything in corporate america is derived from the growing wealth inequality and these shake downs are precisely targetting the glut. soon enough, itll still be cheaper to have a bribe fund, just like tax evasion lawyers, lobbiests and the rest of the feeder classes than a holisitic defense.
- test_epsilon 5y agoThis is a tiresome, meaningless religious mantra nowadays. Yes there is corruption. No not everybody is corrupt. No it does not only exist in USA nor is USA anywhere near the worst. No you can't blame anything and everything you don't like on corruption and greed.
- deleted 5y ago[deleted]
- FractalHQ 5y agoPerhaps, but of all the leading developed nations on Earth, the US has a particularly corrupt government that sells itself to the highest bidder thanks to Citizens United and armies of lobbyists. Our healthcare, prison, and student loan systems, for example, prey on US citizens without repercussions at lengths that don’t fly in most developed countries. I think it’s safe to say that corruption and greed are at the root of most problems in the US, and it’s important to call it like it is.
- aborsy 5y agoI wonder if institutions in other countries and regions, eg, Europe, are also frequently compromised, but we don’t even hear about that. The same sort of software is used by all governments and corporations.
- aj3 5y agoYes they do get compromised and the information is published regularly. E.g. here is a news item from just this week: https://www.reuters.com/technology/denmarks-central-bank-exposed-solarwinds-hack-media-report-says-2021-06-29/ https://www.reuters.com/technology/denmarks-central-bank-exp...
- aaron695 5y agoTheory: REvil is someone DARPA sent from the future to stop future cyber wars. Here's a list of popular Ransomware onions, REvils is called "Happy Blog" https://www.kiledjian.com/main/2021/3/4/popular-ransomware-darknet-websites https://www.kiledjian.com/main/2021/3/4/popular-ransomware-d...
- adventured 5y agoIt's all just one person stuck in a loop. Predestination.
- aaron695 5y agoI think a college graduate with 2030's Metasploit probably would be enough to force the web to secure itself. A cynic might say 2021's Metasploit is enough. It's hard to guess how big REvil would be. From their job ad - "Teams that already have experience and skills in penetration testing, working with msf / cs / koadic, nas / tape, hyper-v and analogues of the listed software and devices.
- BrissyCoder 5y agoI think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.
- tacLog 5y agoI feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)
- vorpalhex 5y agoThese attacks didn't exist before crypto.
- cartoonworld 5y agoNo, they typically sold stolen information on private/underground/invite forums or IRC. Instead of crypto-randomware, it would be an all out worm or booter that would crush a service who would have to acquiesce to demands. Luckily, there weren't too many good services in existence, Cloudflare didnt exist, c10k was a mind blower, webdev was AJAX, XMLRPC, and CGI. The term TLS hadn't been coined, it was still called SSL, and nobody used it. Instead of a money orders, they would trade trade calling cards, NEXON codes, gift cards, other stolen data like "fulls" or exploits or accounts for compromised infrastructure. People would operate DDoS botnets for cash, spam you with V1@GRA ads from cracked boxes or hijacked relays, and the evergreen scam of fake RMAs. Let me know if "LOAD A PALLET OF CATALYST CHASSIS ONTO A BOAT OR ELSE ILL RELEASE YOUR SERIAL NUMBER DATABASE AND ALGORITHM ON MYSPACE" sounds scary or not. The real difference is now we're 28 years into "Eternal September"[0], the whole planet is participating more or less. Cryptocurrency is possibly an enabler, but if it weren't that it would be Apple or Google Play codes. Just straight up exfil and sell. In conclusion, these attacks didn't happen before Apple store or Google Play. [0] - https://en.wikipedia.org/wiki/Eternal_September https://en.wikipedia.org/wiki/Eternal_September
- smcleod 5y agoThe Microsoft team at a company I used to work for tried to push this very software out onto all staff machines. Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor. The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly after. Companies need to ensure that risks raised by senior engineering teams are taken into account before deploying company wide software.
- raverbashing 5y agoAh but things like "security feel good feelings", being "in the cloud" and kickbacks are more important for the higher-ups in certain companies. And of course, it's hard to believe the (upstream) companies responsible for these weak security practices will suffer any consequences
- lostmsu 5y agoWhat software are you referring to? The article only mentions "VSA tool", and that does not ddg well.
- hoppyhoppy2 5y agoThe article links to https://us-cert.cisa.gov/ncas/current-activity/2021/07/02/kaseya-vsa-supply-chain-ransomware-attack https://us-cert.cisa.gov/ncas/current-activity/2021/07/02/ka... , which says it was Kaseya VSA and links to their advisory.
- deleted 5y ago[deleted]
- chillwaves 5y agoVSA appears to be a proprietary name. They are usually referred to as RMM tools (remote monitoring and management). They essentially are enterprise level back doors with good intentions. Think firewall/antivirus/backup software suite run by a remote team.
- throwaway1777 5y agoThe beatings will continue until morale improves
- genmud 5y agoAfter the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for one of the most impactful cyber incidents yet. Hell, if you invested in January, after most of the stuff blew over, you would be up nearly 20% on your investment. There is even a perverse incentive to not do things and just get cyber insurance to cover you. Since these underwriters generally have no fucking clue what they are doing, you can actually make money on a cyber intrusion if you play your cards right. Only now that insurance companies have paid out the nose with ransomware incidents have they started to wise up. Having worked in the space, its absolutely bonkers what we accept as normal business practices with regards to cybersecurity.
- CyberRage 5y agoHonestly, I'm shocked by this comment. As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market. SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time). Insurance is a trap. once you read the small letters, they don't fully cover the damage, usually only direct. Some have refused to pay due to some shady conditions that they insert into contracts to deceive customers(like any other insurance sector)
- bencollier49 5y agoIf the stock market has distorted the price of SolarWinds that badly, as per your analysis, that's probably a sign that the stock market is massively overvaluing everything, and that we're headed for a gigantic crash. Which by coincidence is exactly what Michael Burry, the guy who predicted the 2008 housing crash, has been saying recently.
- d3nj4l 5y ago
- ineedasername 5y agoThis really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware compromise to date.
- technofiend 5y agoThere is also allegedly a reciprocal agreement to allow extradition and prosecution for cyber attacks. So we'll see if that comes to pass or if it's just a little fake glad handing until you actually try to take them up on it.
- djrogers 5y agoNo, there was no agreement. Putin offered it up knowing the US Gov’t could never accept it.
- aksss 5y agoThat didn’t happen. Biden challenged Putin in a convo, Putin made a rejoinder about giving up criminals if the US gave up theirs. Dumbass Biden was like, “of course”, not realizing the implications of Putin’s remarks or his own ability to step on a rake, and his office promptly (like same day) walked back the comments.
- aksss 5y agoLast time Biden was in office, the whole “red line” rhetoric went nowhere so I can’t say I’m surprised that Russia would test the boundaries. But I’m cynical enough that I also would t be surprised if China did the attack making it look like Russia, or even if the NSA did the attack to make it look like Russia. Or even any European country in between. Such is the my level of distrust for all of the actors involved.
- technion 5y agoReally good thread here: https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/ https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom... When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.
- victor9000 5y agoWow | We received an emergency call from our Kaseya rep to shut down our onprem VSA
- technion 5y agoFollowing this, suspicious write up here: https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/ https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/ > we were already running a broad investigation into backup and system administration tooling and their vulnerabilities. One of the products we have been investigating is Kaseya VSA. We discovered severe vulnerabilities in Kaseya VSA and reported them to Kaseya, with whom we have been in regular contact since then. Additionally, we have, in confidence, also reported these vulnerabilities to our trusted partners.
- koheripbal 5y agoIt is a sad say when Reddit has higher quality details than HN.
- palijer 5y agoWhy is that sad?
- ineedasername 5y agoIn some not-so-distant future dystopia, ransomware hackers will morph into a file encryption service w/ optional data exfiltration as a backup. Just don't stop paying the bill. Or at least that's where we're headed if companies keep giving in to the ransom demands.
- sidcool 5y agoSubscription based Ransom ware.
- ineedasername 5y agoRWaaS. It should come with indemnity against other ransomware hackers where your RWaaS provider will either provide you with backups &/or go after (negotiate, hack, or physically assault) the other hackers.
- 6c696e7578 5y agoA few years back didn't bitcoin botnets patch/fix their nodes so that other ransomware/malware operators didn't take over their valuable mining stock? The delicate ecosystem of the unwatched computer.
- ineedasername 5y agoI'm tempted to clone my backups to an unsecure computer deliberately infected with ransomware that exfiltrates data so that I have a tertiary, albeit very expensive, offsite backup. At least if I could negotiate negligible maintenance payments with a balloon payment should I ever need to pursue file restoration. But if REvil etc. are going to branch out like that, they really need to follow the traditional protection racket and engage in, let's say, aggressive counter measures with the potential for rapid bodily disassembly of any competitors that come along.
- aksss 5y agoBlaming companies for paying a ransom is like blaming a ship captain for surrendering to a pirate on the high seas. It’s ransom or death. The captain’s nation wasn’t providing adequate security against piracy, another nation was condoning privateers. What do you expect them to do? Or better yet, what happened with privateering amongst the nations in history? First each nation unleashed its own privateers, then they built up and deployed their own navies, and the countries that couldn’t keep up fell under a new Pax Romana aside from fits and struggles. Where are we in this process today?
- adnmcq999 5y agoI got an abnormally high number of robocalls today - could this be related?
- RocketSyntax 5y agothats bad because kaseya protects other companies
- TeMPOraL 5y agoWell, "protects". My actual experience with Kaseya is that it's an employee monitoring tool that, in a pinch, can also be used by IT to manage machines remotely.
- Black101 5y agoThanks IT
- SheinhardtWigCo 5y agoOddly explosive headline, considering: > It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details. So why "colossal"? > "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency. The BBC is going with "colossal" in their headline simply because the guy who discovered the incident said so?
- deleted 5y ago[deleted]
- decremental 5y agoHacker News hit by "oddly explosive" BBC headline.
- mdoms 5y agoThe BBC headline uses 'colossal' in quotation marks. So yes, it's a quote.
- ruined 5y agotuesday? again? no problem
- kong1 5y agoThe elephant in the room is that over 90% of these attacks are targeting Microsoft Windows [0]. [0] https://www.statista.com/statistics/701020/major-operating-systems-targeted-by-ransomware/ https://www.statista.com/statistics/701020/major-operating-s...
- eidelweissflow 5y ago“ At a summit in Geneva last month, US President Joe Biden said he told Russian President Vladimir Putin he had a responsibility to rein in such cyber-attacks.” I don’t understand how Putin can stop these attacks unless he is personally responsible for them. Imagine someone in the US hacking systems in Russia or China. How in the hell Biden would know who did that and stop them? The naivety of US government is just astonishing. I’m sure Putin just laughs when he hears such accusations. We can’t stop these attacks by asking people not to exploit the systems. We can only stop then by building more secure systems and improving the processes within organizations.
- hamburglar1 5y agoIt may be worth considering if you are naive in thinking that Putin doesn’t explicitly fund and direct the execution of cyber attacks against the west as a lever in improving Russia’s own relative standing. Why do you think he wouldn’t do so? American sponsors the same cyberattacks on Iranian and North Korean entities.
- aksss 5y agoDefine “fund”. I don’t think he directly funds most of those operations simply because there’s no need. Imagine if Merrick Garland announced that he was using prosecutorial discretion to effectively decriminalize cyber attacks on foreign countries as long as they didn’t affect US interests and the best of its allies. The federal government wouldn’t need to fund the entrepreneurial ambitions of the US talent pool. They’d self-fund and make a mint in the process. It’s privateering of the modern age. So Putin only “funds” them in the sense that he allows them to operate, providing them implied letters of marque.
- genmud 5y agoUh... maybe Russia has a bad rap: By providing cybercriminals a safe harbor to carry out their attacks. By refusing to cooperate with foreign LE unless they have targeted RU citizens. By using the LE/MLAT requests that are sent to them to track down these criminals and force them into moonlighting for state intelligence services or be arrested.
- cyberpolygon123 5y agoIt's amazing that the World Economic Forum was able to predict a global pandemic in 2019 with Event 201 [1] and widespread cyber attacks in 2021 with Cyber Polygon [2]. Their timing for conducting these trainings is impeccable. We'll probably need Internet Passports, with malware scan certificates, to get online safely. Hope you're not an anti-scanner (it's totally secure). Evil Russian hackers will be a convenient scapegoat for food supply shortages and power outages, but we really needed climate lockdowns, anyway, so we're actually saving the environment here! So begins Act II of the global feudalist coup. [1] https://www.centerforhealthsecurity.org/event201/ https://www.centerforhealthsecurity.org/event201/ [2] https://www.weforum.org/projects/cyber-polygon https://www.weforum.org/projects/cyber-polygon
- oliv__ 5y agoMake it Vaccine Internet Passports
- lettergram 5y agoI’m really curious how this is going to go down. We have so many simultaneous problems it’s quite astonishing. I have a feeling people who don’t get the vaccine are going to end up in camps. I know that’s already true in some countries. I think we all feel it, frankly. Left, right, center... it’s coming to a head and we all have a feeling of impending doom. It’s really quite interesting (I’m not religious) how close this follows with revelations. The numbers to purchase food, the rounding up of people, the pandemic, etc. I personally have hope, I’m not sure how the trials are going to shake out. But I’m confident the feudal lords are less competent and over confident than they realize. We’ve been in a feudalist system really since WWI in the US (longer globally) and progressively so through the 1960s when it took hold globally. At this point, they’re correct, they need a global reset, because the games over. The mask is off, now it’s a race to see who can recognize the truth. Those in power are losing control. We shall see if they can keep it and / or if they resort to violence to do so.
- insert_coin 5y ago> I have a feeling people who don’t get the vaccine are going to end up in camps. I know that’s already true in some countries. That is a lie. In no country that is happening. I mean, everything you said is a lie, but don't have more time to waste with "arguments" like yours, just wanted to make sure everyone else here knows that that baseless claim in particular is a lie.
- u678u 5y agoI kinda feel at this stage we should go back to air gapped intranets and working from the office again. SAAS just isn't worth it, and the other things like stack overflow you can do from your phone.
- dehrmann 5y agoSaaS offerings that are in a browser tend to be pretty safe. I'd be more concerned with data theft than my network being compromised.
- aksss 5y agoSaaS is so totally worth it and is hardly the problem in this case. Though the Internet connectivity and auto-updating is getting notably untrustworthy.
- RalfWausE 5y agoThe paradox is: The company i work for is (in terms of modern technology) decades behind (we just don`t need it), but in the context of the every bigger growing cybersecurity risk its perhaps an advantage...
- bruce343434 5y agoSure is. Whenever I see a company or product brag about how many millions of lines of code it has I shudder. What could be hidden in that maze? I bet tons of vulnerabilities. You don't need so much code, and if you do - you're doing something egregiously wrong.
- tasuki 5y ago> The gang was blamed by the FBI for a hack in May that paralysed operations at JBS - the world's largest meat supplier. Who is the bad actor here?
- orf 5y ago> The source of these indicators are auto-emailed Kaseya VSA Security Notifications indicated the "KElevated######" (SQL User) account performed this action. We're hesitant to jump to any conclusions, but this could via suggest execution via SQL commands. Some form of remote, unauthenticated SQL injection then? 1. https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e https://www.reddit.com/r/msp/comments/ocggbv/comment/h3u5j2e
- swarnie_ 5y agoSome of those comments are straight up nightmare fuel for sysadmins > We are severly fucked. Up to 2100 endpoints are infected right now, most are desktops but also servers. > We have been hit as well 1000 endpoints. What is your plan of restoration? Happy 4th of July weekend everyone.
- vmurthy 5y agoSlightly tangential but relevant to people who are interested in how some nations are now sponsoring cyber attacks ( Not saying this "colossal" one was state sponsored :-) ) "The Lazarus heist: How North Korea almost pulled off a billion-dollar hack" [0] [0] https://www.bbc.com/news/stories-57520169 https://www.bbc.com/news/stories-57520169
- dgudkov 5y agoSo far events like this one only confirm my theory that sooner or later elected governments will start treating internet security similarly to offline security. Offline security is managed using the army, guarded borders, and internal policing. Expect similar measures in the cyberspace. The damage from cyber-attacks will only grow. When the damage they cause will start being non-trivial (and it absolutely will at some point), governments will start creating safe internet zones with heavy policing.
- dannyw 5y agoGovernments can stop a lot of those breaches if they applied financial and criminal (i.e. imprisonment) penalties to executives for failing to secure their systems. If every CEO and CFO's first priority is "How do I not go to prison?" and the second priority is "How do I enrich shareholders?", then security _will_ be fixed. Simple as that.
- dgudkov 5y agoOf course, a supply-chain software company must have strong security and bear full responsibility for not having one. However, in general I wouldn't be so fast to blame victims. Strong security isn't cheap nowadays and adds to cost of doing business. To make things worse, cyber-attacks become increasingly more sophisticated, so the "security tax" will only grow and fewer organizations will be able to afford it. That's why consolidation is inevitable - it will just become more economically reasonable to share the cost of cyber-defense.
- aksss 5y agoSecurity is not cheap, in real terms. Also, security is not easy to understand even by the technically competent. It’s also boring AF. Processes and tools get impacted and it’s very hard to turn the metaphoric ship that is a business operation. I know it’s contrary to the tasty trend of blaming CEOs for everything, but IME this is not a CEO problem except in a relatively narrow sense. It’s a COO problem at least as much, and a problem whose resiliency is enforced by every manager up and down the line who doesn’t want somebody pissing in their corn flakes while they’re trying to spin five bowls of corn flakes on sticks (to mix metaphors). I’m gobsmacked by how many relatively young adults lack some basic skills at thinking systemically and this retards efforts as well - even conceiving of the motivations driving initiatives, a lack of threat awareness, etc.
- dannyw 5y agoI wish a country would pass the following law: 1. Any company that makes software with low-level access to systems (i.e. admin privileges on Windows, root privileges on UNIX systems) is criminally responsible for any security breaches of its software, unless it can prove that it took all reasonable steps to keep their software safe. 2. The CEO and CFO will receive a mandatory 30 day jail sentence on the first instance of a breach with consequential damage. 3. The jail sentence will be tripled if the company downplayed or omitted to report any security breaches. 4. The minimum sentence increases by 30 days for each subsequent breach linked to an executive, and resets after 10 years of no breaches.
- kkirsche 5y agoI’m not in favor of this. For this to be reasonable, coming from someone who writes exploits for work and fun, you need to define all. Otherwise you’ll be unreasonably putting people in already overcrowded and underfunded jails. Instead of jail, consider a more reasonable and realistic punishment.
- aiisjustanif 5y ago> criminally responsible for any security breaches Criminally? A bit wild. MIcrosoft would probably be bankrupt by now. Just look at PrintNightmare from this week.
- rixed 5y agoI get the outrage when a company leaks its customer data due to a security breach (or, really, for any reason). But punishing the victims of a crime to encourage better protections? Isn't that the same as to punish house owners in case of burglary for failing to protect their home appropriately?
- de6u99er 5y agoWouldn't be surprised if this was connected to the accidentally disclosed 0-day PrintNightmare vulneravility.
- qaq 5y agoIn light of all this escalation could anyone advise of a good VC firm to talk to about funding a product in cyber security space?
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- Mountain_Skies 5y agoAnd despite this, most companies are trying to get senior software developers for the AppSec programs but can't because they don't want to pay senior software developer salaries, or even software developer salaries. So the positions remain open, month after month, sometimes year after year. I've been told several times this is because AppSec is considered by higher management to be mostly a clerical type position or at best, Application Support. Which would be fine if that were the level of experience and bundle of skills they were trying to hire, but it's not. What makes things even more difficult is that many companies have a policy of only hiring citizens and permanent residents for these positions but have outsource rates floating in their heads. If you want to have an AppSec group populated with people who can explain (and often argue) security vulnerabilities in the code of others, you're going to have to pay for someone with enough experience to do so credibly (or you'll lose buy-in from developers) and knowledgably (so you're not wasting developer time with false positives).
- NoImmatureAdHom 5y agoStart demanding chips without back doors! Now! Intel without ME AMD without PSP Work for a better future with a fully open chip architecture
- Paul_S 5y agoWhat are those VSA tools used for in practice? Can anyone in IT who uses them tell us. I don't mean what is sold as I mean what it is used in reality, actual operations performed.
- jcims 5y agoBasically they give you mechanisms to run nearly the full gamut of IT operations remotely. Managed service providers will use these products as the foundation for their offerings...some of which are compete IT outsourcing, others are domain specific and some package it with turnkey products in which they retain responsibility to maintain the hardware. I used to run a small security consultancy and nearly got into this business to expand our operations and get some of that sweet sweet recurring revenue. The problem I found at the time was that none of the software companies selling products that I would use were building in a security posture that I was even remotely (hur dur) comfortable with.
- aksss 5y agoVSA is an RMM tool, remote monitoring and management. They work as local agents to report stats, events, sw/hw inventory back to an aggregation point (on prem or in cloud), facilitate software deployment, approve and deploy updates, script execution, device configuration and compliance, and broker remote screen sharing sessions like teamviewer. These are what they’re sold as and literally what they’re used for daily to manage and monitor thousands upon thousands of endpoints of all flavors. In a traditional on-prem Windows corporate environment these functions would have been offered by the on-prem Microsoft stack like domain services, group policy, WSUS, SCCM, SCOM, RDP, etc., and the overhead was enormous. In a diverse and dispersed environment, these toolsets have adapted accordingly - multi-platform, over-the-air, asset light. Now even internal enterprise IT shops use flavors of RMMs that MSPs would use for SMBs. MSPs can simply apply these systems to more SMBs via economies of scale, whereas an SMB could rarely afford the overhead of maintaining the tooling let alone the circus that is device management. So if you break an RMM platform used by an MSP the impact can be quite broad, and include larger enterprise IT operations. It’s easy to say “don’t use RMM tools, or switch to Macs”, but this kind of simplistic reaction belies an understanding of the environment and the need.
- kaimorid 5y agoThis is why I study
- sloansc 5y agoWorking through the IoC, I see these lines copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe Why append a random number to a copy of certutil.exe other than to change the file signature?
- slumdev 5y agoCyber Polygon begins. https://www.zerohedge.com/geopolitical/cyber-polygon-will-next-globalist-war-game-lead-another-convenient-catastrophe https://www.zerohedge.com/geopolitical/cyber-polygon-will-ne...
- bigmattystyles 5y agoIronically, featured on Kaseya homepage's award section is the Cyber Security Excellence Award for 2021. It's obvious all those awards are always kinda pay-to-play(or win), but in this case, it really shines a fact of how BS those awards are.
- sxhunga 5y agoWow 'colossal' cyber-attack
- jpster 5y ago> Mr Biden said he gave Mr Putin a list of 16 critical infrastructure sectors, from energy to water, that should not be subject to hacking. This sounds like a concession of major weakness on the part of the US. I guess we already knew that Russia has outmatched US’s cyber capabilities, but I was surprised to see it acknowledged by Biden in this way. And if Russia ignores this edict, it means they’re doing so in the full knowledge that it may be seen as a declaration of war? Which would lead the US to respond with its own war-like actions? High stakes.
- aksss 5y agoI don’t think the US is outmatched in capabilities compared to Russia. The difference here is the tacit permission for private criminal groups to operate in Russia as long as they don’t attack Russian interests. If the US criminal justice system effectively decriminalized cyber attacks on foreign entities by the private sector, a lot more people on this forum would be rich and the scourge unleashed would make the Internet a far more interesting and hardened landscape. In other words, it’s less a product a higher class of technical capability maintained by the nation so much as the work product of a deregulated and privatized industry operating in a blue ocean.
- dt3ft 5y agoIs it too soon to say “this is what you get when you cut costs at the wrong place - your IT guys”?
- prirun 5y agoWhat I'd like to see come out of this is for corporations to view customers' collected data as a liability, not as an asset. Then maybe they would think twice before collecting and storing unnecessary customer data. Or if they have to collect it, they would expire it as soon as possible. This is somewhat hampered of course by regulations that may require hanging on to data.
- MR4D 5y agoI wonder how much (if at all) the new Windows 11 security features would protect against this sort of thing. Given the fairly vocal resistance to the TPM 2.0 requirement, if the answer is nothing, then I wonder why it is even necessary. As a Mac/Linux user, I’m out of the information flow on this topic except for a surface level understanding, so please person my ignorance, as I’m genuinely curious.