The Dever Ransomware Experience
wilbursecurity.com
wilbursecurity.com
Also, I can’t help but thinking that the global internet that we’ve created is highly irresponsible. That criminals with sufficient skill and means can anonymously pull off these kinds of crimes with little chance for pursuing justice is indication of some fundamental flaw in the internet’s design. While people should have the right to be anonymous, there’s simply too much potential for abuse by such criminals. I wonder if the internet is ripe for disruption via redesign of core protocols. As I recall, this has been discussed on hn previously but I’ve lost track of such research..
The difference is how malleable the internet infrastructure is compared to the real world. Would ransomware have taken off like it has without bitcoin? Is there some technical change to bitcoin that could make it less attractive to bad guys?
Monero is much harder to purchase in US
It's definitely an inhibitor for the attacker. For a start, it took days for them to get payment. The current "our Onion site will detect the payment and release keys automatically" took a human workflow, which had to impact their scale. I have no doubt some sort of mule received the payment, but it's still much more traceable if overseas LE actually wanted to investigate. And managing that mule again had to hurt scale. The amount of ransomware we see today could never have happened without Bitcoin.
Edit: that too started with an open RDP server. All these years and we're seeing the same vectors in this write up.
Just put up cameras with facial recognition everywhere, require every citizen to have biometric IDs (face from multiple angles, fingerprints, DNA), make covering your face illegal and bam you catch like 99% of bike thieves.
>Would ransomware have taken off like it has without bitcoin?
Probably, yeah. Gift cards work well too for example (they're just not as convenient), and I'm sure there are plenty of other ways to transfer money too if you're willing to incur like 50% transaction losses.
>Is there some technical change to bitcoin that could make it less attractive to bad guys?
Bitcoin already tracks every transaction ever. You'd have to somehow prevent mixers from existing, but I'm not sure how that'd be possible.
Steve Gibson has been heavily covering the increase in ransomeware on his excellent podcast Security Now. From SN I’ve learned some interesting points, including that Ransomeware-as-a-Service is now definitely a thing. There have been a few major operations which hand out ransomeware packages to unethical hackers in exchange for a % of the Bitcoin they collect.
I can only see ransomeware becoming more and more of a problem in the future, though I certainly hope I’m wrong.
I also think that we've begun a reassessment of just how much information needs to be stored, because "Data is a toxic asset." A lot of these systems have data they don't need mixed in with mission-critical data, which raises the complexity of restoration.
- I had Windows Server 2016 with few Hyper-V VMs running
- RDP was exposed to the Internet
I remember I was working on that computer, and the screen got locked, like someone pressed Win+L. So, I logged in and saw the folder on my desktop called, if remember correctly "Process Explorer 2" or something similar. The screen got locked on me again after a few seconds. I immediately realized the computer got infected. But after a few minutes, I had a very important meeting and only came back to investigate after about 3 hours.
Results:
- most of the files on the computer were encrypted. But files, which were in use (should I say "locked"?) - stayed. For example, VM disk images stayed unencrypted (but not metadata). That's how I saved one VM, which was somewhat important for me.
- I had Synology NAS with btrfs connected via SMB to that Windows Server and few folders got encrypted. But because I have daily snapshots - I restored that in few minutes.
After that incident, I reinstalled Windows Server (this time 2019) and started to pay more attention to the security, installed winlogbeats and found, that RDP is getting brute-forces at about 400 000 attempts / week from ~55 000 IPs. So, I installed fail2ban analog for Windows: https://github.com/DigitalRuby/IPBan and now I'm getting about 600 failed attempts/week
Here is the screenshot of how the number of RDP attempts decreased after enabling IPBan: https://hsto.org/webt/oq/q1/ir/oqq1irnzeagwsqnbfpe4gbl9f_o.j...
Also the article never really identified how the "patient zero" machine was infected in the first place. RDP brute force?