What's it like to negotiate with ransomware gangs?
redtape.substack.com
redtape.substack.com
Corporations (and the governments that are supposed to set and enforce standards) are clearly failing to protect the data that is collected about people. These criminals are increasing the incentive for corporate data security.
The Equifax case is a good example of the problem. They leaked data on lots of Americans, who never agreed to their data being collected, they externalized an enormous amount of damage they created, and they are still in business. Government is clearly failing here.
I feel safer knowing that there are people out there, hunting down these unsecured caches of data.
Maybe if the ransom paid was required to be spent on data security improvements...
There's very little difference between maliciously encrypting someone's data once you have managed to establish code execution vs exfiltrating all of the data and then using any PII to open lines of credit.
For you as a consumer, the former doesn't harm you. The later has the ability to harm you quite a bit in ways that take months/years to sort out. Do you really feel safer because the criminals that cracked these systems flipped a coin that landed on the "extort our victim" side rather than the "free leads to customers of our victims" side?
So I don't disagree with your premise, I'm just not sure it's actually true in real life, where companies are not punished by anyone for being lazy.
Are there any examples of orgs that have been repeatedly hit by ransomware over and over?
Working backups are not enough to insulate you from this threat. If you allow an attacker to remain within your systems long enough you might find they've encrypted all your backups!
1. The victim organization that has my data gets everything encrypted and is forced to pay a ransom. 2. The same happens, but the hackers also release the stolen data, including my PII. 3. The hackers just sell the stolen PII from the start.
As a consumer, I far prefer option 1. Maybe it will teach them to protect their system, and my PII, better.
If my PII is released somehow, well that's what used to happen anyway. So it not happening is an improvement.
I also don't think the people being ransomwared are the same people who try to weaponise your data, hospitals being a good example.
"They would lose a lot of reputation if they broke their side of the deal."
What reputation? Is there some sort of website where I can go read reviews of a ransomware gang? Even if there were, what's stopping the "bad" gangs from pretending to be the "good" ones? Trademarks?
It's criminal but the principles of business still apply.
My company bought a small business and it happened next day. A hole in RDP that was simply open to the internets. No backups, no failover, just a regular business, you know. Partially my fault, as this thing should have been evaluated/fixed before the deal. Convincing the owners that it wasn't me (I just got an administrative password) was a separate fun.
What's the magic number to make you think that it was/wasn't an inside job?
I have no idea if that is actually done, but the criminals could simply cryptographically sign a unique message for each attack.
Ransomware operators are as trustworthy as any corporation, because they are a corporation.
My opinion about it is that many companies don't understand their systems (and yes, I do blame Microsoft, Apple and for that matter Salesforce or Oracle). However, many people don't understand their microwave ovens, myself included, so perhaps it's unrealistic to start that conversation and perhaps focus on the pragmatists, like Art.
Active directory and domain controllers.
Ransomware is just the attack vector.
At the end of the cyber kill cHain lies AD.
Then when the payload has been installed on the victim's computer. The next step is to spread and also to get control of as many machines as possible in on the same and neighbouring networks. With the eventual goal of command and control.
When unimpeeded, these attacks now take 5-10 minutes.
From here they lay low, for months.. Then the shit really hit the fan when they take the domain controller infrastructure through a GOLDEN TICKET using KERBEROASTING attacks. Then Kansas is going bye bye. You better pray your competent IT leadership has taken steps to make IDENTIFY, DETECT, PROTECT, RESPOND, RECOVER dimensions (NIST framework) a reality across the technologies your company relies on.
MITRE defines a generic framework for hacking attacks:
- INITIAL ACCESS
- EXECUTION
- PERSISTENCE
- PRIVILEGE ESCALATION
- DEFENSE EVATION
- CREDENTIAL ACCESS
- DISCOVERY
- LATERAL MOVEMENT
- COLLECTION
- COMMAND AND CONTROL
- EXFILTRATION
- IMPACT
From here I recommend you read the MITRE ATTACK framework, great reading!
https://www.youtube.com/watch?v=bkfwMADar0M
https://www.youtube.com/watch?v=b6GUXerE9Ac
https://www.youtube.com/watch?v=_SsUeWYoO1Y
Real talk!
I would have expected a bit more sophistication, like hidden URLs in emails that autoresolve, at the least. Not my area, though.
Better finetune your email security, because humans are a hard problem. Loads of awareness, phishing drills and information sec training is needed.
Paying ransom is bad, but it is bad for the commons and relieves one from a short-term pain point. Just like pollution, the cost will be paid from someone else later.
Holy f..
I knew that is was bad. But that is way worse then i expected.
Source: https://www.sophos.com/en-us/medialibrary/Gated-Assets/white...