FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals
krebsonsecurity.com
krebsonsecurity.com
> Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career.
This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
Not to say that they are the culprit; just that state sponsored and and money driven aren't necessarily exclusive.
They're also involved quite heavily in the illegal drug trade and bootlegging cigarettes and alcohol, using their embassies and diplomats as a distribution network, as well as counterfeiting currency and pharmaceuticals, running an international restaurant chain [2], building statues for tinpot dictators [3], shipping citizens off to Russia as "contract workers", smuggling ivory, trafficking arms, and previously leased out embassy buildings in Berlin to a hostel [4]
[1] https://en.wikipedia.org/wiki/North_Korea%27s_illicit_activi...
[2] https://en.wikipedia.org/wiki/Pyongyang_(restaurant_chain)
[3] https://www.bbc.com/news/magazine-35569277
[4] https://en.wikipedia.org/wiki/Embassy_of_North_Korea,_Berlin
https://www.coindesk.com/ban-all-ransomware-payments-bitcoin
The happy ending of this would be continuing to pay terrorists who keep you IT top notch...
However, not all backups are continuous and pervasive. There are often backup windows, gaps, and processes that halt with no one noticing. Ryuk also actively disables and deletes backups to maximize impact, while also seeking out mount points that might be backup targets - and encrypts those as well.
Of course, we're also talking about hospitals here. Even a well-managed system with hourly differential backups leaves plenty of time for radiology data to be lost in the critical hour before life saving surgery.
More realistically though, how long would it take you to discover and remove a sophisticated penetration, then restore every device, ensure none of the restores are also infected by the malware that had probably been there for a while, and bring a hospital system with thousands of impacted systems back online? 72 hours? A week? A month?
What happens to the patients? Admissions to the emergency room? What if adjacent hospitals are also hit, or are already impacted by the COVID spike and have no open beds?
People literally die due to hospital ransomware attacks. No one deserves that.
Ransomware is akin to kidnapping, it's just the data and customers that are held hostage, not kids or loved ones. Always blame the criminal, never the victim.
There is an expectation that information and services are to be secured with a certain level of care and standards. I don't see how that applies to people.
> Always blame the criminal, never the victim
This argument excludes the concept of negligence. If the victim was grossly negligent then they are also to blame.
If a hospital had random power cables everywhere and someone tripped over one and unplugged an important device, that would be far far more on the side of the hospitals fault than an attack on the computer systems.
That has happened in the past: https://en.wikipedia.org/wiki/Gimli_Glider
It's easy to say "well they should've filled the tank" when you're comfortably sitting on the ground, but it's little consolation for the people 30,000 feet in the air, or for the patients in hospital waiting for time critical, life saving treatment.
There are many organizations which are doing regular secure backups, but are doing so in a way that can be sabotaged once a skilled attacker gains domain admin privileges, and sabotaging backups is one of key things that the attackers are doing after they are in the network and before triggering the ransom encryption. We're not talking about a virus randomly spreading, in such high-ransom targeted attacks the preparation before triggering a ransom is done manually by skilled teams going on from one target to another.
In good countries, we maintain important records and have roll back capabilities on most of the things we control ourselves. But that doesn’t necessarily include the MRI machines windows XP that is maintained by some third party supplier that operates through another 3rd party seller, and that’s just one of the 3000 things that can go wrong.
Then there is the parts where attacks will affect you, even if they don’t do any damage that can’t be reversed. Typically global internet access gets shut down during an attack, but that makes transfers harder. It also makes acute arrivals harder, because the ambulance helicopter might not be in range of your “internal internet” and thus may not be capable of feeding you important live data.
Some attacks target the network itself, and while you’ll generally have a good set of people running that, they aren’t always a match for nation state backed hacking tools.
So there is just a billion things that can go wrong, even if you have the best of the best working on it, and in many countries, there is a good chance that’s not even the case. I can count myself lucky to work in a country where we take digitisation very serious in the public sector, and I can easily see why things could go wrong.
Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.
On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare
Hard to see how they are terrorists? What are they pushing to accomplish with their terror campaign.
Anyways, my health care system constantly assures me security is its "top" priority and "state of the art".
> On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone.
I'm not sure how well that would work. Ransomware generally has responsive and helpful support people, because without that it will be hard to convince victims to pay. If they spend their time instilling fear instead of confidence in the payment process, then no one will pay.
From what I have recently learned, this may no longer be accurate. The latest Risky Business happens to touch upon the subject.
Criminal groups in Russia have financial arrangements with the central government, and may occasionally do some freelancing for them. Now China is getting on the same boat, but apparently with less entrepreneurial approach to target selection.
If they are the only ones, I would be very much surprised. The net result is that ideological and for-profit motives will be harder to distinguish, as the same crew may well be doing different campaigns for different reasons at any given time.
Sure, some of the campaigns might be ransomware, some might be terrorism. I don't see how this disagrees with what I said.
I know anti-Russia propaganda is at its height now and I even admit it's weird watching how worked up Americans get about stuff they're been doing all around the world since WWII, but as bad as Russia might be, I don't really buy they're behind it.
I wouldn't characterize it as an attack, its closer to "preparing an attack". And why not - the former President of the United States outright said on TV that the US had placed dormant implants deep inside key Russian infrastructure without pulling the trigger as a preparations/part of countermeasures for electoral meddling in 2016. The decision to pull the trigger was left as an option for his successor. I do not doubt the Russians may be getting similar "insurance" against a possible unfriendly posture from Washington starting January 2021.
We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losing their computer systems.
>We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losing their computer systems.
You might be partially right. But I see it more of them trying to convince you to take a deal. They're trying to sell you something: your data. They want you to have as little fear as possible that you can get your data back. They want you to be 100% confident in the payment process. Yes there's fear of what would happen if you don't pay. But that's a path they want you to avoid. You could almost categorize any negotiation this way. The person you're negotiating with will try to convince you how good it is to take the deal and how bad it is to not take the deal.
The other difference between this and regular terrorism is that regular terrorism wants the general population to be scared. In ransomware, they have no goal at all of making the general population scared. In fact making the general population scared would be counterproductive, because it could lead to people patching their computers making future profits harder.
From Oxford dictionary. Terrorism absolute includes the political struggle. The point is that terrorism uses violence and intimidation to further its goals and that it has no legal base for it.
(sarcasm / irony / etc)
On the other hand, I believe that the word terrorism and the characterization of acts as terrorists should not be taken too lightly as it can lead to misuse of power rather quickly.
Fear of losing money if you don't pay the ransom: yes. But this could sort of apply to many salespeople, marketers, negotiators. They want to make it sound very good to take the deal and very bad (yes, maybe scary) to not take the deal.
The way the fear is targeted between ransomware and terrorism is also quite different. Terrorism wants the general public to be scared. Ransomware doesn't want the general public to be scared, because that would lead to people patching their systems, reducing future profit opportunities.
Perhaps an even closer corollary would be our embargo of Cuba, which effectively cut them off from having viable trading routes. We did it to destabilize their economy, so they would get rid of Communism because we don't like Communists. How many people have died of starvation because we're artificially dampening their economy?
As others have noted: while this instance is unlikely to be terrorism, this is a tool that is useful in terrorism and has been used as such in the past.
> The use of violence or of the threat of violence in the pursuit of political, religious, ideological or social objectives
One could argue these are all political. In the end, you can deduce anything to being political.
Or this definition by Alex P. Schmid from 1988:
> "Terrorism is an anxiety-inspiring method of repeated violent action, employed by (semi-)clandestine individual, group, or state actors, for idiosyncratic, criminal, or political reasons, whereby—in contrast to assassination—the direct targets of violence are not the main targets. The immediate human victims of violence are generally chosen randomly (targets of opportunity) or selectively (representative or symbolic targets) from a target population, and serve as message generators. Threat- and violence-based communication processes between terrorist (organization), (imperiled) victims, and main targets are used to manipulate the main target (audience(s), turning it into a target of terror, a target of demands, or a target of attention, depending on whether intimidation, coercion, or propaganda is primarily sought".
Source and more scholar definitions see [2].
For in-depth criteria I can recommend Alex P. Schmid's "Revised Academic Consensus Definition of Terrorism" from 2011 [3] as it is what scholars at Leiden University use.
Regarding the criterium is it always political, see #9:
> 9. While showing similarities with methods employed by organized crime as well as those found in war crimes, terrorist violence is predominantly political – usually in its motivation but nearly always in its societal repercussions;
(Its too large to quote all 12 criteria; again, please see [3] (no HTTPS))
Sometimes, the goal of ransomware is political, but its disguised as if goal is financial. This provides cover for e.g. a state actor.
[1] https://en.wikipedia.org/wiki/Definition_of_terrorism
[2] https://en.wikipedia.org/wiki/Definition_of_terrorism#Schola...
[3] http://www.terrorismanalysts.com/pt/index.php/pot/article/vi...
Not that that is any way a defense, and I'm sure there was as much a self-interested motivation of "We are going to be hit hard if we ransom a hospital _now_" as much as "doing the right thing"...
You're correct. Said ransomware case is now under the investigation of involuntary manslaughter, as a woman died during transfer to another hospital: https://www.dw.com/de/haben-russische-hacker-den-tod-einer-p...
Edit: got to point
The Pentagon have at least suggested that there’s a potential for a nuclear response to a significant enough cyber attack.
That's a play "why do you rob the banks". Some choice those hospitals have
Given the (extra-)legal powers that are activated by that word, I'd be circumspect in using it.
Many crimes are "horrifying, terrifying, [and] disgusting" without rising to the level of terrorism.
Strictly speaking, if people we don't like attack a hospital it's a war crime; if we do it, it's an accident.
> so how is it not terrorism?
Murdering civilians during a war is a war crime; that doesn't mean murder automatically equals terrorism outside of war.
And yes, it matters if an enemy or friend does it. That's so obvious to not merit discussion.
First it was terrorism because it's deliberate; now it's terrorism because it creates confusion, death and fear.
Here's just one example that checks all those boxes and is, of course, not terrorism:
Note that Doctors Without Borders believes it was deliberate.
But I'm cynical, so I also think that terrorism is often just masqueraded greed, a money grab under the guise of doing something political.
The other involves financial loss and probably a temporary shut-down of one or more hospitals.
Frankly, a cyberattack is the kind of thing a hospital can and should be hardened against. This is an administrative and regulatory failure being dressed up as "terrorism."
Criminals that use ransomware should be prosecuted and sent to prison, not disappeared to Guantanamo Bay and tortured.
I worked on critical systems in the energy sector and while we were buried in federal compliance paperwork, the systems and software were always a target that was evolving and hard to keep up with. The energy management system was a huge bureaucratic battle between IT and engineering and there were compromises made (that I didn't always agree with) for the sake of support and maintainability within the IT tech landscape. For compliance reasons, and because the system is "offline", upgrades and patches were really challenging and honestly kind of terrifying. The risk of taking something down and impacting grid operations was harrowing. It really made our small team reticent to touch anything. I don't envy these hospitals, it's a really tough battle to ensure your systems are always up to date, locked down, and operational.
Also, a hospital going down is not a small problem. My wife is an ICU doctor for a large hospital and her patients' are sometimes hanging on by a thread. If they lost their EHR and patient history, I imagine that would present a really scary challenge. It's not just financial.
Patients dieing because people don't work 80hr weeks? Why are you working for such a shit management team? That's management's problem. Don't like it? Quit. Really don't like it? Name and shame.
It's unfortunate we live in a day and age that kind of thinking is necissary but it is. Burnout in the middle of a pandemic can get you killed.
If Hospitals nation-wide are under attack, it's a massive national security issue.
We need to figure out some kind of new way to secure general purpose devices - and also - there needs to be much more investment in thwarting and retaliating against these people.
If some random hackers and do this - imagine how badly and quickly a foreign state actor with deep pockets could shut things down.
https://www.bloomberg.com/amp/news/articles/2020-10-28/u-s-h...
Patients are being turned away: Wyckoff Hospital hit by computer virus
https://www.reddit.com/r/nyc/comments/jju0rp/wyckoff_hospita...
It's also ironic that for all the pervasive government surveillance of the internet, this stuff just flies right under the radar. I thought the whole point of this surveillance was for our protection?
Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.
But also what are we doing running life-critical software on Microsoft-made OS? This is idiotic, it is great for gaming and excel but not hospitals. Microsoft could make another OS based on Linux or BSD and it could not be hot garbage. But that would eat into profits and take...effort. Linux and ChromeOS + 2FA is much better although not perfect.
Be careful what you wish for. Many regulations have been written in blood.
It's been a long time since 1996, but most of the IT messes inside health organizations are self-inflicted. HIPAA and friends don't mandate which operating systems you use, specify approved encryption algorithms, or tell you when and how to update your computer systems. These are all choices left to the implementation teams, and they chose to work with vendors who aligned their solutions to information architectures that just don't change very fast. I think if you compared this IT situation to, say, large scale manufacturing in the US you'd find similar problems of outdated platforms supporting expensive and hard-to-change niche software. And it's probably market forces, not government regulation, that's responsible for this similarity.
It is kind of crazy that hipaa compliance isn’t encompassing enough
Hospitals need full backup machines and with health care costs already through the roof, that will just add more. Even if you have all your order entry machines setup to not make external Internet connections except to update servers, one bad e-mail getting through and you could be in trouble.
No way the operator is copying a 5GB+ dicom file to your record in your EMR manually.
You NEED to have the patient name added via modality worklists to reduce errors (ie. add the pt to the MRI software before the scan, and send the scan to the EMR once it's taken).
The worst thing is, this protocol is old and insecure. They just don't have the IT chops at hospitals to handle this.
I worked in hospital IT and it was a tough environment: it seemed like we had at least one big system rollout (EMR, radiology, lab, etc.) every year. It was difficult to manage when the hospital was paying a little below median for the area, now they are way below that where I live (western MA).
Linux would end up the same way, some ancient kernel/distro because the closed source driver only works on that one ancient installation.
Or to put it another way, the worst thing possible short of no regulation at all.
Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.
The struggle with these devices is that they're often cheap embedded systems that never receive firmware updates, so they do present a security concern. However, they're also immensely useful and have without a doubt saved lives.
Thats it. That's the American healthcare field and why its a complete shitshow. IT staff is made to deal with decisions they have no say or power in and turnover is quite high.
That being said, most commercial software seems to be way worse. There was the article the other month of a windows 10 machine automatically updating while a patient was being operated on forcing them to be kept under for an extra few hours.
I understand your point, but surely, simply REPORTING the current OS patch level is not, in and of itself, a change risk?
“Sunlight is the best disinfectant”, and all that.
Anyone who has been to one in the last year, pre-covid even, understands the ferris wheel of nurses and doctors that churn through the butter of what goes on there.
These weren't exactly hardened targets to begin with.
If you don't nurture a wound, you'll get an infection. If you don't clean your hands before eating or you eat something foul, you get diarrhea. The outside world is a dangerous place, and if you wish to interact with it, you should have your defences in order and take necessary precautions. And then still bad actors will get through, such as the yearly flu, so you must deal with that as well.
You won't defeat the outside world with offense, there's just too much out there, adapting too fast.
So yes, typically if your vendor's suppliers increase price, then your vendor will increase their price too. If your vendor has big margins and you have the ability to switch to a different vendor, then maybe the vendor will eat the cost, but health insurance is already a low margin business, so that's not likely.
I’d like to know much, much more about this statement.
Most costs are outside of insurer's control anyway, regulations prevent insurance companies from telling providers how to offer care as long as the care is medically necessary and the standard of care.
I think you're also ignoring healthcare networks. This is important for two reasons.
1. The kind of supply and demand works very well for modeling commodities, but the difference in networks means it's very hard to have two completely equivalent insurance products.
2. Insurance companies can incentivize hospitals to behave in certain ways by regularly pruning those who do not behave that way.
Also, most people get their healthcare from their employer. There's not as much ability to actually switch, unless you're so fed up that you're willing to switch jobs.
besides, i think the issue is the cost of the underlying procedures - doctors charge maximum what the insurance company will pay instead of what the patient would pay. there are plenty of stories where a patient is billed $100 but if they say they don't want it out of insurance the price drops to $40 or whatever.
another elephant in the room is that you can't pick your healthcare provider if you're unconscious. this part of the US system is little more than a scam.
https://naic.org/documents/topic_insurance_industry_snapshot...
https://www.reuters.com/article/us-usa-defense-cybersecurity...
From having some knowledge of some investigations like these (though not on behalf of any government), the investigators and forensics experts are constantly asking themselves "is this a false flag? is this piece of evidence deliberately planted, or an actual mistake?" Investigators obviously want to get the right people and not get the wrong people. And in the case of nation-states, they also have classified information they can use (like from NSA global spying, etc.).
[1] (I shudder at the term "cyber" as much as anyone else reading this, but that pretty much is the official term the government uses.)
Absence of evidence is not evidence of absence.
Everyone should be subject to due process. If some organized crime ring in Ukraine is blamed for some particular ransomware attack and they get tricked into traveling somewhere that lets them be extradited and tried in a US court, the prosecution still needs to prove beyond a reasonable doubt at trial that they're the responsible party. Things get more complicated when an entire nation-state government is accused of launching ransomware attacks, but so far I think only North Korea has faced that (someone please correct me if I'm wrong), and they're kind of an outlier among all the other countries.
We should always be skeptical any time any government accuses any entity of a crime, of course. There should always be a presumption of innocence. But that's what the legal system and due process are for. The onus is on the government to prove their case.
The government alleges something that sounds terrible that would justify an invasion, both parties play along, media is pushing pro war propaganda, allies abroad go along as well. Twenty years later, still no consequences, no apologies from our politicians, and any time someone seriously considers pulling out the troops, mysteriously some dubious war story comes up that is supposed to distract us or justify the war.
During the Cuban missile crisis, US intelligence showed photographs to the world proving the existence of the missile launch pads. During the Mueller investigation, the FBI provided hundreds of pages of concrete evidence to support their claims, which was supported by all other agencies and all of private industry.
Prior to the Iraq war, US intelligence showed jack shit; they just told the public "take our word for it: Saddam has WMDs".
If there were a future situation where there was an attempt to justify a country invasion or war, I absolutely would demand the highest possible rigor.
However, I don't think that can really be compared to trying to extradite and prosecute some criminals accused of ransoming hospitals and other institutions. They're not accusing any government of being behind these ransomware attacks and I doubt they will be. The only government believed to have ever done something like that is North Korea's, but they're kind of a special circumstance and are already technically and pragmatically at war with much of the world in many ways.
I think it's not really fair to assume a priori that the US government is lying, or that they're telling the truth, when they make some accusation. Things have to be carefully evaluated on a case-by-case basis, and the concrete evidence they provide needs to be looked at impartially. If there's no public evidence besides "trust us", then I'd agree that doubt is the correct action.
SWATting via VoIP spoofing etc., could arguably fall entirely within the realm of this.
https://en.wikipedia.org/wiki/United_Nations_Security_Counci...
Reality is essentially unverifiable at this point, so ... nuke Russia?
It's not that that's what I want, I just can't find a way to know what's real.
Then you wonder why everyone is burning US flags.
It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?
But.. there are certain classes of software that I think should be written differently.
I feel like we made a lot of bad decisions. There should be a completely separate stack for hospitals, power plants, etc., including a custom operating system. Why is Windows running on every machine? Isn't this a national security issue at this point?
Because for better or worse people make their choices and who are you to tell them what to run.
Infrastructural software - sure there should be some kind of security certification. this probably will not help much. Switches and routers are not running Windows and are still being attacked and crippled. Or consider the Stuxnet.
WRT engineering- if someone walks into a production cell and a robot swings and hits them in the head, guess who generally gets the blame in an investigation? The group that somehow didn't put safety scanners or a cell wall with door interlocks or didn't use safety-rated equipment.
There's a big difference between "guys, please get out of the way before I make the bot move" and "guys, I can't make the bot move until you're out of the way and the door is closed and latched" and worst-case scenario, that difference can be any number of human lives.
Surely things can improve, but it'll take time, dedication, and sucking it up and rewriting legacy code and probably being slower at pushing features out. (Keep in mind this isn't a universal guidebook- and should mostly be for companies that create software and infrastructure that is or can be life-critical.)
Even if I leave the door unlocked, it's still a crime to break in and take my stuff.
Yeah I agree there.
I'm curious what the surface area could look like. What is the minimum a hospital could operate with? How locked down could things be? Anyone in healthcare care to comment?
TGD
The correct solution is to change the flawed thinking in our regulations that treats all changes as equally hazardous to patent safety. The government should be encouraging (the right) changes to be released more quickly -- punishing companies for following the rules won't fix anything.
"Oh we brought it upon ourselves by making it easy to break in so we should fix that instead of going after the thieves?"
Our life is to this day in many small ways runs on a contract that others are not trying to kill us. Security check or not.
1) Security in healthcare is a shit show. If there are lots of open exploits, there needs to be a fast way for them to get fixed and the software vendors shamed on.
2) when someone discovers an exploit, they shouldn’t have to fight lawsuits. The response to security flaws should not be suppressing them but fixing them ASAP.
3) people shouldn’t have to lose lives to make a point that security is weak and you better pay up for disregarding it.
This is going to be a controversial suggestion, but I have a feeling that we might already be in an asymmetric world war and our leaders might quietly know it. This year has felt like checkmate.
Mutually assured destruction for the cyber-age.
If it's organized criminal hackers we're dealing with, then we should treat them how we would treat any legitimate terroristic threat. I would want our intelligence agencies to reach out and touch them.
This may not be a popular point of view on Hacker News. I unfortunately cannot fathom an alternative solution.
If I can be of any help to stop this, disrupt these guys or whatever I'm ready to give a few of my days and nights to it. Contact email in my about.
I'm a professional developper with a dormant interest in ethical hacking. Been following EH courses, done some CTFs ranging from basic web pen testing to crypto and assembly debugging and been reading/watching keenly everything I saw on cyber-security in the past 5-6 years.
> Public message to ransomware gangs: Stay the f away from medical organizations. If you target hospital computer systems during the pandemic, we will use all of our resources to hunt you down.
https://www.wired.com/story/notpetya-cyberattack-ukraine-rus...
The article you linked is absolutely fascinating. Because network security improvements didn't grant higher ups "bonuses" they didn't make the slightest effort to do what engineered desperately asked.
> The security revamp was green-lit and budgeted. But its success was never made a so-called key performance indicator for Maersk’s most senior IT overseers, so implementing it wouldn’t contribute to their bonuses. They never carried the security makeover forward.
10 billions of damages later...
The Russian that owns the computer never gets framed because the subpoena fails
and the public doesn't look for you and just maintains their antiquated Red Scare™
All because of ignorance and pride on our leaders to not admit they don't have a handle on this
99% of the time the hole in the system is the phishing email that the employee clicks on. you will be amazed how many link clicks, redirects warning messages and notices people will just click through because "hr" needs to verify you payroll information or other nonsense that doesn't even make sense.
Thieves must be heartless to go after such desperate targets. But criminals always have ways of justifying things.
I would be surprised if no one has written a smart contract for this yet - release the keys when X BTC are deposited to address Y.
The smart contract would just wait for payment and the control server would watch for payments. the victim would still have to trust that this process was in place, but for operator can have it completely automated
doesn't actually have to be a smart contract, just any address essentially. but a smart contract could allow for many more features, not sure if you'd really want that here
I thought this proposal was some kind of pitch to solve that specific problem, not just automate the process after receiving a payment.
I just misunderstood what the goal was
people are talking themselves out of how to use cryptocurrency and smart contracts, its like something Plato would write
I mean it's the mafia, same people that traffic women and children, drugs,... profit is the motive, they don't care how. Just because they are now sitting behind a computer doesn't change their nature.
I've been in a hospital recently and they were still running windows XP, my doctor using IE8 (cause activeX on the intranet) and Excel... But hey, they run anti-viruses!... Public institutions absolutely need to get rid of all that ASAP.
https://krebsonsecurity.com/2020/10/amid-an-embarrassment-of...
And once you're doing that, you're going to minimax for hi-value, low-risk targets.
its like yeaaah maaaybe there is one connected and high tech operation that all the world leaders heard about in their whatsapp groups, but my experience with "people with connections" are that they are so low tech and dumb that its almost impossible for them to get the correct clandestine hacker group in play
Considering the timing it could also be geopolitical unfortunately, people dying from a ransomware attack could substantially raise the general tension level in the US.
Lots of high value malware is actually targeted. Things like running phishing campaigns to try and steal credentials from someone inside the institution.
It's substantially less likely, especially if you don't buy the geopolitics angle, but potentially these criminals even have some unpatched vulnerability in a common deployed piece of software, which would allow them to skip the phishing part entirely.
[0] https://www.zdnet.com/article/first-death-reported-following...
Disclaimer: The company I work for is involved in detecting ransomware as a side business.
My understanding is that the ransomware operators just take a look at computers that are infected, and then negotiate based on who they appear to be.
With a consumer attack it's get execution on a computer, encrypt some files, and ransom them back. This might earn a few hundred dollars per computer, and isn't worth putting a whole lot of effort into any individual.
At a corporate level it's get some level of access, use that access to get control of a whole lot more access - and also to get control of servers that actually matter instead of users workstations that mostly don't. Maybe try and delete the backups, often exfiltrate a bunch of data, then encrypt things. If you exfiltrated the data the ransom potentially includes not just the offer to decrypt things but also a promise not to distribute the exfiltrated data.
This is all reasonably high touch "work". They've got to figure out how to move laterally inside that specific companies network. They've need to figure out what data is actually important (especially if the goal is to sell it). And so on. Unfortunately it appears to pay well enough to justify the effort. Companies are routinely paying millions of dollars in ransom.
I don't have stats to back this up (internal or otherwise), but my impression is that most successful attacks against enterprise targets are phishing attacks targeting employees to steal credentials.
Just pointing out that this is a little misleading. The link you're referencing refers to the first ever reported hospital death related to a hospital's ransomware attack, and this article was from just a month ago (I remember, I read it on Hacker News too). But the juxtaposition of these sentences might suggest that death-by-ransomware-in-hospitals has been a common occurrence for quite some time.
So they do target the extortion; already the decision to move on from that initial foothold will be based on the understanding of what institution it is and how much they would be willing to pay. In this case, they have intentionally targeted hospitals.
One way I can think of to disrupt this process is partnering with a new medical device company which is accelerating sales to hospitals. Last time I had this conversation the promising ones were all Chinese, wanted investment solely for development of algorithms under Chinese jurisdiction as part of terms of investment, and carried all the usual IP theft and legal risks you can imagine. Israel has some med tech startups too but they wanted to source talent from within their country and their due diligence seemed to be more of an intelligence gathering operation.
I moved on to working in finance. I don't know what ended up happening to that startup. I left after the paychecks stopped coming.
What'd be heartless is if the malware, such as the ryuk ransomware in December of 2019, had a bug in it that prevented the decryption key from working and all it did was garble and trash data.
Be forwarned, a few groups deploying ransomware are on sanctions lists which carries direct liability if you pay them. If you're the IT staff, make the CFO\CEO pay them and wash your hands of it.
Here's an introduction to our ransomware report: https://youtu.be/2yDqp34JN9k
If any hospital CISO and/or IT admin would like a three month free trial - even just to get through the current attacks - please reach out.
I take this opportunity to complain about regulatory capture and the medical cartels. Their constant irresponsibility (opioid epidemic, coronavirus response) affects everyone. Yet they still are paid more than any other industry.
Non-American (but not ignorant of USA) wondering why this is happening now.
Most hospitals store their data and run systems on-prem and are hyper-allergic to anything cloud based. They often have sloppy if extant back-up policies, and I've never heard of a hospital practicing a restore from backups. They also all seem to have terrible policies around passwords that cause most of their staff to iterate passwords every few months by simply incrementing a number at the end. You're also quite likely to find passwords on post it notes under half the keyboards in a given facility.
Security certifications are kind of a joke and mostly conducted by lawyers and compliance officers who have no technical background, let-alone info sec training.
TL;DR this has been a ticking time bomb for a decade and everyone involved knew it.
It would certainly make them less efficient and result in more errors, but hopefully they wouldn’t grind to a complete halt.
Or anything similar?
But Ryuk is not the Russian government anyways
And no networked computers for processing anything important.
That's got a list of some info, my understanding is that you can take information like that and look at other attack to start to see if there are elements in common to give you more overall information about the group possibly responsible, and how to detect the group again more quickly next time, to possibly jump in and deal with the problem before it leads to exfiltration or destruction or whatever bad thing you're trying to avoid. https://www.youtube.com/watch?v=BhjQ6zsCVSc talks a bit about how to detect UNC1878.
It sounds, specifically, like Hold Security is monitoring criminal communication and picked up a reference to this campaign ahead of the execution. Combined with the subsequent follow-through, it would be pretty straightforward to attribute the folks who said, "We're going to do this thing soon" as the folks who then ended up doing exactly that thing.
For what it's worth, I know nothing more about this than what was presented in the article.
Are we all neocons to you?
They should, however, require those devices are locked down and connected via secure means.
We should borrow an idea from nature and not create a monoculture. That way when a ‘computer virus’ comes along, it won't run rampant through the ecosystem.
Got any proof about those number in regards to HN users or it is just another "everybody knows"