The Worsening State of Ransomware
cacm.acm.org
cacm.acm.org
That is, ransomware as it exists today is only possible because secure, anonymous, non-reversible methods of payment exist in the form of cryptocurrency. Things like bearer bonds were outlawed decades ago because of a similar desire to make large anonymous, easily transportable payments impossible.
Honestly, if anything, I see ransomware as probably the primary use case today for crypto besides speculation.
The only way it could even plausibly work is for every visible and darknet service in the world to subscribe to and abide by the exact same crypto-wallet blacklist. Good luck making that happen when nuclear superpower governments are in fact transnational crime syndicates.
Assuming that the tracing capabilities are useful for anything beyond taking down the amateurs is overly optimistic.
The problem is that to kill ransomware, we would need a near-perfect system, and that is extremely unlikely, or thee will be substantial leakage, and continued profit for ransomers. I'd say it'd be easier to entirely shut down crypto globally than to ransomware-proof existing crypto.
Probably means that the real solution will be to do both. Sanction only fully traceable cryptocurrencies and shut down the rest.
Focusing on controlling onramps and offramps to cryptocurrency, like controlling goods import/export, is a relatively straightforward compromise to this internal dilemma and allows the government to be a player in the space without much direct oversight, even if some folks are slipping through the cracks. A sloppy, haphazard enforcement is likely to prevail.
And there's another way to reassert state control within that framework. If the bad cryptocriminals come for your stuff, the government can bail you out - if you play by their rules. The loss compensation mechanism is a simple plan to mitigate dangers, since it's easy for governments to create and redistribute credit internally and doing so can build consent.
Submitting to this framework does mean that the government is truly in competition with decentralisation to provide a better, more trustworthy service to handle central credit, and has to massively step up security efforts in the process. Everyone started "asleep at the wheel" on this, with individual tech firms all building out their own insecure house-of-cards fiefdoms and relying on the intellectual property law framework to keep them up. But everyone knows it's flawed - of course you can copy, what's important is if you can get credit, and that part is also changing with the crypto sector - assignment of credit is the whole thing of NFTs in a nutshell. The nation that can grasp this the quickest and turn it into a coherent part of their economic framework will cruise ahead.
Will any substantial number of govts have the foresight to setup such a system of on/offramp controls + rules/bailout + investigation and enforcement soon enough?
If the ransomeware plague stays in the non-critical commercial realm, it would work
The key looming problem I see is that it is already sanctioned by criminal adversary nation-states, and there will be a lot of profit temptation to go after critical or military infrastructure - some ransomware gangs are just going to be that short term 'smart' long-term stupid. A sufficiently serious enough attack could cause war-level damage...
Also a hacker could just buy something with the coins between the time the victim sends the money and the time the government is notified.
As for timing, either blocking spending or tracing the transaction back to a person is equally valuable as a deterrent.
Coins used to pay ransomware should effectively taint and freeze everything they touch.
Of course every jurisdiction would want to be in on the “free” bitcoins so lots of complications...
How would they know if the coin is from ransomware? If the randomware criminals say it's not, so it's word against word? And if they accepted just one payment to the wallet (so there's not a pattern of accepting money from strangers)
Or if the organization that got broken in to, doesn't want to be public about that? (Doesn't want to talk with the government)
(I don't know much about crypto coins.)
From criminals perspective they probably have money launderers on darknet markets who are willing to take the dirty crypto, deduct their hefty fee and offer clean crypto instead.
Bitcoin is not for speculators, it's primary use case is a Store of value. There's large demand for a store of value, especially now that the bond market is finished.
Comical world view, to me.
Of course, the nature of cryptocurrency makes both of our claims unfalsifiable. I would suggest hanging out in crypto-adept communities more, being privy to a 300-participant transaction or other things communities get excited about, to give you a different view of how people use it.
> Incredibly, many of these operations look and function like authentic businesses. "They rent office space, they have development teams, data architecture teams, help desks, phone support, and people that negotiate ransoms with targets"
What a crazy world we live in, where criminal organization have a quasi-normal corporate structure and even manage a "customer" support team
From "Why Drug Dealers Live With Their Moms" By Steven D. Levitt and Stephen J. Dubner
https://www.latimes.com/archives/la-xpm-2005-apr-24-oe-dubne...
If you want a really wacky use of scrum, try The Rhesus Chart [0] by Charles Stross, in which (mild spoiler) ...
a bunch of newly transformed vampires use scrum to quickly figure out how to acquire lots of fresh human blood without alerting the authorities by a trail of suspicious murders.
[0] https://en.wikipedia.org/wiki/The_Laundry_Files#The_Rhesus_C...
Edit: link: https://www.bloomberg.com/news/articles/2019-03-27/fifty-wom...
Ransomware was basically non-existent before criminals had a way of being paid anonymously.
- Attacks sovereign currencies and ability of countries to set fiscal and monetary policy. Instead, it rewards "crypto geniuses" that got in early. I'm not sure these are the people that should have power over our elected governments.
- A waste of human and resource capital that could be spent solving more important problems
- Hugely bad for the environment
- Lack of KYC that enables money laundering, terrorism, and other illicit activities. Including randomware attacking hospitals
- Rewards pump and dump and crazy schemes like NFTs that don't contribute to innovation or the economy
- Relies on cryptography to remain post-quantum safe
This is why our backups at work write to a storage bucket with permissions such that they can create new files but not delete old ones. I'd definitely recommend this approach to everyone who can afford the storage space.
For anyone who has serious (I.e. $$$) need of that they already have tapes and optical WORM media though.
You can do something conceptually similar with any sort of NAS that provides immutable snapshots as long as the management and control is effectively out of band.
The out of band part is the key. Our SAN data has snapshots. The backups are written to another storage device that only has an API key to write them to B2 storage. An attacker would effectively need to completely compromise multiple admins in the organization to get at all the stages of data duplication, and frankly there is no additional line of defense for total compromise if the attacker is willing to wait for physical tape or disk swaps.
Fortunately for ransomware, time is money for them too.
Sigh. When are people going to accept that software switches are inherently not secure? How many times must these fail?
> It's difficult to do that unless the filesystem has append only functionality, metadata blocks are rewritten all the time even if data isn't.
There's no reason to continue writing anything to a hard drive once the backup to it is finished.
Even more secure would be hardware write only storage. CD-ROMs fit in this category, but they aren't big enough.
But all we need are hard disk drives with a physical write-enable switch. Turn it on, write your backup, turn it off. No software can then alter it.
A stupidly simple idea, and yet every time I mention it in HN it gets dismissed, denigrated, etc. Apparently people like malware, ransomware, etc. :-(
A physical read-only switch is required.
Not ironclad but pretty good. Issues with it that first come to mind are the live operating system image was already compromised when it was written to say the USB disk, or compromised firmware, and of course user error (nothing to do with ransomware in this case). I am not familiar with this stuff so I may be missing something very important, if so tell me about it.
Just think of all the security issues that would just go away with physical write-enable switches.
Heck, I'd go further, and demand from disk makers a physical write enable switch for a separate volume. Use that volume for the system software.
To what extent should ransomware activity be considered low-grade economic warfare by nation-states who can't or won't police cyber-criminals, and thus justification for robust national responses such as sanctions?
1. https://www.usni.org/magazines/proceedings/2019/october/gran...
[1] This point is debatable, some people feel that tariffs are not 'both-sides-lose' games. Depending on the tariff, and the situation, I too feel that way - but neither I, nor those people hold to an orthodox understanding of neo-liberal economics. [2]
[2] Which as of 2021 are the primary drivers of trade policy in the Western world. This may, or may not change in the decades to come.
That's probably the only solution, besides the obvious ones like actually protecting the systems.
But I would hope that financial pressure - like insurance companies not insuring unprotected systems - would have the same result without the need for regulation.
Windows is not inherently insecure. Executing a malicious program would work just as well under Linux. (Presumed) technical superiority does not help when it's basically social engineering all the way. Ephemeral VMs don't help too much, either. So I highly doubt this would reduce windows market share in any significant way.
The biggest reason is to starve the attackers of incentive and resources. If you get 10 million dollars from an attack you can hire 10 people for a year to work on more attacks.
But it's unlikely that companies will change anything besides reporting in their practices. People are bad at evaluating tail risks of 0.001% chance happening in their lifetime.
That would be true if in 2021 the alternatives were more secure than Windows, which I doubt.
The encryption process ensues over days, weeks, or months, normally progressing through hard drives, attached drives, and network devices. The C&C server decrypts files as they are needed. Along the way, crooks place a ransom note in every folder that has encrypted files; they might also plant other types of malware on systems. During the final stage of an attack, the ransomware uninstalls itself, the thieves remove the encryption key from the infected system and the victim sees a ransom note on the computer screen.
If the encryption goes on over a long enough period, recovery would be a nightmare or even impossible, especially if the tape rotation period is exceeded.
Why can't the OS be write protected? Why can't the configuration also be write protected?
No matter what the application does, it can't access the backups in such a system.
And if the gang get's admin rights on the box your backups are gone.
How is this program to know that a file edited by the virus to encrypt is legitimate or not when the edit is being made by a user that created and owns those files? The backups themselves can be contaminated months before the encryption and ransomware attack is sprung. Restoring from last week or last month's backup might still lead to your system being encrypted.
Additionally, as the other user pointed out the goal would be to gain access to the appropriate user with the level of permissions, such as an admin or root account, and use those credentials to carry out the attack.
The configuration and data which gets changed all the time is valuable (the effort that was made in making those changes) and the prime target of ransomware, and it can't be write-protected because, well, it needs to get changed. I mean, if "reimage all these computers to the default configuration" would be a viable solution, everybody would just do that instead of paying large ransoms.
Precisely the wrong way to think about this.
If the OS can't protect itself, you've got a system with zero security.
It won't prevent lateral movement through the network (that's often memory only, no need to write to disk), it won't prevent persistence through theft of credentials or kerberos tickets (and possibly make it harder to rotate credentials), and of course it won't prevent the exfiltration, encryption and/or destruction of the actually valuable data.
If we look at an advanced ransom attack (e.g. as many described in this article - manually operated after initial access like many Emotet attacks, not some purely automated malware) then I struggle to imagine what parts of the attack would be thwarted if the OS and config would be write protected - do you have something specific in mind?
First - protect the AD and authentication infrastructure from a black start event.
I'd have an offline physical machine, no matter how old, that was a viable backup domain controller. I would have a stack of hard drives for it, and a copy of clonezilla. Every so often, clone the hard drive, boot the replacement, and sync it with the domain, then turn it off.
For the truly paranoid, do this in each location. Keep the machine and drives in a safe.
Test the black start backups on a temporary network built from spare hardware. Note that if you boot a Windows machine, it might adapt itself to the hardware and cause issues, so discard that image, and regenerate it.
In a black start event, you could turn off all the outside networks, and start with the old AD server, and restore from backups.
--
Any Virtualization or SAN layers should have administrative credentials that are unused for anything else, and only written down on pieces of paper, never scanned or typed in.
All servers should have saved images in offline, unencrypted hard drives, in a safe.
--
The main thing then is to get periodic offline unencrypted backups of the systems and data in a safe.
--
So, if the system is breached, there is at least a way to restore to the last backup, and you have some confidence it actually works.
It is getting to the point where the threat is beyond office functions and to manufacturing, infrastructure and IOT.
With the threat escalating to that genuine national security level, and often under sponsorship or blind eye of criminal govts (NK, RUS...), we are not far from the point where the appropriate response is to deliver a kinetic response - as in a cruise missile through the window.
Most/all of these ransomware attacks use the built-in Windows encryption.
However, a complete lack of interoperability would make it really hard to, you know, interact with other businesses and systems.
This isn't throwing the baby out with the bathwater so much as drowning the baby in the bathwater.
(edit: removed some meaningless words)
The type of billionaire individuals who by virtue of inheriting billions upon billions, don't ever have any real skills (nor the need to develop any) and yet, they live in societies (subcultures) which expect that they keep having (and making) billions upon billions.
Think of descendants of descendants of founders of what are now giant corporations.
They fund VC-backed startups, which they then own (by proxy). They can barely use an iPhone; let alone understand how it works or is made.
Except the business being funded is a criminal enterprise, maybe their riches originally come from "shadier" dealings?
My point is that the underlying principle is the same, it's a very powerful principle. This is how the market enables societies to build super complex stuff. The marketplace abstracts away the complexities. This 'principle' is a technology, it's ethically neutral.