Unauthorized Access to Fujifilm Servers
fujifilm.com
fujifilm.com
On one hand it seems a bit expected to see an increase in attacks after big, public ones... but on the other hand how are these networks and computers actually getting compromised with what appears to be such speed and ease?
edit: I also wonder if defenses need to get more proactive about detecting these attacks. Why can't block devices have a mode where they immediately shut down into a fail safe if they see a huge amount of sustained block overwrites (like attempting to overwrite 50% of data within a short time span)? Or maybe bake copy on write filesystems into the hardware such that no matter what happens on the host side a perfect history of previous blocks is kept intact to be restored through some manual/external intervention.
My guess is this is fallout from the SolarWinds hack. Wouldn't be surprised if they discovered intel on a number of vulnerabilities or maybe even backdoors that are helping enable these attacks.
I've not heard of Linux or BSD systems being hit by cryptolocker-type ransomware, but most news reports don't get into the details of what operating system was involved.
As I understand, several ransomware variants circulating today are hybrid windows/linux
But in the real world they don’t. It is really really hard to convince companies to purchase backup solution. Sadly, IT professionals like to talk and work on “fancy” security things. Criminals will do plain old criminal acts (steal, blackmail, kidnapping, etc.) to access to the servers. In short, security is important but it might fail: have a backup.
It could be also that criminals have also the full access to the entire IT infrastructure.
Unfortunately, the answer is largely no. Phishing emails containing malicious documents, now sometimes accompanied by call center operators priming the victims or walking them through the process of infecting themselves, are to blame for a large number of ransomware attacks. Exploitation of recent vulnerabilities (i.e. a handful of CVEs from 2020 affecting VPN devices) is also often used for initial entry, as well as plain old bruteforcing RDP servers and the like. Some groups have begun to invest in in-house vulnerability research teams but I have not seen much come from that as of yet, aside from implementation of exploits for existing CVEs.
> but on the other hand how are these networks and computers actually getting compromised with what appears to be such speed and ease?
The scale and architecture of some of the larger cybercriminal groups responsible for many of these attacks parallel your typical silicon valley startup. One of the larger groups has dozens of employees across a range of different focus areas/departments from malware development, infrastructure management, crypting services, redteam operators, ransomware negotiators, layers of management, etc. These groups work with other affiliate groups which only accelerates the process from initial infection to ransomware deployment, with affiliate groups that blast out malspam broadly as well as to curated target lists often responsible for supplying the steady flow of infections to malware-as-a-service platforms that provide the ability to view and manage bots to yet another set of groups that drop secondary payloads like Cobalt Strike and begin the process of lateral movement towards the domain controller so the final ransomware payload can be deployed. These groups have employee handbooks, training videos, slack-like chat services, Gitlab instances with dozens of projects, CRM-like tools for victim management, and even (in at least one case I'm aware of) physical offices in Russia.
Many many companies are really very insecure, there doesn't have to be some big 0day for most. More like a combination of long known, unpatched vulnerabilities, social-engineering vulnerabilities, and instances of essentially leaving the door entirely open.
https://www.verizon.com/business/resources/reports/dbir/2021...
Now, somebody will say something like: "Everybody knows these companies don't care about security. If they just focused on security and adopted best practices or (insert basic practice here) they would not be having these problems." Sure, these attacks are utterly trivial to implement and the target companies are massively behind the curve on "best practices" by orders of magnitude. But, even the best systems are completely and utterly ridiculously inadequate. You can completely and utterly compromise essentially any currently deployed commercial IT system for less than $10M with the median for total compromise of a Fortune 500 company being ~$100k. And frankly, $10M is just me sandbagging the upper bound. I have never had any person in any security organization from an engineer to a regional cybersecurity director to a CISO at a Fortune 500 company ever give a number over $1M when asked over lunch.
For third party evidence, you can just look at Zerodium where they pay for exclusive rights to zero days in the most "secure" products currently available for only slightly more than $1M. You can literally burn multiple remote zero-click full-chain RCE zero days per attack and you would still be spending less than $10M per attack. If you can leverage a single remote zero-click full-chain RCE zero day even 10 times the cost per attack drops to the $100k-500k range.
So sure, they could improve their security by a factor of 100x, bringing it from $10k to $1M. That might stop some criminals for a time. They might attack cheaper targets for a time. But if they can pay $1M to get $4M from you, then once they eat all the other fish in the barrel they are going to eat you.
But with a hard shell and squishy center security posture, all it takes is one security event, and you're pwned. All it takes is one salesman to click on a phishing email, one data entry drone to get hit by a drive-by ad while watching YouTube during lunch break, one Internet-facing server to miss a security patch, etc. Once with a foothold, these ransomware gangs move with speed and thoroughness that comes of lots of practice. Depending on the size of the enterprise, and how well it is or is not segmented, compromise can spread from patient zero in days, if not hours.
It's not all doom and gloom. Seeing these events happen, or having the near-death experience of surviving a ransomware attack is (at least temporarily) lighting a fire under companies' asses to get their shit together, and start keeping their support contracts current. Detection and response tools are getting better. I know of a managed EDR solution that kills all connections except the control connection back to their security center and clears out the routing table so no new connections can be made. Then they call you.
But for every company that is taking steps to secure themselves against the current threat landscape, there are plenty more that are failing to do so, whether out of naivety or complacence.
Most corporate networks are very bad when it comes to administration practices and credential hygiene. I'm talking about Active Directory of course, which is the identity and management backbone of most every corporate network. However, to be accurate, this isn't a problem with AD as a technology itself - it can be made very secure - but how it's deployed and used in practice. Of course, you could argue that a technology is bad if deploying it securely requires arcane knowledge and isn't the default configuration... However, the same underlying principles or weaknesses exist in the underpinning technologies or concepts themselves and are not AD specific.
Ideally, Active Directory is the identity management backbone of your entire corporate network. Identities and devices are centrally managed through it. Ideally, access to every single server, workstation and application is managed through it.
Compromise the identity management backbone and you compromise everything that it controls access to, i.e. the entire network and all business data. Doesn't matter whether it's AD or MIT Kerberos or whatever.
In practice, this issue is Windows- and Active Directory specific, but mostly because AD is the most widely deployed directory service by far and Windows machines tend to be domain joined for effective management.
But to be clear, Linux would be vulnerable to this in exactly the same way if they were configured similarly, which they're often not. But you could have MIT Kerberos etc. running to centrally manage access to all of your Linux assets - compromise it and you compromise all assets it manages access to.
In AD, there's a group called Domain Admins which grants unrestricted administrative access to every single workstation, server and identity in the directory. In today's security conscious world, that concept is very much a blast from the past, but I digress...
On most networks, practices are generally very lax and the number of Domain Admins and the use of such accounts thereof vastly exceeds the minimal scope they should be used in. Admins log in to standard workstations with them etc. putting the accounts/credentials at risk of theft.
On most networks, it's fairly trivial to move laterally after the initial foothold and to capture Domain Admin credentials (because they're scattered all over the place), after which the entire network is compromised and it's game over.
I've seen it happen in the span of about 12 minutes from initial compromise via the internet to malware being deployed to thousands of endpoints at once through AD. No actual vulnerabilities needed, just bad (network) administrative practices.
I smell a new 'feature' for SAN vendors to charge for! Maybe Microsoft could add it to the 'datacenter' versions of Windows.
discussion here: https://news.ycombinator.com/item?id=27375401
Fujifilm becomes the latest victim of a network-crippling ransomware attack - https://news.ycombinator.com/item?id=27384151 - June 2021 (ongoing)
Ransomware – Unauthorized access to Fujifilm servers - https://news.ycombinator.com/item?id=27375401 - June 2021 (46 comments)
Fujifilm shuts down network after suspected ransomware attack - https://news.ycombinator.com/item?id=27373455 - June 2021 (52 comments)