Ransomware gangs are complaining that other crooks are stealing their ransoms
zdnet.com
zdnet.com
I worked(*) with a credit-card scammer who brought in a software for creating "yes-cards": Cloned Creditcards that had corrupted chip and pin settings(See https://www.zeit.de/2016/05/kreditkarten-banken-betrug-siche..., sorry its only in german).
It was unheard of at the time that you could do this. So we set up a test to clone a credit card of ours. The kicker was, the software didn't work when you disconnected the computer it ran on from the internet. Security mechanism from the creator? Nope, it turns out after tracing/dissassembly it sent the data from the cards to a third party to sell it.
Our informant was first confused, then outraged. No honor amongs thieves!
(*) journalistically!
A merchant or bank in a 3rd world country may decide on thresholds that effectively never do a fallback transaction.
yes, and it makes sense that it would encourage adoption of the new dip-tap machines. That they can also swipe does not decrease the incented appeal of the new safer system
Rare is the bank, and/or CC processor on the hook, it is either the consumer or merchant that is left holding the bag, if the Bank and/or CC processor were always on the hook for fraud, fraud would be almost impossible
Same is true for so called "ID Theft" if the bank and/or other lenders where on the hook for that type of fraud "ID Theft" would also be impossible, but since consumers have to clean up their own victimization the banks and lenders just play lip service to fixing it
An oversight in the EMV specs certainly, but not a showstopper.
IIRC I made one of these with an ICC Solutions programmable card about 20 years ago (in the context of building an EMV system at the time)
I love the story there though :)
There have been reports of crews stating "we won't hit hospitals in covid". With this backdoor, if your customers hit a hospital, you can hold your promise.
Even worse than hospitals (from their perspective) is agitating the American intelligence services. Hit too many pipelines, or similar high-news high-impact targets and 'national security threat' is your new name.
Worse than that still, imagine one of your affiliates is stupid enough to target inside Russia. You need to keep the Russians happy or all of a sudden trial or extradition become likely outcomes.
At the same time, once you have the opportunity, why not use back door for some more money.
Glad to see that they still aren't fully cooperating like legal businesses yet.
I'm not saying that all ransom gangs are coldhearted, but let's not frame them to have morals
And I also wouldn't find it too hard to believe that there must be at least some ransomware groups with morals. Not the same as yours, sure
NSA rather not to interfere, unless infrastructure is involved.
Interference from public sector may actually not be successful in the long run, as companies simply adjust to that, and keep ignoring security at a new equilibrium level.
But yes, ransomware does lead to a hardening of network infrastructure, and reduces the likelihood of successful espionage operations, by alerting parties - via the ransomware attack - to security vulnerabilities.
For the same reason that neither them, nor the Army doesn't serve drug warrants, or investigate tax evasion. Because policing is not their mandate. That's the job of either your local police department, or the FBI, or any one of a number of the other federal police forces.
You don't just get to sprinkle 'potential threat to national security' to turn criminal activity into a problem for the extra-judicial arms of your government. How about we let the police do their core competency - policing, and the military and the spooks to stick to their core competency - extra-judicial violence, and kidnapping random people to hold/torture without trial in Gitmo.
Your comment seems to imply you think the most/all of the remit of the CIA is or should be invalid. That position doesn't contradict my comment in any way.
That is a rather different claim than saying that premptively pursuing ransomware gangs in other countries is outside what the relevant decision makers view as the remit of the CIA. To me it seems to clearly fall in-line with their historic actions (as long as the cyber ransomers are outside of the country.)
I wouldn't say morals play no role, since someone that is perfectly fine robbing a wealthy institution isn't automatically going to be OK with causing someone's death, but there absolutely is risk management at play since the hunt for someone that stole a few hundred thousand dollars is going to be much lower priority than a hunt for a killer.
If the NSA starts deploying the TAO against ransomware crews, the crews are going to have a much MUCH harder time actually making money.
Theft is theft.
As for the comparison to Robin Hood, that would only be apt if the ransomware only targeted exploitative companies and gave the money back to the victims of those companies.
I read somewhere that a lot of these attacks are orchestrated by Russians because the Russian authorities will turn a blind eye as long as such attacks don't hit domestic targets.
So clearly it's well known that this is real and accurate just as most of the reporting is on Russia.
Except when it turn out to be fake news as it usually happens. For instance, linked malware research paper doesn't mentions alleged keyboard layout probe and never reveal how this probe to be performed. So, bogus.
> workarounds e.g. adding an additional keyboard
Just as bogus as placing succulent plant to "protect from computer radiation"
The effort required to make your enterprise look like it’s in Russia is definitely not worth the effort given that this would only stop one slice of organized crime.
Instead, there are stats indicating that The Mother Of All Hoaxes definitely ISN'T safe haven infosec-wise.
Additionally, Krebs completely forgot what there is war between Ukraine and Russia, so there are no reasons for such alleged protective measures any more.
"My friend told he read somewhere that someone read somewhere that a lot of these attacks are orchestrated by Russians because the Russian authorities will turn a blind eye as long as such attacks don't hit domestic targets."
How rumors becomes "real"... :)
It's even a security precaution.
https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
Tldr: it's not hearsay
The only reason I said "somewhere" in my original post was because I cannot remember which network it was published on.
PROHIBITED: a) UKR, RU, CIS - BAN
That WaPo Krebs article links malware analysis which goes into dire detail on how that ransomware probes for Volume Shadow Copy (via amateur WMI) yet... omits keyboard layout probe method(s) at all (there are at least 3 possible ways)
Without their protection, the ransomware crews are screwed.
I heard (and it might be just people making stuff up) that if you had cyrilic anything in your PC some ransomware would avoid you entirely, now, that's probably false but I am interested in knowing how would they avoid infecting russian computers.
You just described it. Maybe now other world powers need their own domestic equivalents. Or if they already do, then something that’s a bit more overt.
That's hilarious. You'd think they'd know better than to trust code they did not write...
Most humans trust code they didn't write
It's interesting that a.) they're back and b.) a secret backdoor that allows REvil to override their affiliates and restore access themselves is found shortly afterwards. Particularly since REvil, in the immediate aftermath of Colonial Pipeline, before they were shut down, sent out a message to their affiliates forbidding any attacks on governments or critical infrastructure. An alternative explanation is that they cut a deal with the CIA where they are allowed to continue to operate in exchange for instituting a backdoor and handing over the keys to major Western governments, such that if they hit any "politically embarrassing" targets, the government can override the affiliate and restore operations.
Keep your friends close and your enemies closer. It's often smarter to co-opt an adversary than it is to shut them down entirely.
CIA would demand a cut of the revenue as well. It should be appalling that anyone would think this is a possibility but sadly I do not put anything past US Federal Agencies anymore
Hilarious.
That this model is breaking is good news! It means that the efficiencies that trust allows are eroding in the ecosystem.
I can't imagine professionals capable of hacking useful targets having problems writing a script that encrypts some files with a public key and needs a private key to be unlocked.
If you have a second computer you're willing to accidentally mess up and require a wipe + reinstall, I recommend you experiment a bit and try writing your own malware or playing with some open source variations floating around. It can teach a lot to see from the attacker's perspective.
Backups.
Both offline media and well configured S3 can do. Although, I'd personally bet much more on my capacity of configuring a server than S3. Anyway, you can't go wrong with offline. The one thing you can't have is a NAS where your computers directly write the data.
(The opposite plays here, too. If everything you have is in the cloud, you should keep local backups.)
I wouldn't describe that as the "best" defense though, it's an "earlier warning system" but not early enough to prevent damage. You've already been hacked, the criminals have already exfiltrated all the data they can, have already installed whatever backdoors they are going to, and have even already started preventing you from accessing some of your own data. (That doesn't mean earlier warning doesn't help, and it's probably worthwhile, but it's a component in a broader last line of defense system that you never want to use in the first place).
The best defense is not getting hacked in the first place, and not letting malware spread when you do. If you are a big enough target that the "detect ransomware" solutions are remotely affordable you should hire some experts on this topic, but think about things like good phishing training, good firewalls, good software engineering, keeping everything entirely up to date, and so on and so forth.
Backups help (a lot!) but are not the cure all that people like to pretend they are. Apart from all the other damage hackers do apart from deleting things, hackers do attempt to delete backups too, and sometimes they succeed.
(Disclaimer: I use to work on one of these products)
1. File history preservation. We use Dropbox Paper, which preserves file history - if someone were to delete all of our documents we could recover them.
This is harder to do for production data, which may take up petabytes of space. Archiving out the data in big chunks can help here (we back up our kafka data to S3, for example, and the exporter will do that in batches).
You can also enable object versioning on those S3 buckets or prevent deletion/ mutation of objects. Another good idea is to use a uuid in the key name so that they can't be guessed.
2. Remove all forms of lateral movement. Move to a 'zero trust' system. Ransoming one machine is not worthwhile, attackers need to own a lot of your network if they want to monetize. They usually do this by traversing over as many machines as possible.
None of our systems can communicate with each other in corporate environments, and there's no remote execution protocols like SSH in our production environment (between servers). All access is explicitly authenticated and authorized.
There's lots of other good defenses but IMO if you do these two things you're in a very good place.
I wouldn't recommend "backups" generically. It's hard to do backups well and safely. (1) is technically a backup, but it's how the system works normally, it isn't some separate backup system that never gets tested. Backups are also very expensive, whereas zero trust is cheap.
Could you elaborate on this? I would have thought that they are at least in the same ball-park. I work at a large software company and we have a lot of internal systems one has access to. You have to harden your AD, you have to be very careful with single-sign on, etc. I'd bet, if I could compromise the machine of one of our employees I could do a lot of lateral movement. You must not only harden the production machine, you need to harden everything in the supply chain for those machines.
I don't think compromising our machines would be easy, nor do I Think lateral movement would be easy, but there's still more that we can do.
In reality the inverse is almost always true unless you are setting up a company from the start to be Zero Trust
Implantation of Zero Trust on an existing network and existing company with establish business processes that depend on a non-zero trust network well that can be very expensive to implement.
Also as we move forward in time with better and better immutable backup technologies the cost of the doing proper backups comes done.
Finally with modern Ransomware it is not just about the encrypted data, it is about data exfiltration as well. This is where the Zero Trust model come in, to prevent exfiltration.
At the end of the day Zero Trust and Backup are 2 different things, used for different purposes, Having Zero Trust does not mean you can forego backup. Having proper backups immutable does not mean can forego Zero Trust.
I didn't say it was one or the other, I recommended both.
The hallmark of an ecosystem.
It’s has been proven that affiliates are the main reason ransomware has been so successful. Piss off your affiliates and now you no longer have incoming victims/targets.
also
I don't watch TV - I sit back - and watch cowrie hijack a box - patch the hole - like howdy - its me - ya new best friend show me the way that you planned to get these ends
Snakes in the grass stay on my toes credentials contained within all these SQL rows no time for these hoes So what you gotta say to me? I need new information, f** all your old queries I'm planted like raspberries, Pycharm's filled with adversaries, static build, f** your external libraries.