When security experts are faced with a ransomware attack , they usually worry about encryption or data theft (or both). However, a recent report claims that ransomware is now coming with a new feature: harvesting credential , which allows an attacker to infiltrate a business’s network whenever and as many times as they want.
This new feature was discovered by security journalist Brian Krebs. Krebs warned users that the usual recovery process after an attack, which is changing passwords on all accounts and systems, is not enough to deal with the situation. Attackers can steal every password stored on devices and networks.
Krebs came to this conclusion after analyzing the ransomware attack (Ryuk) on Virtual Care Provider Inc.( VCPI), which took place in November 2019. The provider manages the IT systems of approximately 110 clients serving 2,400 hospitals in 45 US states.
A cybersecurity firm that liaises with ransomware gangs for ransom negotiations told Krebs that the hackers behind the VCPI ransomware attack had combined the ransomware with the Emotet. Emotet includes Trickbot, which is known for stealing passwords.

According to the data, the credentials stolen by the attackers included those used by the company's employees to log in to over 300 websites and services (password management platforms, Microsoft Office365 accounts, personal and corporate banking portals, cloud-based payroll management services, Amazon, Facebook, LinkedIn, Microsoft, Twitter accounts and others).
What's the moral? Krebs explains: "Companies facing a ransomware attack – or any other attack – should know that all credentials stored anywhere on the local network are at risk and should be changed."
It is necessary to take protective measures and use multi-factor authentication.
