Microsoft is warning hospitals that gateways and VPN devices are vulnerable to ransomware attacks that seek out exposed endpoints. The tech giant claimed that the hackers behind the REVIL (also known as Sodinokibi) are scanning the Internet for vulnerable systems, with VPNs being widely used at this time as COVID-19 forces workers to stay home and work. The group of hackers appears to be changing the malware infrastructure it used last year in the new attacks, which aim to exploit vulnerable healthcare facilities, such as hospitals, which are under extreme pressure as they deal with patients infected with COVID-19.

According to Microsoft, these attacks differ from ransomware attempts on mainstream products, as hackers leverage their extensive knowledge of systems administration, while also exploiting common misconceptions about network security. The company also added that once hackers penetrate a network, they perform extensive reconnaissance and adjust privilege escalation and lateral movements based on flaws and vulnerable services they discover on the network. In these attacks, hackers typically persist, even for months, on networks that have not been detected, and then deploy the ransomware payload. This type of ransomware is more difficult to recover from because it can be difficult for victims to search for where the hackers have discovered flaws and to locate the inboxes, credentials, endpoints or applications that have been compromised.

Ransomware attacks, including REvil, have reportedly targeted vulnerabilities in Citrix ADC and Gateway products. The group is also suspected of exploiting vulnerabilities in the Pulse Security VPN platform to compromise Travelex last year. The National Cybersecurity Center (NCSC) and the NSA warned last October that these products were being targeted by APT hackers.
Microsoft recommends that users update . Finally, a report the company issued in February contains more details on how users can defend themselves, at least to some extent, against ransomware attacks.
