Microsoft warned today about ongoing ransomware campaigns targeting healthcare organizations and critical services and shared advice on how to block new breaches, repairing vulnerable systems.
Many such attacks begin with hackers first exploiting vulnerabilities found in Internet-facing network devices or RDP servers by brute-forcing and then deploying ransomware payloads.
For example, Pulse VPN devices have been targeted by hackers in the past, with one such vulnerable device believed to be behind the Travelex ransomware attack by Sodinokibi (REvil).
Other ransomware gangs, such as DoppelPaymer and Ragnarok Ransomware, also exploited the Citrix ADC (NetScaler) CVE-2019-1978 vulnerability to gain a «foothold» in the network of their victims.
As Microsoft reports, the final stage of ransomware development and system encryption is usually preceded by an identification stage where attackers steal data that they can later use for blackmail, as well as collect credentials and infiltrate their victims' networks.
To prevent all of this from happening, Microsoft advises potential victims to prevent the threat actors behind ransomware campaigns from being able to exploit the vulnerabilities they typically use to launch attacks .

Reduce the risk of becoming ransomware victims
“Applying updated security patches for internet‑facing systems is critical to prevent these attacks”, explains the Microsoft Intelligence Protection Intelligence Team.
From data that Microsoft obtained after recent ransomware attacks, malicious actors typically exploit these security gaps:
• Remote Desktop Protocol (RDP) or virtual desktop endpoints without multi-factor authentication (MFA)
• Older platforms that have reached end of support and no longer receive security updates, such as Windows Server 2003 and Windows Server 2008, which were exacerbated by the use of weak passwords
• Misconfigured web servers, including IIS, electronic health record (EHR) software, backup servers , or systems management servers
• Citrix Application Delivery Controller (ADC) systems affected by CVE-2019-19781
• Pulse Secure VPN systems affected by CVE-2019-11510
While Microsoft has not observed any recent attacks exploiting vulnerabilities CVE-2019-0604 (Microsoft SharePoint), CVE-2020-0688 (Microsoft Exchange), CVE-2020-10189 (Zoho ManageEngine), based on historical evidence, they will eventually be exploited to gain access to networks , so they are worth fixing after going through review.
Detection and response to ongoing attacks
Organizations should also look for signs of an active ransomware attack in their environments, such as tools that help attacks combine with other activities (e.g., Malicious PowerShell, Cobalt Strike, and other penetration-testing tools), credential theft activities , or security breach logs.
Once such signs are identified, organizations' security operations teams should immediately take the following actions to assess the security impact and prevent payload:
• Investigate the affected endpoints and credentials
• Isolate compromised endpoint
• Inspect and remediate devices with related malware infections
Addressing the vulnerabilities facing the Internet by searching for and identifying any perimeter systems that attackers could use as a stepping stone to gain access to their networks is another important measure for defending against ransomware attacks.
Systems that may attempt to exploit ransomware intruders during their attacks:
• Endpoints RDP or virtual desktop without MFA
• Citrix ADC systems affected by CVE-2019-19781
• Pulse Secure VPN systems affected by CVE-2019-11510
• Microsoft SharePoint servers affected by CVE-2019-0604
• Microsoft Exchange servers affected by CVE-2020-0688
• Zoho ManageEngine systems affected by CVE-2020-10189
