HomeSecurityRansomware operators hide in your network after the attack

Ransomware operators hide in your network after the attack

Many companies/victims of ransomware attacks believe that attackers quickly deploy ransomware and flee their networks to avoid detection. Unfortunately, the reality is very different as threat actors are not that fast.

ransomware

In reality, ransomware attacks occur over time, ranging from a day to a month, starting with a ransomware operator breaching a network.

This breach is due to exposed remote desktop services, vulnerabilities in VPN , or through remote access provided by malware such as TrickBot, Dridex, and QakBot.

Once they gain access, they use tools like Mimikatz, PowerShell Empire, PSExec, and others to collect login credentials and spread throughout the network.

As they gain access to computers on the network, they use these credentials to steal unencrypted files from backup devices and servers before deploying the ransomware attack.

Once ransomware is deployed, many victims believe that the ransomware operators are leaving their network, when in fact they remain at risk.

This belief is far from the truth, as shown by a recent attack by the operators of the Maze Ransomware.

Maze continued to steal files after ransomware attack

Recently, the operators of the Maze Ransomware revealed on their website that they had infiltrated the network of an ST Engineering subsidiary called VT San Antonio Aerospace (VT SAA).

What's scary about this leak is that Maze leaked a document containing the company's IT department's report on the ransomware attack.

Ransomware operators hide in your network after the attack

This stolen document shows that Maze was still lurking in their network and continued to spy on the theft of files from the company as the investigation into the attack continued.

This constant access is not uncommon when it comes to these types of attacks.

John Fokker, head of cyber research for McAfee, told BleepingComputer that in some attacks, threat actors read victims' emails even as negotiations are taking place.

“We know of several cases where ransomware operators remained on a victim’s network after deploying their ransomware. In these cases, the attackers encrypted the victim’s backups after the initial attack or during negotiations, which made it clear that the attacker still had access to and was “reading” the victim’s emails.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS