HomeSecurityNephilim Ransomware gang linked to Citrix hacks

Nephilim Ransomware gang linked to Citrix hacks

A criminal gang carrying out ransomware attacks is targeting organisations using unpatched or unsecured Citrix remote access technology, then stealing data, releasing encryption malware and threatening to publish the data to force a ransom payment, New Zealand's national response team has warned.

In a warning issued last week, CERT NZ says a “sophisticated and well-designed” attack campaign is hitting unprepared organizations with the Nefilim – also known as Nephilim – ransomware.

Nefilim ransomware

“We know that attackers are gaining access to organizations’ networks through remote access systems, such as remote desktop protocol and virtual private networks ,” the CERT NZ security alert states. “They are gaining access through weak passwords, organizations that do not use multi-factor authentication as an additional layer of security, or remote access systems that have not been patched.”

After this group of attackers gains access to a network, security researchers say they use legitimate tools to try to avoid detection.

Once attackers gain access to the remote access system, they then use tools such as Mimikatz, PsExec and Cobalt Strike to escalate privileges, move laterally across a network and create network persistence,” says CERT NZ.

Data Extraction and then Ransomware

The attackers in this campaign aimed to locate sensitive data and then extract it. Once they gained access to the network, they installed encryption malware on as many connected systems as possible, CERT NZ says. While this campaign includes the Nephilim ransomware, it notes that “other ransomware may also be used.”

As for the vulnerable software targeted by hackers, “Citrix remote access technologies have been reported as a common way for attackers to gain access,” says CERT NZ, referring to a Citrix vulnerability, CVE-2019-19781, which came to light last December and was patched in January amid reports of widespread exploitation.

Security experts say that unlike ransomware-as-a-services like REvil, also known as Sodinokibi, in which operators provide ransomware code to partners and split the profits, Nephilim appears to operate as a "closed loop" by a single gang.

“Nephilim emerged in March 2020 and shares a significant portion of its code with another ransomware family, Nemty,” notes security firm AlienVault. “Nephilim is another ransomware family that has appeared in several destructive campaigns that threaten to release victims’ sensitive information if they do not cooperate “with the attacker’s demands.”

The tactic of extracting data and using it to force victims to pay ransom was first carried out by the Maze gang last November. Since then, about a dozen other RaaS and ransomware gangs have followed suit.

One of the most significant attacks to date by the Nefilim ransomware was against the giant Toll Group.

Nephilim Ransomware gang linked to Citrix hacks

Watch for lateral movement

To determine if an organization has been affected by Nefilim, “check remote access systems for any signs of unauthorized access,” CERT NZ advises. “If unauthorized access is detected, further investigation is required to determine any lateral network traffic.”

Data breach risk

As with other ransomware gangs now practicing so-called “data exfiltration,” the Nefilim attackers’ focus on stealing data before encrypting systems means that organizations must not only recover systems after ransomware, but also ascertain what data has been stolen.

Under breach notification rules in place in many countries, including the US and Europe under the EU's General Data Protection Regulation, if certain types of personal or financial information are stolen by attackers, the organization may be required to report the breach to authorities and potentially send breach notifications to affected individuals.

Researchers at SentinelLabs, the research arm of SentinelOne, say the Nefilim gang threatens to leak stolen data unless victims cooperate, and historically believes that any attempt to negotiate the size of the required ransom payment will be unsuccessful.

“While Maze, DoppelPaymer, and REvil tend to receive the majority of media coverage, Nephilim is another family that has been linked to numerous, destructive campaigns that threaten to publish victims’ sensitive information should they fail to ‘cooperate’ with the attacker’s demands,” SentinelLabs notes.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS