HomeSecurityFBI: Warns about Netwalker ransomware targeting organizations

FBI: Warns about the Netwalker ransomware targeting organizations

The FBI has issued a security alert regarding the operators of the Netwalker ransomware targeting organizations in the U.S. and other countries, advising ransomware victims not to pay the ransom demanded and to report the incidents to the FBI. The alert issued by the FBI also includes some evidence that a breach related to the Netwalker ransomware, also known as “Mailto,”. In addition, the FBI shared a list of measures it recommends organizations take to mitigate these attacks.


According to the FBI, ransomware operators began targeting organizations in the US and other countries in June 2020, after successfully encrypting systems on the network of UCSF School of Medicine and Australian transportation and logistics company Toll Group. Toll Group was hit again by the Nefilim ransomware, as was Lorien Health Services, earlier this month.

FBI

Additionally, the FBI notes that the operators of the Netwalker ransomware have taken advantage of the COVID-19 in their attacks, managing to compromise a large number of unsuspecting victims in March, via phishing emails carrying a Visual Basic Scripting (VBS) loader.


Starting in April 2020, Netwalker ransomware began exploiting vulnerable VPN devices, user interface components in web applications, or weak RDP connection passwords to gain access to their targets' networks. Two of the most common vulnerabilities exploited by Netwalker operators involve Pulse Secure VPN (CVE-2019-11510) and Telerik UI (CVE-2019-18935).


Also, the Netwalker ransomware group recently released an advertisement, in which it stated that it was looking for new partners who could offer it access to large company networks.

Netwalker ransomware

What mitigation measures does the FBI recommend?

  • Organizations can significantly reduce the chances of falling victim to Netwalker ransomware by using multi-factor authentication (MFA) with strong passwords and keeping all devices and software on their networks up to date
  • The FBI also recommends using anti-virus or anti-malware on all network computers, while organizations should only use secure networks and avoid using public Wi-Fi. Additionally, they should consider installing and using a VPN.
  • A very important measure recommended by the FBI is backups stored either on external storage devices or in the cloud, so that it is more difficult or even impossible for would-be attackers to access them and encrypt them.
FBI

Once the Netwalker ransomware administrators successfully infiltrate a compromised target's network, they will use various malicious tools to collect admin credentials, steal sensitive information, which they may later use to convince the target to pay the ransom and encrypt data on all Windows devices on the network.

The Netwalker ransomware group has been uploading stolen data to the cloud storage and file sharing service, MEGA.NZ (MEGA), by sharing the data via the MEGA website or by installing the MEGA client application directly on the victim’s computer. Additionally, in June, the group switched from uploading and releasing stolen data to MEGA to uploading the stolen data to another file sharing service: website.dropmefiles.com.


The FBI advises victims not to pay ransom after such attacks, as this does not guarantee successful recovery of encrypted devices. However, the FBI understands that when organizations face a vulnerability in their operations, executives will evaluate all options to protect their employees and customers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS