HomeSecurityCring: New ransomware targets unpatched Fortinet VPN!

Cring: New ransomware targets unpatched Fortinet VPN!

Hackers are exploiting the CVE-2018-13379 vulnerability in Fortinet VPNs to deploy the newly discovered Cring ransomware (also known as Crypt3r, Vjiszy1lo, Ghost, Phantom) to industrial organizations. CVE-2018-13379 is a path traversal vulnerability in the FortiOS SSL VPN web portal, which could be exploited by an unauthorized attacker to obtain FortiOS system files via crafted HTTP resource requests.

Cring ransomware appeared on the threat landscape in January, first reported by Amigo_A and the Swisscom CSIRT team . The ransomware encrypts data from victims with AES-256 + RSA-8192 and then demands a ransom of 2 BTC for the return of the files.

Read also: Approximately 80,000 Exchange servers contain exploitable vulnerabilities!

Cring: New ransomware targets unpatched Fortinet VPN!
Cring: New ransomware targets unpatched Fortinet VPN!

Kaspersky said in a related post: “An investigation conducted by Kaspersky ICS CERT experts at one of the attacked companies revealed that Cring ransomware attacks exploit a vulnerability in Fortigate VPN servers. The victims of these attacks include industrial companies in European countries. In at least one case, a ransomware attack resulted in the temporary shutdown of the industrial process, due to the fact that the servers used to control the industrial process were encrypted.”

After gaining access to a system within the targeted network, the attackers downloaded the Mimikatz utility to steal the credentials of Windows users logging into the compromised system.

By compromising the domain administrator account, malicious actors could distribute the malware to other systems within the targeted network. The attackers also used the Cobalt Strike post-exploitation framework to deploy the ransomware.

Cring: New ransomware targets unpatched Fortinet VPN!
Cring: New ransomware targets unpatched Fortinet VPN!

See also: Portable VPN protects your online data

In one case, the «infection» of the servers – which were used for controlling the industrial process – with ransomware caused the temporary termination of the process.

According to the Russian cybersecurity company, the main causes of the incident were the use of an old and vulnerable firmware version on the Fortigate VPN server ( version 6.0.2 was used at the time of the attack ), which allowed attackers to exploit the CVE-2018-13379 vulnerability and gain access to the company's network.

In addition, Kaspersky emphasized the following: “The lack of timely antivirus database updates in the security solution used on the attacked systems also played a significant role, preventing the solution from detecting and blocking the threat. It should also be noted that some components of the antivirus solution were disabled, thereby further reducing the quality of protection. Other factors contributing to the incident were user account rights settings configured in domain policies and RDP access parameters.”

Cring: New ransomware targets unpatched Fortinet VPN!
Cring: New ransomware targets unpatched Fortinet VPN!

In report , Kaspersky also shared indicators of compromise.

Suggestion: FBI/CISA: Beware! APT hackers target Fortinet FortiOS servers

In early April, the FBI and CISA issued a joint warning about attacks carried out by APT groups targeting Fortinet FortiOS servers, using multiple exploits.

Threat actors are actively exploiting the CVE-2018-13379, CVE-2020-12812 , and CVE-2019-5591 vulnerabilities in Fortinet FortiOS .

Information source: securityaffairs.co

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS