HomeSecurityRansomware attack failed at the last minute. How was it discovered?

Ransomware attack failed at the last minute. How was it discovered?

A ransomware gang installed remote desktop software on more than 100 machines on a network, but its plans to encrypt the network failed at the last minute after cybersecurity experts were called to a company when suspicious software was detected on its network.

Cybercriminals' efforts to lay the groundwork for a ransomware attack, which resulted in the installation of legitimate remote desktop software on 130 endpoints, were discovered when security firm Sophos was called in to investigate the company (whose identity remains unknown) after Cobalt Strike was detected on its network.

Cobalt Strike is a legitimate penetration testing tool, but it is commonly used by cybercriminals in the early stages of a ransomware attack. One of the reasons they use it is that it operates partially in memory, making it difficult to detect malicious activity.

Read also: CISA: Ransomware security self-assessment tool released

REVil Ransomware
Ransomware attack failed at the last minute. How was it discovered?

The gang aimed to encrypt as much of the company's network as possible with REVil ransomware, but because the hackers were detected before they could complete their preparations, the attack was unsuccessful – although the hackers did manage to encrypt data contained on some unprotected devices and delete online backupsafter they realized they had been spotted by researchers.

A ransom note left by the REvil gang on one of the few encrypted devices demanded a ransom of $2.5 million in Bitcointo provide the victim company with a decryption key. However, the company did not pay the ransom.

However, the attackers managed to gain significant control of the network and install software on more than 100 machines – and the targeted company didn't notice.

“As a result of the pandemic, it is not uncommon to find remote access applications installed on employee devices. When we saw Screen Connect on 130 endpoints, we assumed it was there intentionally, to support people working from home. It turned out that the company knew nothing about it – the attackers had installed the software to ensure they could maintain access to the network and compromised devices,” said Paul Jacobs, head of incident response at Sophos.

See also: Golang: New ransomware shows that hackers are increasingly using it

Ransomware
Ransomware attack failed at the last minute. How was it discovered?

This was just one of many methods the hackers used to maintain their influence on the network, including creating their own administrator accounts.

And here the following question arises: How did the hackers enter the network to use Colbalt Strike, create remote access accounts, and gain administrator rights?

"From what we've seen in our research, there are a variety of methods used, typically users are phished weeks or months in advance, then exploited through vulnerabilities in firewalls and VPNs or brute-force attacks on RDP if exposed to the internet," said Peter Mackenzie, director of rapid response at Sophos.

In this case, the attempted ransomware attack was not successful, but ransomware is so prolific these days that organizations often fall victim to it. REvil, the ransomware used in the incident investigated by Sophos, was developed in the successful ransomware attack against JBS, with the hackers behind it earning $11 million in Bitcoin.

Suggestion: Conti ransomware: Hits many companies and organizations in Greece!

ransomware
Ransomware attack failed at the last minute. How was it discovered?

However, there are measures that all organizations can take to prevent hackers from gaining access to their network.

Specifically, Mackenzie said the following: "First, make sure every computer on your network has security software installed and centrally managed. Attackers target unprotected machines. Next, make sure they are regularly patched, and keep in mind that if a computer hasn't rebooted in a year, it probably hasn't been patched either."

But while the right use of technology can help protect against cyberattacks, it’s also useful to monitor the network. People who have a good understanding of what’s going on on the network can detect and react to any potentially suspicious activity – like the use of Colbalt Strike, which resulted in the discovery of the ransomware attack described in this case, before serious damage was done.

Finally, Mackenzie noted: “For the best cybersecurity, you need people who are monitoring what’s happening and reacting to it in real time, that can make the biggest difference.”

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS