HomeSecurityFBI, CISA and NSA issue advisories on BlackMatter ransomware attacks

FBI, CISA, and NSA issue advisories on BlackMatter ransomware attacks

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have published advisories on how the BlackMatter ransomware gang operates.

BlackMatter ransomware

See also: Marketron: BlackMatter ransomware targeted software provider

The three services also provide information that can help organizations counter the activity of this dangerous adversary and defend themselves.

The BlackMatter ransomware-as-a-service activity began in July with the clear goal of compromising corporate networks belonging to businesses in the US, Canada, Australia, and the UK, and has generated at least $100 million in revenue so far.

The gang itself has stated, however, that it does not attack hospitals, vital infrastructure, non-profit organizations, defense industries, and government organizations.

BlackMatter is responsible for encrypting systems at multiple organizations in the US and is demanding ransoms of up to $15 million in cryptocurrency.

Cybersecurity advisories released by CISA, the FBI, and the NSA list tactics, techniques, and procedures related to BlackMatter activity that could help organizations protect themselves from the ransomware gang.

A variant of the malware analyzed in an isolated environment shows that the threat actor used administrator credentials to discover all hosts in the victim's Active Directory.

It also used the Microsoft Remote Procedure Call (MSRPC) function (srvsvc.NetShareEnumAll) which allowed listing of all accessible network shares for each host.

The BlackMatter file-encrypting malware also has a version for Linux-based systems that can encrypt VMware ESXi virtual servers, which are common in enterprise environments for resource management purposes.

See also: BlackMatter ransomware: Demands 5.9 million from agricultural cooperative

BlackMatter ransomware

Unlike other ransomware vectors that encrypt backup data stores and devices, the BlackMatter gang deletes or reformats them.

Based on the identified TTPs associated with the BlackMatter ransomware, the three services created signatures for the Snort network intrusion detection and prevention system, which can alert the user when a remote encryption process is initiated.

In addition to using the above Snort signatures, companies recommend using strong, unique passwords for various accounts, such as administrators, services, and domain administrators.

  • Multi-factor authentication should be active for all services that support the feature.
  • Timely installation of security patches remains “one of the most effective and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats.”.
  • Limiting access to resources over the network to necessary services and user accounts.
  • Network segmentation and monitoring, to prevent third-party visibility and mapping of the network and to detect any unusual activity.
  • Temporary access for accounts with administrator privileges and above, for a limited period of time, necessary to complete a task.
  • Disable command line activities and scripts and permissions to prevent privilege escalation and lateral movement on the network.
  • Create offline backups that are encrypted and immutable.

For critical infrastructure organizations, CISA, the FBI, and the NSA have released a special set of supplemental guidance that should be prioritized:

  • Disable storing clear text passwords in LSASS.
  • Consider disabling or restricting New Technology Local Area Manager (NTLM) and WDigest authentication .
  • Credential Guard application for Windows 10 Server 2016. For Windows Server 2012R2, enable Protected Process Light for Local Security Authority (LSA).
FBI CISA

See also: Olympus: Japanese giant victim of BlackMatter ransomware?

  • Minimize the AD attack surface to reduce malicious activity. Malicious activity like “Kerberoasting” exploits Kerberos's Ticket Granting service and can be used to obtain hashed credentials that attackers try to crack.

BlackMatter is one of the top ransomware threats today. It originated from the DarkSide, which was shut down after the infamous Colonial Pipeline in May.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS