HomeSecurityDaixin Team: Targets insecure VPN servers

Daixin Team: Targets insecure VPN servers

The FBI warns: the ransomware group “Daixin Team” targets vulnerable VPN servers. The intruders use the VPN servers to gain access and then SSH and RDP to spread across networks. The attacks are carried out mainly against the healthcare sector.

See also: Windows zero-day allows JavaScript files to bypass security warnings

Daixin Team: Targets insecure VPN servers

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) issued a joint warning about the activity of the Daixin Team against the healthcare sector since June 2022.

See also: TommyLeaks and SchoolBoys ransomware: Are they the same group?

The group uses ransomware to encrypt servers that provide services for electronic health records, diagnostics, imaging, and intranets. They have also stolen personally identifiable information and patient health information.

The agencies are warning healthcare providers to secure their VPN servers, as this is how the group gained access to previous targets, including by exploiting an unpatched flaw in the victim’s VPN server. In a separate confirmed case, criminals used stolen credentials to gain access to an old VPN server that did not have MFA enabled. The hackers are suspected of gaining access to the VPN through a phishing email with a malicious file attached .

After accessing the VPN, the group used the remote SSH and RDP protocols to move between systems and then sought privileged accounts through credential dumping and “pass the hash,” where attackers use stolen passwords to move between systems.

In addition to attacking the organization, the hackers used their privileged accounts to gain access to VMware vCenter Server and reset account passwords for ESXi servers. After that, they SSH into accessible ESXi servers and deploy ransomware on those servers.

The Daixin Team not only infiltrated the victims' systems, but also erased data from them.

Daixin

See also: Typosquatting: Fake sites imitate popular brands and distribute malware

The advisory states that to mitigate risks, organizations should prioritize patching VPN servers, remote access software, virtual-machine software, and vulnerabilities listed by CISA. Additionally, it is recommended to block RDP and disable SSH, as well as Telnet Winbox and HTTP for wide-area networks. When enabled, they should always be secured with strong passwords and encryption. Organizations should also require MFA for most, if not all, services whenever possible. 

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS