HomeSecurityPhobos ransomware targets critical US infrastructure

Phobos ransomware targets critical US infrastructure

US cybersecurity and intelligence agencies are warning of attacks by the Phobos ransomware, targeting government entities and critical infrastructure.

Phobos ransomware critical infrastructure

Phobos ransomware operates as ransomware as a service and has targeted entities such as municipal and county authorities, emergency services, organizations , healthcare organizations, and critical infrastructure.

Phobos first appeared in May 2019 and several variants have been identified to date, including Eking, Eight, Elbie, Devos, Faust, and Backmydata. Late last year, Cisco Talos revealed that the threat behind the 8Base ransomware were leveraging a variant of the Phobos ransomware to carry out their attacks.

In most cases, attacks begin with phishing emails to install hidden payloads such as SmokeLoader. Alternatively, vulnerable networks are compromised via exposed RDP services.

See also: Ransomware groups are using more infostealers

After the initial breach, attackers install additional remote access tools, exploit process injection techniques to execute malicious code, and make modifications to the toWindowsmaintain Registry persistence in compromised environments.

Security services also reported that the hackers behind Phobos ransomware often use built-in Windows API functions to steal tokens, bypass access controls, and create new processes to gain more privileges by exploiting the SeDebugPrivilege process.

“The hackers behind Phobos attempt to gain access by using cached password hashes on victims' machines until they reach domain administrator access.“.

Additionally, open-source tools such as Bloodhound and Sharphound are used. File extraction is completed via WinSCP and Mega.io, after which volume shadow copies are deleted, in an attempt to make recovery more difficult.

Phobos ransomware targets critical US infrastructure

Ransomware attacks on critical infrastructure

A Phobos Ransomware attack on critical infrastructure in the US could have serious consequences. First, it could cause paralysis in systems IT, disrupting services provided to citizens.

Second, an attack could lead to the loss of sensitive data, which could pose national security. This data could include information about infrastructure, energy, health, and other critical assets.

See also: BlackCat ransomware: Data theft from Change Healthcare platform?

Third, the attack can cause financial damage. Restoring systems and recovering data can cost millions of dollars, while service disruption can have a negative impact on the economy.

Finally, there is a risk that public trust in government and public services will be undermined. This could lead to political instability and increase concerns about cybersecurity.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Fortunately, there are some methods to deal with Phobos Ransomware. First of all, it is important to use antivirus software and security programs.

Additionally, regularly backing up important data and files can prevent information loss in the event of an attack.

Phobos ransomware targets critical US infrastructure

Educating users on how to recognize and avoid suspicious emails and links is also an effective method for preventing ransomware from being installed .

See also: Rhysida ransomware: Selling Lurie Children's Hospital data

Updating systems and applications is also essential to correct security gaps that hackers.

Finally, working with IT security experts can help address the impacts of a Phobos Ransomware attack.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS