[ad_1]

This file photo shows the inside of a computer in Jersey City, NJ Cybersecurity teams worked frantically on Sunday, July 4 to halt the impact of the largest global ransomware attack ever, with some details emerging about how the Russia-affiliated gang who was responsible for the company whose software was the channel.
Jenny Kane/AP
hide caption
switch caption
Jenny Kane/AP

This file photo shows the inside of a computer in Jersey City, NJ Cybersecurity teams worked frantically on Sunday, July 4 to halt the impact of the largest global ransomware attack ever, with some details emerging about how the Russia-affiliated gang who was responsible for the company whose software was the channel.
Jenny Kane/AP
BOSTON Cybersecurity teams worked frantically on Sunday to contain the impact of the largest global ransomware attack ever, unearthing some details about how the Russia-affiliated gang responsible for a breach of the company whose software was the channel .
A subsidiary of the infamous REvil gang, best known for extorting $11 million from meat processor JBS after a Memorial Day attack, infected thousands of victims in at least 17 countries on Friday, largely through companies that provide IT infrastructure for multiple customers. manage remotely. according to cybersecurity researchers.
REvil demanded ransoms of up to $5 million, investigators said. But late Sunday, in a post on its dark website, it offered a universal decryptor software key that would decrypt all affected machines in exchange for $70 million worth of cryptocurrency.
Earlier, the FBI said in a statement that while it was investigating the attack, its magnitude “may make it so that we are unable to respond to each victim individually.” Deputy National Security Adviser Anne Neuberger later issued a statement saying that President Joe Biden had “used all government resources to investigate this incident” and urged anyone who believed they had been compromised to alert the FBI.
Biden suggested saturday the US would react if the Kremlin was found to be even involved.
Less than a month ago, Biden urged Russian President Vladimir Putin to stop giving REvil and other ransomware gangs a safe haven. unrelenting extortion attacks the US considers a threat to national security.
A wide range of businesses and government agencies were affected by the latest attack, apparently on all continents, including in the financial services, travel and leisure and public sector, although there are few large companies, cybersecurity firm Sophos reported. Ransomware criminals infiltrate networks and seed malware that paralyzes them by encrypting all their data. Victims receive a decoder key when they pay.
Swedish supermarket chain Coop said most of its 800 stores would be closed for a second day on Sunday because their POS software supplier was crippled. A Swedish pharmacy chain, gas station chain, the state railways and the public broadcaster SVT were also hit.
In Germany, an undisclosed IT services company told authorities that several thousand of its customers had been compromised, the dpa news agency reported. Among the reported victims were also two large Dutch IT service providers VelzArt and Hoppenbrouwer Techniek. Most ransomware victims do not publicly report attacks or indicate whether they have paid a ransom.
CEO Fred Voccola of the hacked software company Kaseya estimated the casualties in the low thousands, mostly small businesses like “dental offices, architectural firms, plastic surgery centers, libraries, that sort of thing.”
Voccola said in an interview that only 50-60 of the company’s 37,000 customers had been compromised. But 70% were managed service providers using the company’s hacked VSA software to manage multiple customers. It automates the installation of software and security updates and manages backups and other vital tasks.
Experts say it was no coincidence that REvil launched the attack at the beginning of the July 4 holiday weekend, knowing the US offices would be lightly staffed. Many victims may not learn until they return to work on Monday. Most managed service provider end users “have no idea” whose software keeps their networks running, Voccola said,
Kaseya said it sent a detection tool to nearly 900 customers on Saturday evening.
REvil’s offer to decrypt all victims of the Kaseya attack in exchange for $70 million suggests it is incapable of dealing with the massive amount of infected networks, said Allan Liska, an analyst at cybersecurity firm Recorded Future. While analysts reported seeing demands of $5 million and $500,000 for larger targets, it apparently demanded $45,000 for most.
“This attack is much bigger than they expected and it’s getting a lot of attention. It’s in REvil’s best interest to put an end to it quickly,” said Liska. “This is a nightmare to manage.”
Emsisoft analyst Brett Callow said he suspects REvil hopes insurers can crack the numbers and determine that the $70 million will be cheaper for them than prolonged downtime.
Sophisticated REvil-level ransomware gangs usually examine a victim’s financial records and insurance policies if they can find it in files they steal before activating the ransomware. The criminals then threaten to dump the stolen data online unless they are paid. This does not appear to have happened in this attack.
Dutch researchers said they notified Miami-based Kaseya of the breach and said the criminals were using a “zero day,” the industry term for a previously unknown software vulnerability. Voccola wouldn’t confirm that or give any details about the breach, except to say it wasn’t phishing.
“The level of sophistication here was extraordinary,” he said.
When cybersecurity firm Mandiant completes its investigation, Voccola said he is confident it will show that the criminals not only breached Kaseya code by breaking into its network, but also exploited vulnerabilities in third-party software.
It was not the first ransomware attack to use managed services providers. In 2019, criminals stumbled into the networks of 22 Texan municipalities via a. That same year, 400 dental practices in the US were paralyzed in a separate attack.
One of the Dutch vulnerability researchers, Victor Gevers, said his team is concerned about products like Kaseya’s VSA because of its total control over the vast computing resources they can provide. “An increasing number of products used to keep networks safe and secure exhibit structural weaknesses,” he wrote in a blog post on Sunday.
Cybersecurity firm ESET identified victims in at least 17 countries, including the United Kingdom, South Africa, Canada, Argentina, Mexico, Indonesia, New Zealand and Kenya.
Kaseya says the attack only affected “on-premise” customers, organizations that run their own data centers, as opposed to the cloud-based services that run software for customers. However, it also shut down those servers as a precaution.
Kaseya, who called on customers Friday to shut down their VSA servers immediately, said Sunday he hopes to have a patch in the coming days.
REvil has been in business since April 2019 and offers ransomware-as-a-service, meaning it develops and leases the network-crippling software to so-called affiliates that infect targets and earn the bulk of the ransom. US officials say the most powerful ransomware gangs are based in Russia and allied states and operate with tolerance from the Kremlin and sometimes colluding with Russian security forces.
Cybersecurity expert Dmitri Alperovitch of the think tank Silverado Policy Accelerator said that while he doesn’t believe the Kaseya attack was sent by the Kremlin, it shows that Putin “has not yet started” taking out cybercriminals.
|
Sources 2/ https://www.npr.org/2021/07/05/1013117515/scale-details-of-massive-kaseya-ransomware-attack-emerge The mention sources can contact us to remove/changing this article |
[ad_2]