Thursday, August 18, 2022
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

Regional U.S. Government Agency Hit With LockBit Ransomware

Researcher by Researcher
April 12, 2022
in Cybersecurity
0
Mobile Zero-Day, Phishing Attacks on the Rise
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Attackers compromised the network of a regional U.S. government agency, where they lurked for at least five months before the LockBit ransomware was ultimately deployed.

Upon closer investigation of the behavioral log data, researchers with Sophos observed that there may have been at least two threat groups active on the compromised network of the unnamed agency before a final group deployed the payload. While at first, the attack appeared to be carried out by seemingly-novice attackers that “then seemed unsure of what to do next,” later a likely different set of attackers deployed the ransomware, stealing data and encrypting files, according to Andrew Brandt, principal security researcher with Sophos.

“This was a very messy attack,” said Brandt. “About four months after the initial breach, the nature of the attack activity changed, in some cases so drastically that it suggests attackers with very different skills had joined the fray.”

The initial point of access for the attack, which occurred in September, appeared to be an open remote desktop protocol (RDP) port on a firewall, which was configured to provide public access to a server, said Sophos researchers in the Tuesday analysis.

After gaining initial access, attackers installed the Chrome browser to search for and download hacking tools on the compromised server. In some cases, the attackers while searching for tools visited sketchy download sites that delivered adware, rather than the tools they were looking for, an unintentionally noise move that could have opened up the attack to detection, said researchers. Attackers installed various commercial remote-access tools on accessible servers and desktops, as well as RDP scanning, exploit and brute-force password tools.

“In addition to various custom scripts and configuration files used by hacking tools the attackers installed, we found a wide variety of other malicious software, from password brute-forcers, to cryptominers, to pirated versions of commercial VPN client software,” said researchers.

“About four months after the initial breach, the nature of the attack activity changed, in some cases so drastically that it suggests attackers with very different skills had joined the fray.”

“There was also evidence the attackers used freeware tools like PsExec, FileZilla, Process Explorer or GMER to execute commands, move data from one machine to another, and kill or subvert the processes that impeded their efforts,” they said.

Despite the download of these tools, researchers noted that the attackers did not appear to be “moving toward a particular goal or operating with great urgency.” Then, in mid-January the attackers’ tactics changed significantly, when they attempted to uninstall security software, collected and exfiltrated data and deployed the LockBit ransomware, which researchers said had “limited success.”

“Fortunately for the target, on at least a few machines, the attackers didn’t complete their mission, as we found files that had been renamed with a ransomware-related file suffix, but that had not been encrypted,” said researchers. ”Cleanup in those cases just involved renaming the files to restore their previous file suffixes.”

Local governments and government agencies continue to be targeted in cyberattacks, with the FBI recently warning that in 2021, local governments represented the second highest group to be victimized by ransomware actors. In March, researchers disclosed a campaign by the APT41 group that had compromised at least six U.S. state government networks between May and February.

Researchers with Sophos said that organizations can prevent initial access by implementing security measures, like multi-factor authentication or setting firewall rules to block remote access to RDP ports. Another way to avoid an attack like this is to stay on the lookout for various tools that may have been installed for malicious purposes.

“If a member of the IT team hasn’t downloaded them for a specific purpose, the presence of such tools on machines on your network is a red flag for an ongoing or imminent attack,” said Brandt. “Unexpected or unusual network activity, such as a machine scanning the network, is another such indicator.”



Source link

Related articles

Spring Framework Flaw Exploited in Mirai Malware Attacks

CISA Warns of Ongoing Exploitation Against Zimbra Flaws

August 18, 2022
High-Severity Flaw in Argo CD is Information Leak Risk

Apple Patches New macOS, iOS Zero-Days

August 18, 2022
Tags: agencyGovernmenthitLockBitRansomwareRegional
Share76Tweet47

Related Posts

Spring Framework Flaw Exploited in Mirai Malware Attacks

CISA Warns of Ongoing Exploitation Against Zimbra Flaws

August 18, 2022
0

Attackers are exploiting multiple, previously disclosed flaws that impact Zimbra’s enterprise collaboration software and email platform, warned the Cybersecurity and...

High-Severity Flaw in Argo CD is Information Leak Risk

Apple Patches New macOS, iOS Zero-Days

August 18, 2022
0

Apple on Wednesday rolled out emergency patches for a pair of already exploited zero-day vulnerabilities in its flagship macOS and...

Seaborgium targets sensitive industries in several countries

Seaborgium targets sensitive industries in several countries

August 17, 2022
0

Image: Adobe Stock New research from Microsoft Threat Intelligence Center (MSTIC) sheds light on a cyberespionage threat actor known as...

DEF CON – “don’t worry, the elections are safe” edition

DEF CON – “don’t worry, the elections are safe” edition

August 17, 2022
0

Don’t worry, elections are safe. Our Security Researcher Cameron Camp provide us highlights from the DEF CON 30 conference. Scattered...

Azure Developers Targeted By Malicious NPM Packages

RubyGems Requires MFA for Popular Projects

August 17, 2022
0

RubyGems, the popular community site for hosting Ruby projects, is now requiring the maintainers of the most popular projects to...

Load More
  • Trending
  • Comments
  • Latest
Brave browser’s Tor mode exposed users’ dark web activity

Brave browser’s Tor mode exposed users’ dark web activity

February 18, 2022
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 18/08

August 18, 2022
Spring Framework Flaw Exploited in Mirai Malware Attacks

CISA Warns of Ongoing Exploitation Against Zimbra Flaws

August 18, 2022
High-Severity Flaw in Argo CD is Information Leak Risk

Apple Patches New macOS, iOS Zero-Days

August 18, 2022
How Can Crypto and CBDCs Help Communities?

How Can Crypto and CBDCs Help Communities?

August 18, 2022

Recent Posts

This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 18/08

August 18, 2022
Spring Framework Flaw Exploited in Mirai Malware Attacks

CISA Warns of Ongoing Exploitation Against Zimbra Flaws

August 18, 2022
High-Severity Flaw in Argo CD is Information Leak Risk

Apple Patches New macOS, iOS Zero-Days

August 18, 2022

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • Malware
  • Networking
  • Protection

Tags

Access Android attack Attacks banking BiWeekly breach bug Cisco critical Cyber Cybersecurity Data devices Digital financial Finds Fintech Flaw flaws Google Group Hackers Krebs Latest malware Microsoft million Network News open patches Payments phishing platform Ransomware RoundUp security Software TFT Threat vulnerability warns Week Windows

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved