I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more!
If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the ability of a country to respond. There's only so many recovery specialists and IT contractors available to respond in an emergency. Encrypt only a few hundred targets and they can all recover. But if you encrypt a few hundred thousand, then there wouldn't be enough warm bodies available!
Thinking about it, I wonder if these attackers have set up permanent operations, with staff, payroll, and everything. Maybe they just to fly under the radar and collect a nice steady income instead of a risky but potentially huge one-time payoff...
Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack.
No worries though, the ransom from this round should serve nicely as a Series B round of financing & enable rapid scaling of the post-hack ransom extraction process.
I wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.
As I understand it there is often a lot of discourse that takes place between the hacker and the hacked - agreeing prices, haggling, proof of files etc.
Yes much can be automated but there is usually a human element to these deals and that costs the hackers money.
They also want to be careful to limit their hacks to companies their handlers are happy for them to hack. Go too wide and you risk hitting a company directly or indirectly linked to your state/handler/patron.
You are correct. I have had the "pleasure" of going through the negotiation process before. There are even companies that specialise in it, and have DBs on who is a "trusted" threat actor (the industry term) who will actually honor the terms of the transaction or not.
There are thousands, if not tens of thousands, of such deals done every year.
What's not is managing big sums of money, turning crypto in to a more traditional currency/assets. That side of the operation probably has more people doing leg work than you'd think.
We really need someone from REvil to do an AMA on HN for this sort of detail. How did they get their first paying "customer"? What's their churn rate? Do they appreciate strong security measures, rendering each lost "sale" somewhat bittersweet? How are they handling the transition from developer-driven startup to a more mature organization?
I know, and yet I'm only half joking because they probably face some of the same issues as any legitimate tech business. There's plenty of extra issues on top that go with any organized crime-- money laundering, worrying about law enforcement, loyalty of their members and brutal enforcement of it. I really am fascinated by what the structure of this would look like from the inside. Of course much of it depends on the degree to which it may actually be state-sponsored, or just lightly assisted or politely ignored. Now with the added prospect of a powerful country with a vendetta against them.
It's even conceivable that if they go too far and political pressure in the US builds high enough, and Russia &/or their countries of residence are also put under pressure, that they could find themselves on the wrong end of a drone strike or no-knock flash-bank assisted rapid entry to homes and business locations. All they have to do is pick the wrong target that directly leads to deaths-- hospitals the most obvious, but industrial accidents or "rapid unplanned disassembly" of something like a chemical plant...
I was shocked at the pipeline attack, followed by one on the US's food supply. These rise to the level of terrorism, and when fear & anger become dominant motivating factors the event horizon for any ability to predict what happens will become significantly shorter and less certain.
And in the middle of all of that will be a team of techies and support staff struggling to cope with day to day realities of running a thriving organization. There's an IT Crowd satire show somewhere in there that Netflix should consider.
Unsure why everyone is acting like this is a new phenomena. These organizations have been getting multi-million payments for the better part of a decade, it is just only being covered by the media now.
Why couldn't they have bootstrapped years ago? I suspect the real reason is they actually want to avoid extensive media coverage.
1) Scale of the attacks. Taking large portions of a country's petro-chemical/energy pipeline is far above the threat level presented by most prior hacks. The same goes for shutting down ~20% of the nation's pork & beef food supply. And now hundreds of companies impacted as a result of a single breach. Ransomware isn't new, but it is in hockey-stick growth mode.
2) Increased market for crypto currencies. Criminal activity may not, by far, be the dominant activity, but the more legitimate transactions there are, the easier it is to hide criminal transaction.
3) Bootstrapping this type of thing takes time because it's not just about capital in this case. It's also about accumulating vulnerabilities and compromising systems long enough that backups-- for example a week or month old-- are still useless (also encrypted). And going back to earlier backups will lose the company too much essential data.
4) And as you said, avoiding media coverage that will bring too much attention, and with it the potential for a crackdown. The slow burn on increasing ransomware over the years has acclimate people to it in a way that makes even the most recent massive attacks a little more normalized, especially when they pay the ransom & get back up & running in a few days. That limits the amount of public pressure to fight this head on with mandated increased security and massive resources thrown at pro-actively going after these hackers.
5) In 2016 ransomware wasn't quite as mature. 2020 is different, and the political landscape is different: I'm not making a partisan comment here. I'm not saying the previous US administration prevented these things better or the current administration dropped the ball. What I'm saying is that when there's any new administration, there are threat actors that will test the waters, see how far they can go. I definitely thing that's a factor here, especially so close after the Biden administration delivered its list of 16 untouchable sectors to Russia & Putin. There's going to be a lot of adversarial interest in just how firm those limits are, and what the response will be.
Otherwise, from a national awareness standpoint, you do approach an important point: It may not be a new phenomena, but for the vast majority of Americans that don't follow tech news, this is new and, given the scale of recent attacks, somewhat scary.
It's not enough to just gain access - once you're in you need to compromise other defenses, you need to communicate your demand to the victim, you need to know how much to extort, you need to actually process the payment. Either you do this on a case by case basis or you take advantage of additional exploits that will only be viable for a subset of your potential targets, and this is all a race against time before someone notices your initial exploit. Either way, it's likely impractical for any non-nation state actor to simultaneously attack more than a few thousand targets in one go.
This is combined with a business model resembling patent trolls: you want to extort just a little less than is worth fighting for. If a company gets hit on its own, it's probably not in a position to really do anything about it, but if there is some major hack affecting tons of companies, the odds of an actor with significantly more tech capability like the US government getting involved go way up, and suddenly fighting seems like a good option.
My mind went there as well. Say I'm an affluent oligarch shorting major companies. I'd paying the ransom group to massively attack the company or various companies. Then cash out during the chaos.
SolarWinds affected 100% of installations that updated their deployments during that 8 month window. Your 1% comes from the ratio of networks that were specifically targeted and received 2nd stage with all the goodies.
The reason why 2nd stage was only given to (relatively) small number of organizations - because the attack wasn’t ransomware, attackers didn’t have economical motives (in fact they were spooks on a government payroll).
FWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic)
The administration left it alone for days saying they'll let private business sort it out. (Default investigation notwithstanding.)
When a bunch of news media started reporting the group was Russian and then insinuate it was a state sponsored attack, DarkSide said something along the lines of, "We didn't realize this would start geopolitical conflict. We will be careful to vet clients more carefully in the future."
They also accepted a ransom substantially below their typical going rate. The Darkside people were probably shitting their pants, this is not what they intended at all.
Well, if the attacker manages to kill a few thousand people, there's precedent for the USA going to war over it. It would depend on the host nation of course, if it was e.g. China, Russia or some state in their sphere of influence, it'd be different than if the hackers were holed out in, say, Afghanistan.
At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism.
Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker.
Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters didn't pay. There were no further attacks. The Teamsters declined to comment. (For those unfamiliar with American labor history, trying to push around the Teamsters Union usually ends badly for the pushers.)
You make it sound like the Teamsters Union could do something bad to the attackers, so attackers gave up, but in reality Teamsters just rebuilt from archives, which was perhaps an economical decision:
“Ultimately, the union decided not to pay the ransom based on advice from its insurance company, and instead rebuilt its systems based on archived materials, NBC reported.”
If i recall correctly solarwinds was more of an espionage operation by russia government actors. Their targets were mainly government agencies in US. The ransomware attack are from private profit-seeking groups, although I remember the head of REvil tweeted once he was neighbours with KGB's number two guy so you could argue the distinction is vague
Attribution is quite hard. When the 3-letter-agency tools leaked a few years ago, one of their leaked tools concerned deliberate false attribution.
The solarwinds attack seemed to be about using a supply-chain attack to gain persistent access for recon and lateral movement. Pivot to Azure via Microsoft via SolarWinds software. Whomever it was tried to stay invisible for as long as possible. Once the game was up, they were not so careful about visible actions.
RansomWare is more smash and grab though it's interesting/sad to see the current trends of Supply Chain attack prevalence and Ransomware attacks converge.
> The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more!
If it was me (it was not), I’d use it to gain persistance in companies like Kaseya, extending my beachhead as first priority. After that is basically game over, cleaning it would take making new IT systems from scratch. And lets not forget firmware…
Solarwinds was distributed by a malicious patch (through legit channels). So all orgs were unpatched and in fact all got at least first stage downloaded (if they patched during that window).
Steady income is definitely the way to play. You don’t want to make a demand so large that there’s cheaper alternatives of dealing with you.
Also you want the company to stay in business so it can continue generating revenue to extract future ransoms, and not have it lose a bunch of its customers from your repeated attacks.
I did write an answer before but now it seems like only Internet facing VSA servers are effected and some other measures may have stopped the attack. It could be all the servers they could find...
I would not be surprised if there is a market for the tools and the knowledge. That the real hackers just sells it and then other people do the attacks and thereby taking the risk. Similar setups existed with botnets.
Yeah unless they work from an office in e.g. Moscow. The US is powerful for sure but even they would think twice before droning a building in Moscow over some hacks, especially without concrete proof that's where they originated. At least I hope they would because if not then we may be closer to a world war than we thought...
If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the ability of a country to respond. There's only so many recovery specialists and IT contractors available to respond in an emergency. Encrypt only a few hundred targets and they can all recover. But if you encrypt a few hundred thousand, then there wouldn't be enough warm bodies available!
Thinking about it, I wonder if these attackers have set up permanent operations, with staff, payroll, and everything. Maybe they just to fly under the radar and collect a nice steady income instead of a risky but potentially huge one-time payoff...