Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Security

REvil Ransomware Hits 200 Companies In MSP Supply-Chain Attack (bleepingcomputer.com) 39

A massive REvil ransomware attack affects multiple managed service providers and their clients through a reported Kaseya supply-chain attack. Bleeping Computer reports: Starting this afternoon, the REvil ransomware gang targeted approximately eight large MSPs, with thousands of customers, through what appears to be a Kaseya VSA supply-chain attack. Kaseya VSA is a cloud-based MSP platform that allows providers to perform patch management and client monitoring for their customers. Huntress Labs' John Hammond has told BleepingComputer that all of the affected MSPs are using Kaseya VSA and that they have proof that their customers are being encrypted as well. "We have 3 Huntress partners that are impacted with roughly 200 businesses encrypted," Hammond told BleepingComputer. Kasey issued an security advisory on their help desk site warniong all VSA customers to immediately shut down their VSA server to prevent the attack's spread while they investigate. In a statement to BleepingComputer, Kaseya stated that they have shut down their SaaS servers and are working with other securty firms to investigate the incident.

A sample of the REvil ransomware used in one of these attacks has been shared with BleepingComputer. However, it is unknown if this is the sample used for every victim or if each MSP received its own ransom demand. The ransomware gang is demanding a $5,000,000 ransom to receive a decryptor from one of the samples. While REvil is known to steal data before deploying the ransomware and encrypting devices, it is unknown if the attackers exfiltrated any files.

This discussion has been archived. No new comments can be posted.

REvil Ransomware Hits 200 Companies In MSP Supply-Chain Attack

Comments Filter:
  • by oldgraybeard ( 2939809 ) on Friday July 02, 2021 @09:19PM (#61546172)
    when you outsource security and patch management. But then it looks great in the sales brochure and allows the c-suite to pat themselves on the back. Until the chickens come home to roost.
    • You are generally not trying to outsource “trivial” things like patch management, but some level of expertise that you don’t have in-house and that requires 4-12 hours a week of work and more than a single person to accommodate vacations and such. I am fine with Linux machines, but we need Windows servers for many critical services— and having someone else manage your backup system, check logs, etc. is nice.

      I hate using them, but finding hourly IT consultants to manage this stuff ha

      • I wonder if anyone has tried to tote up the cost of all of these attacks on cloud based systems and compare them to the cost of not using the cloud?

        I'm a techie myself, but I've helped enough non-techies to have some appreciation of how difficult it is for them to manage things on their own.

        Part of the problem though, is centralization. If there were a bunch of little systems out there, each slightly different, they might be easier to crack individually, but you'd have to crack each of them individually.

        I

    • The middle managers bought "somebody else to blame" when things go wrong, and now they did, and they have what they bought.

  • Have they considered just asking for donations? And saying please? Just might work.
  • by Ostracus ( 1354233 ) on Friday July 02, 2021 @09:38PM (#61546206) Journal

    Seems no one's using honey-pots [ieee.org] to catch and shut down things.

  • by psergiu ( 67614 )

    So, basically, if a company is stupid enough to use exclusively Windows PCs, they will get 100% f-ed.
    Anyone heard of any ransomware cases for companies with Linux or Mac OS workstations ?

    • Re: (Score:2, Funny)

      by Anonymous Coward

      Yep, and the striking thing is that Windows users keep coming back for more abuse. Same psychology as Tesla owners, proof that the Stockholm syndrome is real.

    • Who cares about the workstations if you can do it directly from the servers? Very few companies manage SSO from a Linux machine as there are simply too many things that just don’t work. Likewise, robust backup software for SMEs is almost exclusively Windows. How about enterprise accounting systems nothing for Linux servers.

      • How about enterprise accounting systems nothing for Linux servers.

        That's a surprisingly large gap in the market that shouldn't exist. It could easily be filled by 3 interns over a long weekend. That was obviously how SAP was written, so the quality will be the same.

        I kid. An open source enterprise accounting system for Linux will rapidly eclipse SAP in quality.

    • by Anonymous Coward
      Depending on where you get your numbers, the current OS market share is roughly Windows 75%, MacOS 15%, and Linux 2.3%. With 7% listed as Unknown, there is some wiggle room for all those numbers.

      Let's pretend you are a malware writer. Which OS would you target for the best return of your misplaced talent? Sure, plenty of universities and artists are using MacOS, but they probably aren't going to pony up a few million dollars to get their data back.

      Anyone heard of any companies with Linux or Mac OS workstations ?

      FTFY.

      • I mean, if you want to hit any significant tech company (a than Microsoft), youâ(TM)d better be targeting macOS, not windows. I suspect their choice to attack windows is because theyâ(TM)re softer targets for a variety of reasons:

        1. Itâ(TM)s more likely that windows businesses are using this kind of management scheme that amounts to preinstalled malware. Itâ(TM)s easy to attack a system thatâ(TM)s already deliberately compromised.

        2. The big tech companies running macOS actually kn

    • by labnet ( 457441 )

      Lets See.
      Our ERP System - Windows Only
      ECAD System - Windoes Only
      MCAD System - Windows Only
      XRAY System Software - Windows Only
      Robot Prep Software - Windows Only
      3CX - Windows Only
      Yes, we have many linux servers for things like RedMine, BuildBot, Git
      BUT, most engineering businesses have to use windows.

    • If Linux had a 90% desktop market share, yes absolutely.

  • Mandatory backups and you have to be able to restore those backups in less than an hour: then where would ransomware attacks be?

    • > Then where would ransomware be? In your backup program
    • Encrypting the backups.

      A backup like this has to be networked and automated. So attacking it becomes a priority goal.

      In any case, the problem with Ransomware in the age of remote working is not cleaning the network and getting your data from backups. The problem is bringing the workforce back online after that. You never know. One of the PCs that just came over the VPN may carry the viral payload. Then it is back to the starting point.

    • by Entrope ( 68843 )

      Restoring within an hour would be optimizing for the wrong case, and probably open an additional attack surface through the automated-restore function.

      Being able to start restoring within two hours, and complete restore within another two, seems reasonable. For a current typical desktop, that is pretty easy -- maybe 1 GB/minute. A server might need a higher-speed network to restore data on time. Maybe extend it to eight hours if enough computers are affected; businesses should have a continuity plan that

    • In the MSP space, backups are the red-headed stepchild. Most companies employing an MSP don't really want to spend money for backups with high retention, high performance and better security options. In my experience, they barely are willing to pay for something that meets the definition of a "backup".

      MSPs who try to "solve" this while respecting low-budget customer cost expectations end up magnifying some vulnerabilities with too many shared credentials and often a backup environment too heavily exposed

  • Sad world we have, where convenience on using windows means more of this to continue. As far as I can remember, since at least the 1990's windows has been the constant giver of problems.
  • by johnnys ( 592333 ) on Friday July 02, 2021 @10:11PM (#61546248)

    The "MSP" to quietly shut down, lay off all the employees, and the owners decamp to a non-extradition location to live a life of luxury with all the money left over. Meanwhile the suckers, I mean customers, are left to deal with the mess.

    This is what happens when you outsource your responsibilities.

    • by mjwx ( 966435 )

      The "MSP" to quietly shut down, lay off all the employees, and the owners decamp to a non-extradition location to live a life of luxury with all the money left over. Meanwhile the suckers, I mean customers, are left to deal with the mess.

      This is what happens when you outsource your responsibilities.

      Actually they don't need to go to a non-extradition location. Just declare bankruptcy to get legal protection whilst you start up a new company. Pheonixing, protecting your bad business decisions. I work for a GSI, we've been receiving calls all day about this, but it's OK because we patch and isolate our shit to prevent these kinds of attacks (shit for the guys on the phone though because they have to repeat the same thing over and over again).

  • I haven't flown for a couple of years, but I usually fly from or to Minneapolis St. Paul airport (MSP)

    • by bardrt ( 1831426 )
      Managed Service Provider.
      Basically, instead of having in-house IT people at your company, you pay another company to do the IT work for you.
    • from the wiki: https://en.wikipedia.org/wiki/... [wikipedia.org]

      A managed IT services provider (MSP) is most often information technology (IT) services provider that manages and assumes responsibility for providing a defined set of services to its clients either proactively or as the MSP (not the client) determines that services are needed.[26][27] Most MSPs bill an upfront setup or transition fee and an ongoing flat or near-fixed monthly fee, which benefits clients by providing them with predictable IT support costs. Sometimes, MSPs act as facilitators who manage and procure staffing services on behalf of the client. In such context, they use an online application called vendor management system (VMS) for transparency and efficiency. A managed service provider is also useful in creating disaster recovery plans, similar to a corporation's. Managed Service Providers[28] tend to prove most useful to small businesses with a limited IT budget.[29]

      The managed services model has been useful in the private sector, notably among Fortune 500 companies,[30] and has an interesting future in government.[31]

  • by dromgodis ( 4533247 ) on Saturday July 03, 2021 @03:55AM (#61546646)

    In Sweden an entire supermarket chain (Coop, ~800 stores) is closed since last evening because the supplier of their cash register services got hit.

    • That amounts to 20% of the national market for food. Guess ICA will get new customers...
    • I know for a fact that the Dutch Ahold group (which also owns several U.S. grocery chains e.g. Giant) uses Linux for its in-house developed cash registers and I have a hunch they will not be targets for ransomware.
      • I know nothing about what security measure Dutch Ahold has taken. But if someone is dumb with security on Linux, there is no magic reason it can't be hacked. Example: maybe they allow a remote login for diagnostics, remote firmware update, etc. Employee finds the username/password hard to remember and stores it on another machine that gets hacked. Most hacking isn't some fancy shit like in the Matrix. Most of it is getting information from dumb people (social engineering.) Linux isn't defended from th
  • When is the U.S. government finally going to urge its departments to use only microkernel-based operating systems which are known to be much more secure, even if the software running on it isn't. The best any threat actor would be able to do is a denial of service attack.

    If this continues the way it is now, the government might become rash and starts striking out at other nations, both in cyberspace and the real world.

    Seriously, I wouldn't want our government to start a nuclear war just because we can
  • by stabiesoft ( 733417 ) on Saturday July 03, 2021 @07:37AM (#61546854) Homepage
    Cost, convenience, security. Guess which two biz picks?

To be is to program.

Working...