The attack on the popular MOVEit file transfer system — whose effects are as yet impossible to gauge and will likely reverberate for months, even years to come — was an unprecedented campaign of mass-produced extortion.
Orchestrated by ransomware gang CL0P exploiting a zero-day vulnerability, it is now considered one of the largest hacks of 2023 — and potentially in recent history. To date, it is known to have impacted more than 1,150 organizations and nearly 56 million individuals, putting its global cost at close to $11 billion.
“Companies small and large, in different locales, were hurt,” Alex Holden, CISO of cybersecurity company Hold Security, said in an in-depth webinar during the recent RSA Conference. “Everybody was surprised.”
Recounting the MOVEit file transfer software ransomware attackMOVEit file transfer software is used by thousands of organizations around the world. In late May, it was discovered that large amounts of data were being transferred from its deployments. Attackers were exploiting a zero-day software vulnerability — or that which is discovered by threat actors before defenders, meaning there is no known or as-yet developed patch.
The campaign indicates that ransomware is taking on a whole new model, Holden said. In the past, threat actors would hack a system and encrypt data while also exfiltrating unencrypted data to have a copy when blackmailing organizations. Then, if enterprises didn’t pay, exfiltrated data would be sold on the dark web.
But this method is dropping rapidly, Holden said, because it is much less reliable due to advanced cybersecurity mechanisms. Also, more organizations have simply refused to pay, thus stalling threat actors’ momentum.
Thus, data exfiltration extortion is becoming the best way to go for attackers, who are increasingly targeting data-rich apps rather than networks.
“We're seeing a transformation of ransomware, the term is changing meaning,” said Holden. “Data encryption is not the big focus, it's data exfiltration and extortion.”
Push to the cloud is introducing vulnerabilities like MOVEitWhile digital transformation is a must for modern enterprises, it can result in dire consequences when done too fast — as was the case with MOVEit, Holden said. Driving customers to the cloud in rapid fashion often results in lack of development and testing and neglect of cybersecurity hygiene.
MOVEit had fallacies in its legacy products that had not been given proper care or monitoring, Holden said. There was also a lack of webroot file monitoring and quantitative analysis that could have identified the massive transfers CL0P was making.
“Very sophomoric-level vulnerabilities found within MOVEit software led to this whole demise,” said Holden.
Because it was zero-day, exfiltration of terabytes of data to CL0P storage happened very quickly and with “surgical strikes,” he said.
And, because FTP software is embedded in many systems, processes and workflows, it is more difficult to patch and pinpoint exactly what was exfiltrated, Peter Firstbrook, Gartner distinguished VP analyst, told SDxCentral.
“It’s difficult to find this stuff, it’s embedded in architecture in different places,” he said, adding that it’s impossible to know how many organizations were impacted. He added, “In some ways, this was a digital supply chain attack.”
Furthermore, the CL0P gang was extremely coordinated and resilient, with secure storage and strict directives, Holden pointed out. They also didn’t brag about their exploits, instead keeping it top secret because they knew it had the potential to be one of the greatest ransomware campaigns of our time.
“They were very diligent; very, very careful about not getting caught,” he explained.
Shaming is the primary directivePost-breach, blackmail notes were sent out to hundreds of victims, many of whom paid (which at this point is legally and ethically permissible), Holden said.
In instances where organizations didn’t pay, on the other hand, CL0P became “incensed,” Holden said. The group vehemently posted on their website: “The company doesn't care about its customers, it ignored their security!!!”
In some cases the attackers called out specific companies including Aon (accusing them of corruption, bribery and operation within terrorist states), Ernst and Young (posting client lists to prompt consternation among customers) and TD Ameritrade (calling out one of their negotiators who angered them).
“This was purely shaming and companies trying to save face,” Holden said, adding that in Ameritrade’s case, “bad negotiations can hurt a company.”
Dynamic monitoring and quotasNumerous vendors now offer patches of the vulnerability, while some organizations are hastily abandoning MOVEit software altogether. However, Firstbrook pointed out, this vulnerability could well make the file sharing vendor much stronger and resilient.
Whatever FTP server is used, Holden advised, organizations must have file transfer protocols, management tools and limitations in place. They should “dynamically monitor” and check the size of each account for maximum data storage — a good practice is to have quotas on each account (typically 10 gigabytes), with transfers of more than that amount to an external IP address setting off alerts.
“This way, the CL0P gang would get caught,” he said. “Yes, there will still be a data loss, but it's not going to be a complete data loss.”
Practice basic cybersecurity hygieneAt the end of the day, though, experts say that protection against such attacks comes down to basic cybersecurity practices and hardening of the digital supply chain.
At a minimum, said Firstbrook, infrastructure that is handling sensitive data should be monitored for suspicious changes and deviations in traffic flows. He pointed out that “change doesn’t indicate maliciousness,” but it could be a strong indicator that an attacker is in the system.
Additionally, the network should also be restricted so that it only communicates with the servers it needs to, he said.
When acquiring software, meanwhile, analyze vendors’ vulnerability disclosure programs, he advised — for instance, how often they patch, how they maintain quality control, and whether they perform reverse testing.
While catastrophic in some cases, the MOVEit breach is a good opportunity to step back and look at the digital supply chain, he contended.
Because it’s impossible to predict where the next threat will come from, it's important to do scenario planning on keystone software. And, while patch management is a critical functionality in security that is nothing new, “organizations shouldn't lose sight of that,” he said. “It’s basic hygiene.”
In the end, all software has flaws, and organizations need to accept that they will be vulnerable until those are discovered.
“The rub is this is one piece of software, most organizations have thousands of pieces of software,” said Firstbrook. “We don't know where the next attack will come from in the digital software supply chain, there will be one.”
Paying ransoms a tough choice — and a personal oneHolden agreed that organizations shouldn’t have “blind trust” in cybersecurity tools, and that “the lesson is to be ready.”
And, if organizations are breached and their data is held ransom, the question of paying up is case by case. While he emphasized that he doesn’t advocate for paying ransom, the simple fact is that companies have to make “dire decisions under dire circumstances.”
Until ransomware response protocols are regulated — if they ever are — it is a personal decision for organizations, “which perhaps are fighting for their survival.”
The ransomware industry is flourishing because enterprises pay large sums to protect their data and groups like CL0P have an honor of sorts in keeping to their word that they won’t exploit it.
“If no companies paid the ransom, ransomware gangs would cease to exist — but this probably won't happen anytime soon,” Holden said.
CL0P: Inside the gangAt least that’s what CL0P and gangs like it are hoping for.
To this point, CL0P likes to call itself a “cockroach” — typically a pejorative — because the bugs are so resilient and can seemingly survive anything, Holden said, who has had conversations with members while posing as a hacker and has also negotiated with them on behalf of clients.
Indeed, the gang has been around since 2018 — five years is a long time for a ransomware group to exist, Holden said. They started out by focusing purely on encryption-based attacks and were “unremarkable” in their beginning with several “very spectacular failures” because they targeted smaller companies without the means to pay ransoms.
As a result, they weren’t expected to last long, particularly in light of the fact that, in summer 2021, Ukrainian police arrested and raided the homes of two members.
Still, they persisted, fueled largely by the success of a zero-day vulnerability attack on a legacy file transfer application from investment banking firm Accellion. That campaign has impacted more than 100 companies, organizations, universities and government agencies around the world.
Accellion provided a good formula that the gang — which, based on Holden’s research, has a core team of six on the technical side, two to three coordinators, two negotiators and a couple other members “phasing in and out” — that they keep replicating to great success.
It’s believed that CL0P purchased the zero-day vulnerability used against MOVEit on the dark web for about a quarter million dollars, Holden said — but that’s nothing compared to the millions they received from Accellion payouts.
As he noted, extortion and shaming is “a very resilient and very good business model for them, unfortunately for us.”
Comments