Networking giant Cisco admitted on Wednesday that its corporate IT infrastructure was compromised in May. On the same day, Yanluowang ransomware group published a list of files it claimed were stolen from Cisco to the dark web.
Cisco first noticed the breach on May 24 and its Security Incident Response (CSIRT) and Cisco Talos teams took immediate actions to contain and work to remediate it.
The company claims it didn’t observe any ransomware, nor identify any impact on its business, including its products, services, and sensitive customer data, so no customer’s or partner’s action is required.
“We have not identified any evidence suggesting that the attacker gained access to critical internal systems, such as those related to product development, code signing, etc.,” the Cisco Talos team wrote in a blog post. “While we did not observe ransomware deployment in this attack, the TTPs used were consistent with ‘pre-ransomware activity,’ activity commonly observed leading up to the deployment of ransomware in victim environments. ”
Cisco said it has blocked further attempts to access its network since discovering the incident. “The threat actor was successfully removed from the environment and displayed persistence, repeatedly attempting to regain access in the weeks following the attack; however, these attempts were unsuccessful,” according to the blog.
The team said an adversary who was previously identified as an initial access broker linking to the UNC2447 gang, Lapsus$ group, and Yanluowang ransomware operators, conducted the attack.
UNC2447 is a financially-motivated threat actor group that targeted organizations in Europe and North America using ransomware and “double extortion” techniques. Lapsus$ hacking group was reportedly responsible for several recent notable breaches targeted at companies including Okta and Microsoft. Yanluowang is a ransomware threat used to attack U.S. corporations since at least August 2021, according to Symantec.
Cisco’s Employee Falls Victim of Stolen Credential, Voice Phishing AttacksAttackers obtained the initial access via compromising a Cisco employee’s personal Google account.
“The user had enabled password syncing via Google Chrome and had stored their Cisco credentials in their browser, enabling that information to synchronize to their Google account,” Cisco wrote in the blog.
Then, to bypass the multi-factor authentication (MFA), the attacker used techniques including a series of sophisticated voice phishing (Vishing) attacks and sending a high volume of MFA push requests.
“Vishing is an increasingly common social engineering technique whereby attackers try to trick employees into divulging sensitive information over the phone,” according to the blog.
Ultimately, the victim accepted the MFA push notifications and the attacker gained access to the Cisco VPN.
After discovering the incident, Cisco implemented a company-wide password reset.
Comments