As the story behind the Kaseya ransomware attack by a Russian cybercrime cartel continues to unfold, threat researchers at Palo Alto Networks Unit 42 and Cisco Talos warn that all networks are susceptible, trust must be continually validated, and that REvil may not have been the first to exploit Kaseya’s VSA software.
The attack, which hit late Friday ahead of the Fourth of July holiday weekend, had two parts. First, the criminals exploited a zero-day vulnerability in Kaseya VSA software. This gave them privileged access to VSA servers, which they then used to deploy REvil ransomware across multiple managed service providers (MSP) that use the IT management software and demand a $70 million payment.
Kaseya estimates the attack hit “fewer than 60” of its customers, however because most of these are MSPs, the total number of affected organizations is likely between 800 and 1,500. These include New Zealand schools, a Swedish grocery store chain, and hundreds of other small and midsized businesses.
“Because this was a zero-day, this particular group used it in a very noisy manner that really opened the door to everybody seeing what it was,” Cisco Talos threat researcher Nick Biasini said during a LinkedIn live-stream event. “That does not mean they are the first group to use this exploit.”
Both Kaseya and law enforcement advised organizations to immediately shut down VSA servers, and Kaseya has not yet issued a patch. But after shutting down the servers, Talos suggests reviewing logs for any irregularities that might point to additional exploits of this zero-day bug. “Go back in time, and look at your logs to find if you had a potential incident previous to this that you weren’t aware of,” Biasini said.
The attack also illustrates the importance of adopting a zero-trust security framework, he added. Zero-trust technologies ensure that only continuously verified users and devices are allowed access to corporate resources and restrict data on a least-privilege basis.
“What they’re really trying to do is abuse trust,” Biasini said, referring to the attackers. “We’ve seen MSPs abused before, we’ve seen MSP management software abused before. This is not new, and what organizations need to realize is: Trust is a necessary part of doing business. But it’s something that you need to continually evaluate. Trust is a great thing, but it can be abused if it’s not validated and vetted, on a continual basis."
While the $70 million ransom demand is the largest to date, it follows REvil’s earlier Memorial Day attack against JBS during which the Russia-based ransomware gang extorted $11 million from the meat processor.
“It’s an escalation from the ransomware cartels because this is a full supply-chain attack,” Biasini said. “These actors are not going away. There is hundreds of millions of dollars flowing into this illicit marketplace right now and, unfortunately, things are gonna get worse.”
This puts added pressure on companies to reevaluate their security posture and risk, he added. “Small vulnerabilities that you don’t patch can be devastating,” Biasini said. “With affiliate groups growing more and more prevalent, there’s going to be more and more people that are very skilled at this looking at organizations that aren’t used to being looked at by this level of adversary. So be proactive, work ahead, address your issues before a ransomware cartel finds them.”
Palo Alto Networks Investigates REvilPalo Alto Networks’ threat intelligence team, Unit 42, has been monitoring attackers tied to REvil since 2018, and has responded to more than a dozen cases involving this particular ransomware gang, Palo Alto Networks SVP Wendi Whitmore wrote on LinkedIn. “It is now one of the most prominent providers of ransomware as a service, or RaaS,” she wrote.
In a subsequent Unit 42 blog post, threat researcher John Martineau said REvil and its affiliates pulled in, on average, $2.25 million per ransomware attack over the first six months of 2021. “The size of specific ransoms depends on the size of the organization and type of data stolen,” he wrote. “Further, when victims fail to meet deadlines for making payments via bitcoin, the attackers often double the demand. Eventually, they post stolen data on the leak site if the victim doesn’t pay up or enter into negotiations.”
The ransomware gang frequently uses phishing or compromised credentials to remotely access corporate assets through Remote Desktop Protocol (RDP) in its attacks, he added. However, REvil has also compromised networks via the Microsoft Exchange server bugs and the more recent SonicWall vulnerability.
Unit 42 urges network defenders to “think like the attacker,” and implement least-privilege access to corporate resources as well as strong endpoint visibility and detection tools.
“While the REvil operational group may target large organizations, all are potentially susceptible to attack,” Martineau said. “As we draw closer to a post COVID-19 environment, IT and other defenders of networks should take time to learn what’s normal in their environments and notice and question abnormalities.”
Comments