{"id":47383,"date":"2022-08-10T03:24:00","date_gmt":"2022-08-10T03:24:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/47383"},"modified":"2022-08-10T03:24:00","modified_gmt":"2022-08-10T03:24:00","slug":"coopetition-a-growing-trend-among-ransomware-gangs","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=47383","title":{"rendered":"\u2018Coopetition\u2019 a growing trend among ransomware gangs"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/08\/coopetition-a-growing-trend-among-ransomware-gangs.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>More and more ransomware victims are finding they are being attacked by multiple gangs, with attacks taking place in waves that can be days or weeks apart, and sometimes even occur simultaneously, <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/08\/09\/multiple-attackers-increase-pressure-on-victims-complicate-incident-response\/\">according to cyber kingpin Sophos<\/a>.<\/p>\n<p>Presenting its findings at <a href=\"https:\/\/www.blackhat.com\/us-22\/\">Black Hat USA 2022 in Las Vegas<\/a>, the Sophos X-Ops team found that multiple ransomware exploitations boil down to two key issues: the target having failed to address significant exploitable vulnerabilities in their systems (Log4Shell, ProxyLogon and ProxyShell being the most widely used); or the target having failed to address malicious tooling or misconfigurations that previous attackers had left behind them.<\/p>\n<p>Furthermore, X-Ops \u2013 <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252522922\/Sophos-launches-cross-operational-task-force-X-Ops\">a recently launched unit<\/a> within the business that is bringing together its research and threat response teams to create an \u201cAI-assisted\u201d security operations centre (SOC) \u2013 said that in many cases, access-as-a-service (AaaS) listings posted to dark web markets by initial access brokers (IABs) are sold on a non-exclusive basis, meaning they are sold to multiple buyers many times over.<\/p>\n<p>\u201cIt\u2019s bad enough to get one ransomware note, let alone three,\u201d said John Shier, senior security advisor at Sophos. \u201cMultiple attackers create a whole new level of complexity for recovery, particularly when network files are triple encrypted. Cyber security that includes prevention, detection and response is critical for organisations of any size and type \u2013 no business is immune.\u201d<\/p>\n<p>In its whitepaper <em><a href=\"https:\/\/assets.sophos.com\/X24WTUEQ\/at\/q6r6n3x43mnrfchn5tfh3qmw\/sophos-x-ops-active-adversary-multiple-attackers-wp.pdf\">Multiple attackers: A clear and present danger<\/a><\/em>, X-Ops shares the story of one recent incident in which three different ransomware crews \u2013 Hive, LockBit and BlackCat \u2013 consecutively attacked the same victim network, with the first two incidents unfolding in the space of just two hours, while the third attack came a fortnight later. In each case, each gang left its own ransom demand, and some of the victim\u2019s files were encrypted three times over.<\/p>\n<p>This attack dates back to 2 December 2021, when a likely IAB established a remote desktop protocol (RDP) session on the victim\u2019s domain controller in a session lasting 52 minutes. Everything then went quiet until 20 April 2022, when <a href=\"https:\/\/www.computerweekly.com\/news\/252522035\/LockBit-ransomware-gang-launches-bug-bounty-programme\">LockBit<\/a> gained access to the network \u2013 possibly, though not necessarily, via the exposed RDP instance \u2013 and exfiltrated data from four systems to the Mega cloud storage service. A little over a week later, on 28 April, the LockBit operator began moving laterally and executed Mimikatz to steal passwords.<\/p>\n<p>Then, on 1 May, they created two batch scripts to distribute the ransomware binary using the legitimate PsExec tool. It took 10 minutes to execute the binary on 19 hosts, encrypt the data and drop ransom notes. However, within the space of 120 minutes, a <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252522715\/Researcher-develops-Hive-ransomware-decryption-tool\">Hive<\/a> affiliate appeared on the network using the PDQ Deploy tool to distribute their own ransomware binary, which executed within 45 minutes on 16 hosts.<\/p>\n<p>The <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252516148\/BlackCat-emerges-as-one-of-the-top-ransomware-threats\">BlackCat<\/a> (aka ALPHV) attack took place on 15 May, when an affiliate gained access to the network, moved laterally using stolen credentials, and distributed their ransomware binaries, again using PsExec. These executed on six hosts within 30 minutes, after which BlackCat started to clear the victim\u2019s Windows Event Logs relating not only to their attack, but to those of LockBit and Hive. This significantly complicated subsequent&nbsp;Sophos investigations \u2013 which was, of course, BlackCat\u2019s intention.<\/p>\n<p>The X-Ops team said cyber criminal gangs were competing for resources that are ultimately limited to some degree, making it harder for them to operate simultaneously, and in some of the other attacks detailed in the extensive whitepaper, the team described how other types of malware, like cryptominers or remote access trojans (RATs), often make a virtue of being able to kill off competitors if found.<\/p>\n<p>However, said Shier, in the case of ransomware gangs, there appears to be less open antagonism. \u201cIn fact,\u201d he said, \u201cLockBit explicitly doesn\u2019t forbid affiliates from working with competitors, as indicated in the Sophos whitepaper.<\/p>\n<p>\u201cWe don\u2019t have evidence of collaboration, but it\u2019s possible this is due to attackers recognising that there are a finite number of \u2018resources\u2019 in an increasingly competitive market. Or, perhaps they believe the more pressure placed on a target \u2013 i.e. multiple attacks \u2013 the more likely the victims are to pay. Perhaps they\u2019re having discussions at a high level, agreeing to mutually beneficial agreements, for example, where one group encrypts the data and the other exfiltrates.<\/p>\n<p>\u201cAt some point, these groups will have to decide how they feel about cooperation \u2013 whether to further embrace it or become more competitive \u2013 but for now, the playing field is open for multiple attacks by different groups.\u201d<\/p>\n<p>Sophos has previously reported on similar attacks, earlier this year detailing the tale of one US public sector victim which fell victim to a particularly messy attack, <a href=\"https:\/\/www.computerweekly.com\/news\/252515905\/Criminals-researched-hacking-TTPs-post-breach-in-messy-cyber-attack\">also involving LockBit<\/a>.<\/p>\n<p>In this attack, the initial compromise took place in September 2021 via RDP and saw an attacker gain access to one of the victim\u2019s servers which they then used to research hacking tools that they then attempted to install.<\/p>\n<p>However, in January 2022 someone with access to the network started to act in a way that suggested a separate group had become involved \u2013 the activity became altogether more skilled and focused, and ultimately, a partially successful LockBit attack occurred.<\/p>\n<p>This could indicate a number of different scenarios, but based on X-Ops research, it is very likely also an example of access having been sold on to multiple groups.<\/p>\n<p>As with any investigation relying on observations made or incidents responded to by a single cyber company, it is hard to say with any statistical certainty that multiple attacks are a trend, but Sophos incident response director Peter MacKenzie said the signs pointed to an answer in the affirmative. \u201cThis is something we\u2019re seeing affecting more and more organisations,\u201d he said.<\/p>\n<p>As ever, attention fully paid to some basic aspects of cyber hygiene will reduce one\u2019s chances of falling victim to any cyber attack \u2013 let alone multiple concurrent ones.<\/p>\n<p>Top tips include patching early and often, and ensuring patches are correctly applied; monitoring the cyber community and news agenda to get a heads up on new vulnerabilities; monitoring and responding to alerts, particularly during off-peak hours, at weekends or holidays; locking down accessible services used by VNC, RDP and the like; practicing segmentation and zero trust; enforcing strong passwords and multifactor authentication (MFA); taking inventories of all assets and accounts; using layered protection to block attackers at more than one point, and extending that to all permitted endpoints; and configuring products correctly and checking them frequently.<\/p>\n<p><strong>&nbsp;<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>More and more ransomware victims are finding they are being attacked by multiple gangs, with attacks taking place in waves that can be days or weeks apart, and sometimes even occur simultaneously, according to cyber kingpin Sophos. Presenting its findings at Black Hat USA 2022 in Las Vegas, the Sophos X-Ops team found that multiple [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":47384,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-47383","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/47383","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=47383"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/47383\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/47384"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=47383"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=47383"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=47383"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}