Joint advisory warning on the global increase in sophisticated ransomwareLeigh Mc Gowranon February 11, 2022 at 15:17 Silicon RepublicSilicon Republic

0

Cybersecurity authorities in the US, UK and Australia have issued a joint advisory warning on the increase in sophisticated, high-impact ransomware attacks on critical infrastructure.

In the US the FBI, the Cybersecurity and Infrastructure Security Agency and the NSA observed ransomware attacks against 14 of the 16 US critical infrastructure sectors in 2021.

These sectors include the defence industrial base, emergency services, agriculture, government facilities and IT.

“Ransomware tactics and techniques continued to evolve in 2021, which demonstrates ransomware threat actors’ growing technological sophistication and an increased ransomware threat to organizations globally,” the agencies said in a joint statement.

The UK’s National Cyber Security Centre recognised ransomware as “the biggest cyber threat facing the United Kingdom”.

The cybersecurity authority said education is one of the top UK sectors targeted by ransomware, but it also noted attacks targeting businesses, charities, the legal profession and public services.

The Australian Cyber Security Centre noticed a similar trend of cyberattacks aimed at the country’s critical infrastructure sectors, such as medical, financial services, energy and the higher education sector.

“If the ransomware criminal business model continues to yield financial returns for ransomware actors, ransomware incidents will become more frequent,” the agencies said. “Every time a ransom is paid, it confirms the viability and financial attractiveness of the ransomware criminal business model.”

A shift towards mid-sized victims

The report said the first half of 2021 saw a rise in ransomware attacks toward “big game” or high value organisations that provide critical services. However, these ransomware groups suffered disruptions by US authorities by the middle of 2021.

“Subsequently, the FBI observed some ransomware threat actors redirecting ransomware efforts away from “big-game” and toward mid-sized victims to reduce scrutiny,” the agencies said.

The agencies provided a list of ways organisations can try to mitigate the risk of being affected by a ransomware attack. These include keeping all OS systems and software up to date, closely monitoring riskier services such as remote desktop protocol (RDP) and implementing a user training program to raise awareness among employees.

Alon Arvatz, senior director of product management at cyber intelligence company IntSights  – a Rapid7 company – said the joint advisory is an “important step” to ensure organisations bolster their security against ransomware attacks. He said understanding the threats organisations are exposed to can be the difference between quickly dealing with malicious code or malware causing “significant damage” to a network.

“Whilst this is a step in the right direction, organisations must work to fully understand the ‘context’ behind cyberattacks,” Arvatz said. “Security teams have to be aware of the cyber criminals which are likely to target them, the techniques they use, and which systems they are most likely to target.

“With this knowledge, organisations can then increase their security in areas of the network most vulnerable and know how to defend against cyberattacks which do breach their network,” Arvatz added.

Linux attacks

A similar report released by cloud computing company VMware said there has been a rise in cybercrime aimed at Linux-based systems, in order to infiltrate corporate and government networks.

The report said Linux has become the most common operating system for “multi-cloud environments” such as data centres. It added that Linux powers more than 78pc of the world’s most popular websites. However, most current malware countermeasures are focused on addressing Windows-based threats, which cybercriminals have taken notice of.

“Cloud infrastructures and data centres host key components, such as email servers and customer databases, that have been the target of high-profile intelligence-gathering breaches,” VMware said.

VMware also said that ransomware attacks toward Linux systems are using more sophisticated techniques, such as targeting host images used to spin workloads in virtualised environments. Many of the attacks it noticed against cloud deployments were targeted rather than opportunistic.

“Ransomware attacks against cloud environments are often combined with data exfiltration, implementing a double-extortion scheme that improves their odds of success,” VMware said.

The report said one of the most common tools used by attackers is Cobalt Strike and its recent variant of Linux-based Vermilion Strike, which helps give remote access to hackers. A version of Cobalt Strike was used last year in the HSE cyberattack.

VMware said it discovered more than 14,000 active Cobalt Strike team servers on the Internet between February 2020 and November 2021.

The cloud company said organisations need to “bolster their ability to identify and defend against these types of attacks”.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

The post Joint advisory warning on the global increase in sophisticated ransomware appeared first on Silicon Republic.

Leave a Comment