5 ms·
Dutch university hit by cyber attack on its Windows systems
- raverbashing 7y agoon its Windows systems
- supakeen 7y agoThere really isn't more information about this than the above so we don't know. Here's a few Dutch sources at the bottom you can throw through a translation service: "nearly all windows computers were hacked", "we dont know if this was criminal and if the perpetrator(s) demand money". Noteworthy quote "We are researching if the attackers could access that. Our expectation is that this is very difficult." on the storage of scientific data. https://nos.nl/artikel/2316120-cyberaanval-op-computers-van-universiteit-maastricht.html https://nos.nl/artikel/2316120-cyberaanval-op-computers-van-... https://www.1limburg.nl/groot-cyberhack-bij-um-criminele-aanval-niet-uitgesloten?context=topstory https://www.1limburg.nl/groot-cyberhack-bij-um-criminele-aan...
- chroem- 7y agoIt's interesting how the language around these incidents has shifted to give the impression that cybercommandos have stormed into cyberspace with their cyber assault rifles, when in reality the chances are very high that some university administrator probably downloaded a shady program from a porn site.
- WrtCdEvrydy 7y agoJason from Defcon had an interesting quote about it... "It's not an Advanced Persistent Threat, it's Basic Ass Threat, but you just want your cyberinsurance policy to pay out. Fuck off"
- noinsight 7y agoWhy would you blow your zero days on something when you can just download stuff off GitHub that works? Russia initially compromised the 2018 Olympics with publicly available malware off GitHub. See: https://www.wired.com/story/untold-story-2018-olympics-destroyer-cyberattack/ https://www.wired.com/story/untold-story-2018-olympics-destr...
- noinsight 7y ago> chances are very high that some university administrator probably downloaded a shady program from a porn site. Nah, in reality someone probably clicked a link in a malicious email that launched a backdoor on their computer. The likelihood of that approaches 100% on untrained users. And, as this is a university environment, that user likely had local admin. You only need 1 successful click to breach the good ol' "secure internal network" after which all bets are off - few companies sufficiently secure their networks from "internal" attackers. On a traditional Windows network, credential hygiene practices are woeful and Domain Admin (admin access to every single domain-joined device on the network) level credentials are lying around everywhere and once those are compromised, every single domain-joined device on the network can be compromised. I've seen this all happen in the span of 10 minutes - a remote user with VPN gets compromised, the attacker connects to the corporate network through them, gets Domain Admin and spreads malware through Active Directory to every single device on the network - X thousand workstations, Y hundred servers etc. There's no actual vulnerability to remediate - you just have to "administrate properly" to prevent this. (https://aka.ms/spa https://aka.ms/spa)
- FDSGSG 7y ago>Nah, in reality someone probably clicked a link in a malicious email that launched a backdoor on their computer. The likelihood of that approaches 100% on untrained users. In 2019 this is actually very unlikely. Driveby exploits have been pretty rare for years now.
- noinsight 7y agoIt's still one of the top methods. See for example Symantec's report [1] with lots of data. [1] https://www.symantec.com/content/dam/symantec/docs/reports/istr-24-2019-en.pdf https://www.symantec.com/content/dam/symantec/docs/reports/i...
- igetspam 7y agoI literally just got a call about someone being hit. The avenues used to penetrate are email spam and RDP.
- iwantagrinder 7y agoAll of this shit comes through phishing emails with Office docs containing malicious macros or links. Literally 99% of it. All of these stories should say "Sysadmins ignored best practices of disabling unapproved macros, allowing malware to gain a foothold, dump privileged credentials on the system, and move laterally through the environment with ease"
- briffle 7y agoIts a university, so more likely "Sysadmins implemented best practices of disabling unapproved macros, but due to an extreme number of complaints from academic staff that all their research would be ruined, had to disable it again."
- iwantagrinder 7y agoSo you allow it for those folks and block it for the rest, there will always be edge cases but you need to reduce risk and attack surface. So hopefully they have those academic staff members on record as accepting the risk.
- gruez 7y ago>So hopefully they have those academic staff members on record as accepting the risk. Then what? Use them as the scapegoat when the network does get compromised? Feels like the exact opposite of blameless postmortems.
- bathory 7y agoaccording to an insider, tweakers [0] is reporting that it is a ransomware attack and many device have been encrypted [0] https://tweakers.net/nieuws/161538/deel-diensten-universiteit-maastricht-offline-door-cyberaanval.html https://tweakers.net/nieuws/161538/deel-diensten-universitei...
- DavideNL 7y agoAllegedly it's the CLOP ransomware. "All dhcp-servers, Exchange-servers, domaincontrollers and networkdrives have been encrypted." Source in Dutch: https://tweakers.net/nieuws/161538/deel-diensten-universiteit-maastricht-offline-door-cyberaanval.html https://tweakers.net/nieuws/161538/deel-diensten-universitei... Clop: https://securingtomorrow.mcafee.com/blogs/other-blogs/mcafee-labs/clop-ransomware/ https://securingtomorrow.mcafee.com/blogs/other-blogs/mcafee...
- taspeotis 7y agoUh so they don’t have up-to-date AV definitions? Sounds like McAfee was on it in August and Windows Defender has it no later than the 9th of December [1]. [1] I’d expect it to be earlier than that, but this article date is the only thing I’ve found: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/Clop!MTB&ThreatID=2147746036 https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...
- kjhioyiurewr 7y agoCentral point of control (domain), central point of infection. As someone else said it, many networks are crunchy on the outside, chewy on the inside. We need a new model, that makes lateral movement much harder. There's no reason to allow an infected domain controller to infect the whole network, but I don't know what the solution looks like which still allows centralized control.
- throw0101a 7y agoAre there any documented reports of Linux/Unix systems ever being hit by ransomware? Or files on NAS appliances (NetApp, Isilon, etc) being encrypted in a way that is unrecoverable (especially since snapshots can be scheduled regularly)? Certainly you can steal data from non-Windows systems, so exfiltration attacks are similar on both, but AFAICT, these "we've got your data" style attacks are unique to Windows. If an IT (desktop/laptop) environment was more Mac-heavy, would these be an issue either?
- rb808 7y agoBasically 99.99% of companies and governments use windows so its unlikely to see this happening.
- bromonkey 7y agoWhat orifice did you pull that stat from?
- HarryHirsch 7y agoTen years ago or so, our NMR spectrometer was held ransom. OK, it was a completely out-of-date Solaris, not Linux, but if don't use Windows you are not immune.
- mmilgauss 7y agoLinux systems are less targeted because they're less commonly used, their userbase on average knows more about technology and they're inherently more secure.
- zeta0134 7y agoHa! This got a good chuckle out of me. Check again; this happens more often than you would think in the web hosting business, especially the small to medium business segment. "It's just a website how hard could it be?" If I had a nickel for every RHEL 5 (yes, 5!) box still running after we begged customers to please, please move to something actually receiving patches... In theory ransomware shouldn't have as large of an impact, but in practice backups are not a magical wand of "restore website and lose 0 transactions" either. That's assuming the backups are actually configured to grab the correct data, and haven't been silently failing for months...
- Twiebie 7y agoIs this similar to what happened this month in Germany? https://www.zdnet.com/article/more-than-38000-people-will-stand-in-line-this-week-to-get-a-new-password/ https://www.zdnet.com/article/more-than-38000-people-will-st...
- gshubert17 7y agoBig list of ransomware or possible ransomware attacks in 2019 at: https://techtalk.pcmatic.com/2019/01/09/ransomware-attacks-2019/ https://techtalk.pcmatic.com/2019/01/09/ransomware-attacks-2... I think the date should be December 2019 (not January), judging from the list of incidents by month. One I know of, against Regis University in Colorado, occurred in late August (first reports from August 22). https://www.regisupdates.com/regis-quick-updates/test-post https://www.regisupdates.com/regis-quick-updates/test-post It's mainly a Windows shop. Lots of disruptions for weeks (I teach there part-time, but was not teaching that term). By November(!) things were pretty much back to normal: https://www.regisupdates.com/regis-quick-updates/its-updates-for-saturday-nov-2 https://www.regisupdates.com/regis-quick-updates/its-updates...
- ozim 7y agoHuh that note reads like something generated by this: https://whythefuckwasibreached.com/ https://whythefuckwasibreached.com/
- samsquire 7y agoRemote browser isolation protects against this sort of thing https://en.wikipedia.org/wiki/Browser_isolation https://en.wikipedia.org/wiki/Browser_isolation
- neverhigh 7y agoInteresting to read, the University in Gießen (Germany) is down for weeks with similar issues. https://www.uni-giessen.de/index.html https://www.uni-giessen.de/index.html (engl. Version below). They use Instagram and Facebook to organize 38.000 people and distribute passwords offline https://www.instagram.com/jlu.giessen/?hl=en https://www.instagram.com/jlu.giessen/?hl=en - https://www.denbi.de/news/763-shut-down-of-de-nbi-services-hosted-by-justus-liebig-university-giessen https://www.denbi.de/news/763-shut-down-of-de-nbi-services-h... - https://www.instagram.com/jlu.giessen/?hl=en https://www.instagram.com/jlu.giessen/?hl=en