Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

21–30 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#21

That's messed up if true, but why would a ransomware operator target them? I mean like, they don't really target, they just wait for people to install something right?

Ransomware shops don't sit passively by, waiting for someone to install a trojan. Some of them are actually outsourcing the actual penetration, according to Krebs:

https://krebsonsecurity.com/2020/10/amid-an-embarrassment-of...

And once you're doing that, you're going to minimax for hi-value, low-risk targets.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#22
post #12

Earlier quoted context omitted.

Probably for initial infection it’s random but the negotiation for keys happens between real people. Thieves must be heartless to go after such desperate targets. But criminals always have ways of justifying things.

>but the negotiation for keys happens between real people I would be surprised if no one has written a smart contract for this yet - release the keys when X BTC are deposited to address Y.

How would the smart contract be able to validate that the 'keys' it releases are authentic before-hand?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#23
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

My hospital offline for a whole week because they got hit by a ransomware attack, and they use Epic. I asked someone I knew at Epic what she knew about it, and confirmed that my hospital was up-to-date on the latest version of their software and following most of their security protocols. My initial thought was they had weak IT security and now I’m not so sure.

The EMR probably wasn't the vulnerability, but rather the OS, etc. that was running it.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#24
post #12

Earlier quoted context omitted.

Probably for initial infection it’s random but the negotiation for keys happens between real people. Thieves must be heartless to go after such desperate targets. But criminals always have ways of justifying things.

>but the negotiation for keys happens between real people I would be surprised if no one has written a smart contract for this yet - release the keys when X BTC are deposited to address Y.

you can write the contract and always automatically get a cut if you get people to use it, no negotiations, no contracts, no incorporation - the overhead costs to making money have never been lower

people are talking themselves out of how to use cryptocurrency and smart contracts, its like something Plato would write

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#25
post #21

That's messed up if true, but why would a ransomware operator target them? I mean like, they don't really target, they just wait for people to install something right?

Ransomware shops don't sit passively by, waiting for someone to install a trojan. Some of them are actually outsourcing the actual penetration, according to Krebs: https://krebsonsecurity.com/2020/10/amid-an-embarrassment-of... And once you're doing that, you're going to minimax for hi-value, low-risk targets.

Or the leaders of these "shops" have a variety of national politicians as clients.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#26

Earlier quoted context omitted.

>but the negotiation for keys happens between real people I would be surprised if no one has written a smart contract for this yet - release the keys when X BTC are deposited to address Y.

How would the smart contract be able to validate that the 'keys' it releases are authentic before-hand?

It wouldn't.

The smart contract would just wait for payment and the control server would watch for payments. the victim would still have to trust that this process was in place, but for operator can have it completely automated

doesn't actually have to be a smart contract, just any address essentially. but a smart contract could allow for many more features, not sure if you'd really want that here

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#27

Earlier quoted context omitted.

>but the negotiation for keys happens between real people I would be surprised if no one has written a smart contract for this yet - release the keys when X BTC are deposited to address Y.

How would the smart contract be able to validate that the 'keys' it releases are authentic before-hand?

You don't know this when interacting with the human ransomware people either, doesn't seem like a requirement.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#28

Earlier quoted context omitted.

Why the assumption that its terrorist and not a state sanctioned attack?

If we're honest, it's neither. It's 1000% profit-orientated.

Most state sponsored terrorism is profit-oriented

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#30

That's messed up if true, but why would a ransomware operator target them? I mean like, they don't really target, they just wait for people to install something right?

Why hospitals? They have lots of money (same as any big organization) and a very good reason to pay up. It would be far from the first time a hospital was attacked. It wouldn't even by the first time it directly resulted in a death [0]. Unfortunately ransomware operators aren't very ethical.

Considering the timing it could also be geopolitical unfortunately, people dying from a ransomware attack could substantially raise the general tension level in the US.

Lots of high value malware is actually targeted. Things like running phishing campaigns to try and steal credentials from someone inside the institution.

It's substantially less likely, especially if you don't buy the geopolitics angle, but potentially these criminals even have some unpatched vulnerability in a common deployed piece of software, which would allow them to skip the phishing part entirely.

[0] https://www.zdnet.com/article/first-death-reported-following...

Disclaimer: The company I work for is involved in detecting ransomware as a side business.

Post reply on HN