Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

61–70 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#61
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

If there's a zero day, there's not a lot you can do. NHS got hit so bad because they were running very old Windows versions. A lot of embedded systems have no upgrade paths (MRIs running embedded XP should probably not be on the network at all).

Hospitals need full backup machines and with health care costs already through the roof, that will just add more. Even if you have all your order entry machines setup to not make external Internet connections except to update servers, one bad e-mail getting through and you could be in trouble.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#63

Earlier quoted context omitted.

True. The United States is the largest state sponsor of terrorism in the world (School of the Americas, Bay of Pigs, Iranian-Contra, Operation AJAX, COINTELPRO, Operation Mockingbird, United Fruit...)

got anything from the past 50 years?

You gotta wait for it to be declassified. Syria was likely CIA funded. Same with Libya. Just wait a bit. It all comes out after everyone's stopped caring.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#64
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

If there's a zero day, there's not a lot you can do. NHS got hit so bad because they were running very old Windows versions. A lot of embedded systems have no upgrade paths (MRIs running embedded XP should probably not be on the network at all). Hospitals need full backup machines and with health care costs already through the roof, that will just add more. Even if you have all your order entry machines setup to not…

Zero days may get the headlines, but attackers are finding a lot of value in leveraging old vulnerabilities. CISA, FBI and NSA have issued several advisories over the last month highlighting an overarching theme of advanced persistent threat groups targeting unpatched vulnerabilities lately.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#65

Earlier quoted context omitted.

True. The United States is the largest state sponsor of terrorism in the world (School of the Americas, Bay of Pigs, Iranian-Contra, Operation AJAX, COINTELPRO, Operation Mockingbird, United Fruit...)

got anything from the past 50 years?

The entire year of 2020?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#67

Earlier quoted context omitted.

It wouldn't. The smart contract would just wait for payment and the control server would watch for payments. the victim would still have to trust that this process was in place, but for operator can have it completely automated doesn't actually have to be a smart contract, just any address essentially. but a smart contract could allow for many more features, not sure if you'd really want that here

I'm imagining that "keep this value secret until payment is made" could be handled entirely on the blockchain, so that there is no C&C to shut down. But I'm not actually that familiar with the capabilities and limitations of smart contracts.

ah okay, Secrets (formerly Enigma) is a crypto-payments smart-contracts technology to look into for this. Otherwise you run into the problem of everything being stored onchain and visible or there would always have to be some oracle system that has the secret. I'm not sure if Secrets solves this use case, their main thing is storing secrets in the encrypted-key co-processors client side, but they might have other offerings.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#69

Earlier quoted context omitted.

Why hospitals? They have lots of money (same as any big organization) and a very good reason to pay up. It would be far from the first time a hospital was attacked. It wouldn't even by the first time it directly resulted in a death [0]. Unfortunately ransomware operators aren't very ethical. Considering the timing it could also be geopolitical unfortunately, people dying from a ransomware attack could substantially r…

I'm not experiencing any surprise that the hospitals are attacked, I know that happens, I am experiencing surprise at three government agencies hanging out in a chatroom where hackers are credibly discussing attacking a bunch of hospitals with ransomware. My understanding is that the ransomware operators just take a look at computers that are infected, and then negotiate based on who they appear to be.

I get the impression you're taking what you know of attacks against consumers, and just assuming that attacks against large organizations work the same way. They (generally) don't.

With a consumer attack it's get execution on a computer, encrypt some files, and ransom them back. This might earn a few hundred dollars per computer, and isn't worth putting a whole lot of effort into any individual.

At a corporate level it's get some level of access, use that access to get control of a whole lot more access - and also to get control of servers that actually matter instead of users workstations that mostly don't. Maybe try and delete the backups, often exfiltrate a bunch of data, then encrypt things. If you exfiltrated the data the ransom potentially includes not just the offer to decrypt things but also a promise not to distribute the exfiltrated data.

This is all reasonably high touch "work". They've got to figure out how to move laterally inside that specific companies network. They've need to figure out what data is actually important (especially if the goal is to sell it). And so on. Unfortunately it appears to pay well enough to justify the effort. Companies are routinely paying millions of dollars in ransom.

I don't have stats to back this up (internal or otherwise), but my impression is that most successful attacks against enterprise targets are phishing attacks targeting employees to steal credentials.

Post reply on HN