Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

201–210 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#201
post #127

Earlier quoted context omitted.

There have been ransomware attacks that are covers for outright attacks, iirc some where the payment and decryption mechanism didn't even function. On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. But it seems a lot of the big gangs are suspected state-sponsored, which is less terrorism and more cyber warfare

If it's a fake ransomware then yeah that's probably terrorism. If it's fake it's obviously not done for profit. I'm referring to actual ransomware that works, that's done for profit. > On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. I'm not sure how well that would work. Ransomware generally has responsive and helpful support people, because without that it…

> I'm referring to actual ransomware that works, that's done for profit.

From what I have recently learned, this may no longer be accurate. The latest Risky Business happens to touch upon the subject.

Criminal groups in Russia have financial arrangements with the central government, and may occasionally do some freelancing for them. Now China is getting on the same boat, but apparently with less entrepreneurial approach to target selection.

If they are the only ones, I would be very much surprised. The net result is that ideological and for-profit motives will be harder to distinguish, as the same crew may well be doing different campaigns for different reasons at any given time.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#202

Earlier quoted context omitted.

In general, regulated entities are required to regularly prove that their change-management processes are sufficiently heavy as to make regular patching a non-starter.

This. A million times. Regulation isn't the solution to this industry's woes -- it's the cause.

I am pretty sure patients outcomes would be much better with no regulation at all.

Be careful what you wish for. Many regulations have been written in blood.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#203

Earlier quoted context omitted.

The fear of losing money is a real one. On the other hand, I believe that the word terrorism and the characterization of acts as terrorists should not be taken too lightly as it can lead to misuse of power rather quickly.

I wouldn't want to use the word lightly either, but if Russia is trying to destabilize our economy, for their own political gain, and they inadvertently threaten or kill many people in the process (by shutting down hospital information systems)... that is the textbook definition of terrorism.

When it's done by a nation-state, we used to call that "war".

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#204
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

Maybe the US should also invest some of their military money to solve the situation of insecure hospital IT. You need defense, you won't win it with offense. There'll always be another bad actor out there.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#205
Consider a hospital like a person's body.

If you don't nurture a wound, you'll get an infection. If you don't clean your hands before eating or you eat something foul, you get diarrhea. The outside world is a dangerous place, and if you wish to interact with it, you should have your defences in order and take necessary precautions. And then still bad actors will get through, such as the yearly flu, so you must deal with that as well.

You won't defeat the outside world with offense, there's just too much out there, adapting too fast.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#206
This is truly appalling per se, even more so during a global pandemic.

If I can be of any help to stop this, disrupt these guys or whatever I'm ready to give a few of my days and nights to it. Contact email in my about.

I'm a professional developper with a dormant interest in ethical hacking. Been following EH courses, done some CTFs ranging from basic web pen testing to crypto and assembly debugging and been reading/watching keenly everything I saw on cyber-security in the past 5-6 years.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#207

Earlier quoted context omitted.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

Usually the goal is political change through fear. Fear doesn't really make sense as an end in and of itself

Fear is a good tool to keep people under control though...

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#208

Earlier quoted context omitted.

I think it's an interesting comment and see no reason America deserves some special shield from criticism, trope or not. It should be responded to on its own merit, just like anyone sharing any other opinion on HN.

I thought it was interesting too. It didn’t seem inflammatory or political flamewar. Sometimes I miss the days when such conversation was permitted. I’d vouch it, but I like my vouch privileges too much to risk it.

It's not interesting. Every major thread on HN has at least one comment trying to force the America Bad angle into the conservation regardless of whether the discussion is about the US.

If the primary conversation - derived from the linked article - is about the US and about a topic having to do with something negative about the US, then it's both interesting (as the root source) and makes reasonable sense that it should be in the thread.

Otherwise it's nothing more than a political agenda - someone being triggered and unable to control theirself - being force-wedged into a conversation where it doesn't belong and it degrades the quality of HN dramatically. As it would if the same treatment were applied to any other nation.

Imagine if every large thread had someone trying to force comments about all the bad things France or Britain have done. Every single major thread. Now apply it to dozens of nations. Of course that wouldn't be allowed because it would be insane. It's insane to allow it for the US just the same.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#209

Earlier quoted context omitted.

Wasn't there a ransomware case in Germany recently where when they advised the hackers that they'd hit a hospital, the hackers immediately turned over the unlock keys, without a ransom? Not that that is any way a defense, and I'm sure there was as much a self-interested motivation of "We are going to be hit hard if we ransom a hospital _now_" as much as "doing the right thing"...

At a certain point a “hack” becomes an “attack” and the response moves from “police action” to “military response” and I’m guessing that only state actor or sponsored groups are willing to cross that line.

Such responses happened in the past, sometimes with some added sarcasm https://twitter.com/idf/status/1125066395010699264

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#210
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.

Most of current best practices for backups, redundancy and business continuity are intended for the risks of random disasters. Malicious attacks are substantially different.

There are many organizations which are doing regular secure backups, but are doing so in a way that can be sabotaged once a skilled attacker gains domain admin privileges, and sabotaging backups is one of key things that the attackers are doing after they are in the network and before triggering the ransom encryption. We're not talking about a virus randomly spreading, in such high-ransom targeted attacks the preparation before triggering a ransom is done manually by skilled teams going on from one target to another.

Post reply on HN