Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

1–10 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#3
“tl;dr REvil popped @KaseyaCorp. Abused Kaseya's auto update to conduct supply chain attack that DLL side loads Windows Defender binaries and ransoms the customer

tl;dr tl;dr REvil just pulled off a colossal ransomware supply chain attack” @vxunderground

Thread includes samples.

https://twitter.com/vxunderground/status/1411058433558786049...

Re: US companies hit by 'colossal' cyber-attack

#4
I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more!

If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the ability of a country to respond. There's only so many recovery specialists and IT contractors available to respond in an emergency. Encrypt only a few hundred targets and they can all recover. But if you encrypt a few hundred thousand, then there wouldn't be enough warm bodies available!

Thinking about it, I wonder if these attackers have set up permanent operations, with staff, payroll, and everything. Maybe they just to fly under the radar and collect a nice steady income instead of a risky but potentially huge one-time payoff...

Re: US companies hit by 'colossal' cyber-attack

#5

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

You'd need to be able to process all the orders also. Every company needs support to pay the random and unlock.

Also, at some point the military gets involved.

Re: US companies hit by 'colossal' cyber-attack

#6

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.

Re: US companies hit by 'colossal' cyber-attack

#7

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

DarkSide's business model was to professionalize ransomware attacks with a dedicated professional services IT model, finance, and helpdesk support.

Re: US companies hit by 'colossal' cyber-attack

#8

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.

FWIW though (and I don't have easily available "sources") there was this immediate retaliation where Biden was like "we will completely prosecute these offenders" and within days DarkSide PR department said "Hey sorry we didn't mean to disrupt core services, we just want money" (sic)

So it's a spectrum

Re: US companies hit by 'colossal' cyber-attack

#9

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.

[deleted]

Re: US companies hit by 'colossal' cyber-attack

#10

“tl;dr REvil popped @KaseyaCorp. Abused Kaseya's auto update to conduct supply chain attack that DLL side loads Windows Defender binaries and ransoms the customer tl;dr tl;dr REvil just pulled off a colossal ransomware supply chain attack” @vxunderground Thread includes samples. https://twitter.com/vxunderground/status/1411058433558786049...

Samples at that link, for anyone curious.
Post reply on HN