US companies hit by 'colossal' cyber-attack
1–10 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#2Re: US companies hit by 'colossal' cyber-attack
#3tl;dr tl;dr REvil just pulled off a colossal ransomware supply chain attack” @vxunderground
Thread includes samples.
https://twitter.com/vxunderground/status/1411058433558786049...
Re: US companies hit by 'colossal' cyber-attack
#4If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the ability of a country to respond. There's only so many recovery specialists and IT contractors available to respond in an emergency. Encrypt only a few hundred targets and they can all recover. But if you encrypt a few hundred thousand, then there wouldn't be enough warm bodies available!
Thinking about it, I wonder if these attackers have set up permanent operations, with staff, payroll, and everything. Maybe they just to fly under the radar and collect a nice steady income instead of a risky but potentially huge one-time payoff...
Re: US companies hit by 'colossal' cyber-attack
#5I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
Also, at some point the military gets involved.
Re: US companies hit by 'colossal' cyber-attack
#6I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
Re: US companies hit by 'colossal' cyber-attack
#7I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
Re: US companies hit by 'colossal' cyber-attack
#8I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.
So it's a spectrum
Re: US companies hit by 'colossal' cyber-attack
#9I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
Yeah, I'm guessing they're going for steady income over risking a serious retaliation. If the hack is serious enough, there will be consequences.
Re: US companies hit by 'colossal' cyber-attack
#10“tl;dr REvil popped @KaseyaCorp. Abused Kaseya's auto update to conduct supply chain attack that DLL side loads Windows Defender binaries and ransoms the customer tl;dr tl;dr REvil just pulled off a colossal ransomware supply chain attack” @vxunderground Thread includes samples. https://twitter.com/vxunderground/status/1411058433558786049...