I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
It's not enough to just gain access - once you're in you need to compromise other defenses, you need to communicate your demand to the victim, you need to know how much to extort, you need to actually process the payment. Either you do this on a case by case basis or you take advantage of additional exploits that will only be viable for a subset of your potential targets, and this is all a race against time before so…
US companies hit by 'colossal' cyber-attack
81–90 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#82https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom...
When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.
Re: US companies hit by 'colossal' cyber-attack
#83Or at least that's where we're headed if companies keep giving in to the ransom demands.
Re: US companies hit by 'colossal' cyber-attack
#84I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.
Without crypto, would it be impossible to extract cash from a company? What is the current mechanism used to get funds that the FBI can’t track down? Wire the money to a jurisdiction mostly out of our sphere of influence.
One way is to demand that a smaller amount of money be wired to 1,000 accounts throughout the world.
You — the bad guy - own merely one of them.
Difficult to trace them all before you empty your particular account.
Re: US companies hit by 'colossal' cyber-attack
#85Re: US companies hit by 'colossal' cyber-attack
#86The Microsoft team at a company I used to work for tried to push this very software out onto all staff machines. Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor. The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly…
What software are you referring to? The article only mentions "VSA tool", and that does not ddg well.
Re: US companies hit by 'colossal' cyber-attack
#87Earlier quoted context omitted.
I think that the problem is these companies are publicly-traded. Chasing YoY returns and never having a down quarter are antithetical to building a lasting security model.
Microsoft, Apple, and Google seem to be doing ok.
Re: US companies hit by 'colossal' cyber-attack
#88I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
No worries though, the ransom from this round should serve nicely as a Series B round of financing & enable rapid scaling of the post-hack ransom extraction process.
Re: US companies hit by 'colossal' cyber-attack
#89I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…
Re: US companies hit by 'colossal' cyber-attack
#90Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
It's been wallpapered over as just cutting unnecessary expense for too long.