Live data from Hacker News

Garmin received decryptor for WastedLocker ransomware

bleepingcomputer.com

1–10 of 27 posts

Re: Garmin received decryptor for WastedLocker ransomware

#4
post #3

Is Evil Corp their actual name, or just what the US law enforcement called them? https://home.treasury.gov/news/press-releases/sm845

It looks like that's just the name of a group - like anonymous, lulzsec, equation, shadow brokers, etc.

It's likely a nod to Mr. Robot, where the company that the hackers are infiltrating is called Evil Corp.

Re: Garmin received decryptor for WastedLocker ransomware

#6
To me the fascinating part is that with the ransom payment they received the decrypt key as well as the security system patches needed to protect the system. However I would be very nervous that the hacker didn’t leave something behind but perhaps they would rather a good reputation and not risk losing payment for the next attack.

Re: Garmin received decryptor for WastedLocker ransomware

#7

I bet they’ll start investing in backup solutions right about now.

I recall a story here on HN, some days ago. A company was attacked, then the attackers waited some months to make sure that all backups had been contaminated, then they struck.

So victims can only make sure that they have a malware checker that finds the culprit, then do fresh installs, then check each file before it's restored from backup. Sounds like a crazy amount of work.

Re: Garmin received decryptor for WastedLocker ransomware

#8
post #6

To me the fascinating part is that with the ransom payment they received the decrypt key as well as the security system patches needed to protect the system. However I would be very nervous that the hacker didn’t leave something behind but perhaps they would rather a good reputation and not risk losing payment for the next attack.

Given the references the author found to apparently reputable ransomware recovery firms, my reading is that the decryptor was built by one of those companies using the key provided by the intruder.

Re: Garmin received decryptor for WastedLocker ransomware

#9
post #7

I bet they’ll start investing in backup solutions right about now.

I recall a story here on HN, some days ago. A company was attacked, then the attackers waited some months to make sure that all backups had been contaminated, then they struck. So victims can only make sure that they have a malware checker that finds the culprit, then do fresh installs, then check each file before it's restored from backup. Sounds like a crazy amount of work.

Immutable append-only backups would protect against this, right? Nuke the OS to make sure you're running on good software, then pull in data that's as good as it was when it was backed up.

Re: Garmin received decryptor for WastedLocker ransomware

#10
post #7

Earlier quoted context omitted.

I recall a story here on HN, some days ago. A company was attacked, then the attackers waited some months to make sure that all backups had been contaminated, then they struck. So victims can only make sure that they have a malware checker that finds the culprit, then do fresh installs, then check each file before it's restored from backup. Sounds like a crazy amount of work.

Immutable append-only backups would protect against this, right? Nuke the OS to make sure you're running on good software, then pull in data that's as good as it was when it was backed up.

Only to the degree that attackers can't figure out a way around them (given months of planning with access to internal systems & documentation).

For instance: I have backups going to an append-only s3 bucket in a separate AWS account, but I don't have monitoring in place to ensure that bucket hasn't been wiped. An email would get generated, but it'd go to the root account holder, who may not notice in time.

Post reply on HN