News: 1588705270

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Surprise surprise! Hostile states are hacking coronavirus vaccine research, warn UK and USA intelligence

(2020/05/05)


Foreign state hackers are trying to brute-force their way into pharmaceutical and medical research agencies hunting for a COVID-19 vaccine, British and American infosec agencies are warning.

The National Cyber Security Centre (NCSC) and America’s Cybersecurity and Infrastructure Security Agency (CISA) cautioned of a “password spraying” campaign targeting healthcare and medical research organisations.

Hostile countries are also said to be abusing [1]a specific Citrix vulnerability (CVE-2019-19781) that, if unpatched, permits remote code execution by an unauthenticated user. In addition, they are also abusing vulns in VPNS from Palo Alto Networks, Fortinet and Pulse Secure to snare people working from home.

Paul Chichester, NCSC director of operations, said in a statement: “Protecting the healthcare sector is the NCSC’s first and foremost priority at this time, and we’re working closely with the NHS to keep their systems safe.”

Vietnam alleged to have hacked Chinese organisations in charge of COVID-19 response [2]READ MORE

The [3]joint warning comes hot on the heels of [4]reports from Sunday newspapers that Iran and Russia are targeting British universities in the hope of stealing insights into how to fight the deadly coronavirus pandemic.

Bryan Ware, CISA’s assistant director of cybersecurity, said in another canned statement: “The trusted and continuous cybersecurity collaboration CISA has with NCSC and industry partners plays a critical role in protecting the public and organizations, specifically during this time as healthcare organizations are working at maximum capacity.”

A lightly detailed advisory note [5]published [PDF] by NCSC explained: “The NCSC and CISA are currently investigating a number of incidents in which threat actors are targeting pharmaceutical companies, medical research organisations, and universities…"

"Actors view supply chains as a weak link that they can exploit to obtain access to better-protected targets. Many elements of the supply chains will also have been affected by the shift to remote working and the new vulnerabilities that have resulted.”

NCSC’s Chichester warned that his agency “can’t do this alone,” and called on “healthcare policy makers and researchers” to “take our actionable steps to defend themselves from password spraying campaigns.”

Password spraying differs from common-or-garden brute-forcing by trying a single commonly used password against a list of target accounts. Having done so, attackers then try the next most common password, thereby avoiding rate-limiting or compromise detection software that locks targeted accounts against new login attempts. ®

Sponsored: [6]Choosing A Low-Code Vendor



[1] https://www.theregister.co.uk/2019/12/23/patch_now_published_citrix_applications_leave_network_vulnerable_to_unauthorised_access/

[2] https://www.theregister.co.uk/2020/04/23/vietnamese_hackers_hit_chinese_organisations/

[3] https://www.ncsc.gov.uk/news/warning-issued-uk-usa-healthcare-organisations

[4] https://www.dailymail.co.uk/news/article-8281091/Iran-Russia-launch-hacking-attacks-British-unis-attempt-steal-vaccine-secrets.html

[5] https://www.ncsc.gov.uk/files/Joint%20NCSC%20and%20CISA%20Advisory%20APT%20groups%20target%20healthcare%20and%20essential%20services.pdf

[6] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

Bullshit article based on bullshit press releases.

grizewald

"Hostile countries". What kind of dumb expression is that?

This article is all about attributing motive to unknown actors with zero evidence of the intent of the attacks.

An equally plausible explanation is that the usual actors are taking advantage of the fact the the targeted companies are likely to be "rushed off their feet" busy at the moment and are less likely to notice being penetrated.

Bullshit, bullshit, bullshit.

How about some analysis of your own Gareth instead of just recycling dodgy press releases like most lazy print hacks?

Re: Bullshit article based on bullshit press releases.

foo_bar_baz

Is it not news that said agencies have released said press releases?

You’re right that the linked source has no mention of state actors, so that looks like a bit of embellishment. Good catch.

Re: Bullshit article based on bullshit press releases.

Paratrooping Parrot

Citing the Daily Mail and the US government as your source is a bit rubbish. Remember this is the same US government that loves spreading false rumours.

APT groups mentioned in the NCSC release.

Anonymous Coward

These are state actors, or at least affiliated?

To be fair, what else has El Reg to report on this? Do you want journalism, or commentary?

Any rogue state locked out of the global share could be motivated to get the info. Equally, it could be opportunistic hackers looking for information for the unscrupulous equities traders willing to pay.

Barrie Shepherd

So will the NHS centralised Track & Tracing APP will be secure from snoopers? /s

Maybe that's why Sirco will be doing the track and tracing so that when the data from the APP is leaked it will not be the Governments fault? /s

Andy1

What possible reason would there be to hack into this research, isn't it supposed to be shared between nations. Or is it to wreck the computer system the data is held on or possibly a ransomware attack. Come on journos try and find out why it's really happening.

Anonymous Coward

I thought Iran had a reasonably effective covid-19 treatment already, using sofosbuvir (possibly together with daclatasvir).

We're talking medical research, not nuclear launch codes.

vtcodger

I'm trying to think of a reason for not simply giving legitimate Russian, Iranian, Icelandic, Fenwickian etc. representatives user accounts that let them view any and all research info on Coronavirus. Can't come up with much.

Heck, why not just publish the information on Wikipedia?

Re: We're talking medical research, not nuclear launch codes.

Chewi

I'm glad I'm not the only one thinking this. I was really angry when I saw this reported in the mainstream media. They're taking the totally wrong angle. Sure, they have cause to be concerned if the intent is malicious damage but that seems highly unlikely. The official warning talked about potential theft of "intellectual property" and that makes me sick. Placing more concern over that than the welfare of humanity makes them no better than Trump trying to score that exclusive vaccine deal.

"Hey! Who took the cork off my lunch??!"
-- W. C. Fields