Maze ransomware gang threatens to publish sensitive stolen data after US aerospace biz sensibly refuses to pay
- Reference: 1593001807
- News link: https://www.theregister.co.uk/2020/06/24/maze_ransomware_gang_vt_aerospace_rant/
- Source link:
In a "press release" published on its leaks website, Maze raged against victims who refused to play its game and cough up vast sums of money to decrypt their illicitly encrypted data.
Among those [1]recent targets was VT San Antonio Aerospace, a maintenance, repair and overhaul (MRO) company in Texas. A subsidiary of ST Engineering, VT San Antonio was said to have lost 1.5TB of data to the Maze criminals. Its MRO customers include Air Canada, Fedex and UPS Airlines.
Earlier this week the Maze gang highlighted ST Engineering for not paying the ransom, a sensible action that busts the gang's business model.
'Work pressure' sees Maze ransomware gang demand payoff from wrong company [2]READ MORE
In its post the gang complained that ST Engineering's ransom negotiator "lied" before declining to take part in "further negotiation" with them, promising: "Soon it will be the time for weapon contacts, contracts for alteration of airplanes for first persons, contracts with dictatorship countries, contacts for cybersecurity systems for government structures. We just can't understand what cybersecurity they are talking about as they have an Australia size security hole in their security perimeter."
Ed Onwe, veep and general manager of VT San Antonio Aerospace, told The Register that local authorities had been informed of the ransomware attack as the firm figured out how to respond to the initial infection, adding: "As part of this process, we are conducting a rigorous review of the incident and our systems to ensure that the data we are entrusted with remains safe and secure. This includes deploying advanced tools to remediate the intrusion and to restore systems.
"We are committed to responding to this incident transparently and proactively, and already have begun notifying potentially affected customers. We will be working with our customers and industry peers to share insights and any lessons learned so that they can learn from our experience."
The Maze gang has stepped up its public-facing activities in recent weeks, not without cost to itself. Last week it sent a ransom demand to the wrong company, [3]having mixed up two firms' names . It has also targeted [4]Posh Spice's perfumers and other celebrity lawyers, about whom El Reg will be writing more soon. Its tactics include leaking selected files publicly to apply further pressure to victims, in the hope they pay the demanded ransom, as well as – it now seems – ranting away when they refuse to play the game.
Current British government advice is never to pay a ransomware demand: it not only encourages and enriches the crooks but there's no guarantee that they'll delete your data as they promise. ®
Sponsored: [5]Modernizing Your .NET Application for Google Cloud Platform
[1] https://www.flightglobal.com/aerospace/ransomware-attack-hits-st-engineerings-usa-aerospace-unit/138722.article
[2] https://www.theregister.com/2020/06/18/maze_ransomware_gang_name_screwup/
[3] https://www.theregister.com/2020/06/18/maze_ransomware_gang_name_screwup/
[4] https://www.theregister.com/2020/06/12/posh_spice_threadstone_advisors_ransomware_maze/
[5] https://go.theregister.com/tl/1956/-8473/modernizing-your-net-application-for-google-cloud-platform?td=wptl1956
An sensible response, indeed
That's exactly the way to put these crooks out of business.
Paying ransom makes the problem worse for everyone.
Re: An sensible response, indeed
That's exactly the way to put these crooks out of business.
Personally I'd prefer to see a SEAL or SAS team do it. Sends a much better message.
Re: An sensible response, indeed
Agree, however, determining physical locations is very hard in most instances of an electronic attack.
And even if you succeed, SEALs blowing up a coworking space in downtown SF or SAS in an east London neighborhood might not be seen as an adequate reaction by some ...
Re: An sensible response, indeed
If this keeps up they'll upset somebody who might do just that.
Remind me again.....
....how this works:
1. Bad guys penetrate a target network and steal data.
2. Then bad guys encrypt data on the target network.
3. Then bad guys demand a ransom...they will UN-ENCRYPT the network in exchange for money.
4. Once the money is paid, they will destroy the stolen data.
*
In this case, refusal to pay has resulted in bad guys having a conniption.
*
About item #1, do the target folk actually know how the breach was accomplished?
About item #2, do the target folk have recent backups?
About item #3, once the money is paid, will the bad guys actually un-encrypt?
About item #4, these are bad guys...will they actually destroy the data?
*
And then there's item #5.....Are the bad guys STILL IN THERE (with enough permissions to repeat item #2)?
*
And finally.....I'm trusting LOTS of people with my PII......how common is this disaster? Is this the only time this has happened this week....or are there thousands of unreported breaches going on all the time?
*
I think we should be told!
Maze raged against victims who refused to play its game
This sort of entitled idiocy by crooks amazes me. I got the same thing when I played along with "Microsoft" who had phoned me up to tell me they'd detected a virus on my computer in a thick Indian accent. After about half an hour I got bored and pointed out that I don't actually have any Windows boxes in the house, at which point they complained vehemently about me wasting their time.
Re: Maze raged against victims who refused to play its game
"they complained vehemently about me wasting their time"
Yes, that's when it gets really funny - "Me? Wasting your time?". My record is just under the hour to keep them on the hook, getting passed up the chain to senior crooks on the journey. They now mostly know how to check if I'm using a Mac, and there is a halfhearted attempt to get me to download the Mac version of TeamViewer, which I can rebuff for at least 15 minutes then tey give up. But they get really pissed when I repeatedly tell them I really have a Windows key, which I do on my Thinkpad P50, but that it does nothing - mostly because I'm running Kubuntu and don't map that key to anything. Twice I've been told I was the bad person and they will shutdown my internet.
Re: Maze raged against victims who refused to play its game
I just tell them that I pressed the windows key and the computer switched off. They have to wait 'while it boots again' and I can play a couple of hard sudoko while thanking them for their diligence in helping me.
Re: Maze raged against victims who refused to play its game
They're just trying to make a dishonest living here. You don't have to go and mess them about over it.
Re: Maze raged against victims who refused to play its game
"at which point they complained vehemently about me wasting their time". That's the money shot for me. Its worth Shielding just to have the time to reach that phrase or similar.
And in the Other Corner we have ..........
In its post the gang complained that ST Engineering's ransom negotiator "lied" before declining to take part in "further negotiation" with them, promising: ...
The suspicion there then is the ST Engineering's ransom negotiator is in the pay/pocket of others with an altogether different agenda?
Current British government advice is never to pay a ransomware demand: it not only encourages and enriches the crooks but there's no guarantee that they'll delete your data as they promise.
:-) That's rich ..... coming as it does from an operation that thinks to extract taxes from every Tom, Dick and Harriett and their employers to enrich themselves with a presumed immunity and impunity from investigation and prosecution/persecution.
And when one can't or won't pay, praise be for the Magic Money Tree and the Quantitative Easing Slug Drug ...... A Bottomless Pit of Phantom Paper Help Billed to the Future for Something/Someone Else to Pick Up the Tab and Pay with More of the Same Sort of Mega Meta Data Base Bull Shit?
However, not a particularly bright plan that one, whenever it relies so heavily on ignorant schmucks always playing such a dumb game ...... whenever greater intelligence today is virtually free and available practically everywhere for a more enlightened race/more enlightened races on Earth, highlighting the perversion and catastrophic systemic vulnerability being exhaustively exploited, abused and misused.
Re: And in the Other Corner we have ..........
Throw a few references to Brexit and the handling of COVID-19 and you got yourself big old Daily Fail NIMBY style rant going there my friend!
Keep talking bar stewards, it improves the chances of finding you.
No one likes ransomware criminals, but this article seems weirdly schoolchildish. They mixed up two companies' names? Ooooh!
Where's the critique of bad company security?