News: 1602265209

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Software AG hit with ransomware: Crooks leak staffers' passports, want millions for stolen files

(2020/10/09)


Software AG has seemingly been hit by ransomware, with the German IT giant itself telling the country's stock market it had been “affected by a malware attack.”

In a [1]notification to the German stock market published earlier this week Software AG said: “The IT infrastructure of Software AG is affected by a malware attack since the evening of 3 October 2020.”

News of the “malware attack” has been slow to filter into the Anglosphere, though the German Press Agency newswire published a brief note that was syndicated on obscure investment websites [2]yesterday evening .

That report also says “data from Software AG servers and employees' notebooks were downloaded.”

"While services to its customers, including its cloud-based services, remain unaffected, as a result, Software AG has shut down the internal systems in a controlled manner in accordance with the company's internal security regulations," the firm’s note to the stock market continued.

"The company is in the process of restoring its systems and data in order to resume orderly operation. However, helpdesk services and internal communication at Software AG are currently still being affected."

It added: “Software AG is not aware of any customer information being accessed by the malware attack.”

The Register has asked Software AG for comment. At the time of writing the company’s homepage refers visitors to “important customer information,” but only ‘fesses up to “technical issues with our online support system,” albeit with a link to the stock market note.

At least one customer seemed unaware of what was going on:

[3]@SoftwareAG Is there an issue with your documentation website? I have been unable to access it for a few days, the response is 'connection timed out' — Graham Rainbow (@zippygwr) [4]October 9, 2020

Screenshots of the attackers’ ransom webpage seen by El Reg show scans of staffers’ passports, internal billing notes and what appears to be internal directories on a Windows-based system. Folder names suggest the contents could relate to Software AG customers in the US and Canada.

Brett Callow, a threat analyst with ransomware specialist firm Emsisoft, told The Register that the Clop ransomware variant, thought to have been used in this attack, is relatively new.

Doppelpaymer ransomware crew fingered for attack on German hospital that caused death of a patient [5]READ MORE

"Clop is a variant of CryptoMix and may be used by the group behind the Dridex banking trojan. Like REvil and NetWalker, it is primarily used to target enterprise networks, with known past victims including Prominent and ExecuPharm. Clop’s demands can run to the millions.”

Speaking in general about the murky world of ransomware, Callow added: “In 2018, the average ransom demand was $5k USD with most victims being small businesses. Today, the average demand is somewhere between $150k and $250k, with multi-million dollar demands increasingly the norm and victims including multinationals. governments and hospitals. As a result, the criminals are better resourced and more motivated than ever.”

Echoing an increasingly common demand, he concluded: “As we’ve said before, the only way to stop this escalation and to put a spoke in the wheel of this multi-billion industry, is to prohibit the payment of demands. If the revenue stream dries up, the attacks will dry up.”

We understand the ransom demand against Software AG runs into millions of dollars and will update this article if the company gives any more details. ®

Get our [6]Tech Resources



[1] http://otp.investis.com/generic/dgap-story.aspx?cid=2167&newsid=13974&culture=en-US

[2] https://translate.google.com/translate?sl=auto&tl=en&u=https%3A%2F%2Fwww.4investors.de%2Fnachrichten%2Fboerse.php%3Fsektion%3Dstock%26ID%3D146616

[3] https://twitter.com/SoftwareAG?ref_src=twsrc%5Etfw

[4] https://twitter.com/zippygwr/status/1314531947423694849?ref_src=twsrc%5Etfw

[5] https://www.theregister.com/2020/09/23/doppelpaymer_german_hospital_ransomware/

[6] https://whitepapers.theregister.com/

Ransomware

RM Myers

I agree with the guy from Emsisoft. The law needs to be changed to (1) limit insurance to covering the cost of business interruption and system recovery, and specifically make it illegal to cover ransom, and (2) treat paying a ransom similar to paying a bribe, that is, make it illegal with criminal penalties and don't treat the payment as an expense for tax purposes.

This will obviously be difficult given the number of countries involved, but it is the only way to prevent ransonware from becoming ever more common.

Re: Ransomware

MiguelC

Paying a ransom could be construed as aiding and abetting, as it translates effectively to paying for criminal activity

Re: Ransomware

Anonymous Coward

Unlikely. As its being made under duress. Only a twisted legal system like the US's generally goes after the victim.

Re: Ransomware

Anonymous Coward

Disagree. Its not worth getting your knickers in a twist about. Its just this years ThreatThing. Something new will be along to replace it soon enough.

There are only so many groups clever enough to do this thing. It takes weeks of surveillance and picking and choosing your targets and vulnerabilities.

At work, the authority of a person is inversely proportional to the
number of pens that person is carrying.