Clop ransomware gang leaks online what looks like stolen Bombardier blueprints of GlobalEye radar snoop jet
- Reference: 1614115322
- News link: https://www.theregister.co.uk/2021/02/23/bombardier_clop_ransomware_leaks/
- Source link:
Over on their Tor hidden service, the cyber-extortionists published what they said were screenshots of blueprints swiped from Bombardier as evidence of their crimes. The gang abused the same vulnerability in file-transfer software from Accellion that was [1]exploited earlier this year to nab documents from Trump's lawyers.
[2]
Bombardier confirmed its security had been breached, putting out a public statement only minutes after The Register grilled the Canadian business jet maker on the Clop gang's claims. “An initial investigation revealed that an unauthorized party accessed and extracted data by exploiting a vulnerability affecting a third-party file-transfer application, which was running on purpose-built servers isolated from the main Bombardier IT network,” the biz said.
Bombardier added it is working with “cybersecurity and forensic professionals,” and insisted it “was not specifically targeted — the vulnerability impacted multiple organizations using the application.” A spokeswoman confirmed the breach came about thanks to a hole in an Accellion file-transfer product.
[3]
Thus, Bombardier was among various corporations using Accellion's vulnerable file-transfer software, which were [4]exploited to pilfer documents. A flaw in the application was revealed in December, and it [5]appears criminals were quick to make hay before the world got round to patching their deployments.
Around 130 Bombardier employees in Costa Rica were “impacted” by the hack, we're told, suggesting their personal information was obtained or otherwise accessed by miscreants.
Radar antenna and military jet
Pictures dumped online by Clop, and seen by The Register , showed a CAD rendering of a Bombardier GlobalEye aircraft, a Global 6000 business jet converted to carry a distinctive Saab Erieye plank-style radar mounted on top of its fuselage. A second picture showed a detailed 3D view of what appeared to be a radar head complete with its mounting.
Scottish enviro bods shrug off ransomware gang's extortion attempt as 4,000 files dumped online, saying it's nothing big [6]READ MORE
The screenshots also showed an email seemingly sent by an employee of Marshall Aerospace of Cambridge, UK, which has previously worked on military conversions of Global 6000s for various countries.
Experts, almost all of whom spoke to us on condition of anonymity because they were not authorized to speak publicly, drew different conclusions about the radar equipment in the picture leaked by Clop.
One, with extensive professional experience of airborne radars, suggested the hardware was a passive array antenna with beam-forming wave guides mounted behind it. Another suggested it was consistent with mechanically scanning radar heads mounted in aircraft, saying: “My first thought upon seeing it was that it reminded me of the old 1970s and 1980s vintage radar arrays in the F-15 Eagles.”
A third said: “I think I know; if so, it’s no comment, I’m afraid”.
Philip Ingram, a former British intelligence officer and now a security commentator, told The Register : “The aircraft looks like the GlobalEye,” adding: “It could be a Synthetic Aperture Radar image but neither picture would be sensitive in the detail – they look like they could be out of sales or pre-sales literature.”
The Global 6000 airframe used for the GlobalEye also forms the basis of the British Royal Air Force’s Sentinel airborne early-warning aircraft. In the orientation shown in the CAD image, the radar antennas could be the ones mounted in the Sentinel’s long ventral radome, pictures of which can be [7]seen in this Royal Aeronautical Society feature about the aircraft.
It’s more likely that the actor responsible for the file-transfer application hacks has delegated the extortion to Clop
Clop has made a habit of targeting high-profile companies for its ransomware extortion activities, which consist of infiltrating a businesses' networks, exfiltrating and encrypting files, and then demanding payment to not only decrypt and restore the scrambled data but also to not publicly release the sensitive purloined materials.
Brett Callow of infosec firm Emsisoft told The Register that while Clop is bragging about the intrusion, it may not have been the ransomware gang itself that broke into the corporations.
“It’s more likely that the actor responsible for the file-transfer application (FTA) hacks has delegated the extortion to Clop, as they have the necessary infrastructure and expertise,” he said. “Other organizations which have disclosed FTA breaches include the [8]Reserve Bank of New Zealand , the [9]Australian Securities and Investments Commission , and Colorado University – and it’s not at all unlikely that Clop has those organizations’ data, too.”
[10]
Clop also last year [11]hit Software AG. What’s the lesson here? Patch your IT estate promptly and watch out for third-party suppliers. ®
Get our [12]Tech Resources
[1] https://www.theregister.com/2021/02/22/in_brief_security/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDWJCsL3aHz9xh-0JnODcQAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDWJCsL3aHz9xh-0JnODcQAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.globenewswire.com/news-release/2021/02/22/2179666/0/en/Accellion-Provides-Update-to-FTA-Security-Incident-Following-Mandiant-s-Preliminary-Findings.html
[5] https://www.theregister.com/2021/01/25/asic_accellion_breach/
[6] https://www.theregister.com/2021/01/22/sepa_ransomware_failure/
[7] https://www.aerosociety.com/news/sentinel-reloaded/
[8] https://www.rbnz.govt.nz/news/2021/01/reserve-bank-response-to-illegal-breach-of-data-system
[9] https://www.theregister.com/2021/01/25/asic_accellion_breach/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDWJCsL3aHz9xh-0JnODcQAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2020/10/09/software_ag_ransomware/
[12] https://whitepapers.theregister.com/
Price and worth are easily confused by some people. sftp, scp and the like are free, therefore worthless. Much better to use something paid for.
Not the voice of experience speaking...
Whilst I haven't worked with Accellion itself there are plenty of other similar file transfer/workflow type packages out there.
Why not SFTP you cry? Well for one thing, these platforms tend to offer lots of features that companies find genuinely useful without having to roll their own and usually support various different transfer/authentication options *including* SFTP, IP address whitelisting etc.
Maybe you want to push files to a remote server, perhaps you wish to be able to see the time and date that a client logged in to pull their files. Perhaps the recipient requests that certain files be retransmitted because they had a processing issue on their side.
None of the above is hideously complex, but it is non-trivial if you want it to work well and not have an interface that stinks.
What on Earth is an Accellion and why would anyone use it or pay for it when there’s SFTP? Just asking for trouble.