News: 1614790806

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Qualys hit with ransomware: Customer invoices leaked on extortionists' Tor blog

(2021/03/03)


Infosec outfit Qualys, its cloud-based vuln detection tech, and its SSL server test webpage, have seemingly fallen victim to a ransomware attack.

Files appearing to originate from Qualys were dumped online this afternoon on the Tor blog of the Clop criminal extortionists.

[1]

While Qualys declined to comment immediately, a spokeswoman said the company was aware of the incident and investigating.

While we’re not reproducing those files here because doing so merely fuels the extortionists’ purpose, they appeared to include purchase orders, results of scans of customer appliances and quotations. The nature of the files suggests they were stolen from the admin side of the Qualys business rather than its infosec side.

[2]

Ransomware gang specialist Brett Callow, of infosec biz Emsisoft, told The Register : “Entities that have had dealings with Qualys should be on high alert.”

The incident will be hugely embarrassing for Qualys. At the time of writing the precise attack vector was unknown, though Clop has spent the past few months focused on extorting users of Accellion file transfer appliances. In 2016 Qualys itself published research ( [3]PDF ) into vulns in Accellion devices, though that is no indicator of whether or not the appliances were in use by Qualys itself for their intended purpose.

[4]Revealed: The military radar system swiped from aerospace biz, leaked online by Clop ransomware gang

[5]Clop ransomware gang leaks online what looks like stolen Bombardier blueprints of GlobalEye radar snoop jet

[6]Digital burglars break into the Australian Securities and Investments Commission

Jake Moore, security specialist at ESET, opined: “Malicious actors have somewhat matured and now use full-blown extortion tactics to make sure they get what they came for. Going further than simply encrypting data seems so ‘old hat’ now when exfiltrating and selling the data seems that much more lucrative.”

Recent victims of Clop’s Accellion-focused extortion spree [7]include Canadian aerospace firm Bombardier , in the process exposing details of [8]a military-grade radar supplied to various air forces around the world. Others targeted by steal’n’ransom criminals include [9]London ad agency The7stars , German firm [10]Software AG and others.

US infosec behemoth FireEye has [11]theorised that Clop has been acting as a reseller for a second criminal operation which carried out the actual thefts from Accellion appliances during December and January.

Yesterday Accellion published a report from FireEye’s Mandiant breach response tentacle ( [12]PDF ), which said: “Both the December Exploit and the January Exploit demonstrate a high level of sophistication and deep familiarity with the inner workings of the Accellion FTA software, likely obtained through extensive reverse engineering of the software.”

Emsisoft’s Callow added that the US CISA infosec agency had hinted that the ransomware criminals were making a profit from their extortionist endeavours, pointing to a line in a [13]recent CISA advisory that hinted some victims had paid up to prevent embarrassment or worse.

[14]

“In 2020, Clop et el posted data stolen from more than 1,300 companies – including contractors in the military industrial space – while many other organizations will have paid to prevent it being published,” said Callow. “And, of course, as not all groups were stealing data at the start of 2020, we can look forward to even more cases this year.” ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YEAVDIiEPCBNwZkgrBhZJQAAAJE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YEAVDIiEPCBNwZkgrBhZJQAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[3] https://www.qualys.com/2016/12/06/qsa-2016-12-06/qsa-2016-12-06.pdf

[4] https://www.theregister.com/2021/02/24/seaspray_radar_ransomware/

[5] https://www.theregister.com/2021/02/23/bombardier_clop_ransomware_leaks/

[6] https://www.theregister.com/2021/01/25/asic_accellion_breach/

[7] https://www.theregister.com/2021/02/23/bombardier_clop_ransomware_leaks/

[8] https://www.theregister.com/2021/02/24/seaspray_radar_ransomware/

[9] https://www.theregister.com/2021/01/22/the7stars_ransomware_attack_clop/

[10] https://www.theregister.com/2020/10/09/software_ag_ransomware/

[11] https://www.theregister.com/2021/02/24/seaspray_radar_ransomware/

[12] https://www.accellion.com/sites/default/files/trust-center/accellion-fta-attack-mandiant-report-full.pdf

[13] https://us-cert.cisa.gov/ncas/alerts/aa21-055a

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YEAVDIiEPCBNwZkgrBhZJQAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/

Man, that's a bummer

Anonymous Coward

If only Qualys had some sort of vulnerability reporting tool which would help them identify potential weaknesses in their IT infrastructure. I suppose kicking them on that point is a little too easy. If only Qualys provided more accessible hooks into other tools so that the Qualys scan reports could be directly converted into action rather than being fed into incomprehensible spreadsheets which must then be deciphered by hapless operations teams.

Muppet Boss

Clop means a bedbug in Russian. Coincidence I think not, rather I think they humbly define their place in a food chain as parasitic pests. If so, spot on.

So, Qualys

tfb

is the company that [1]thinks its scanner should have unrestricted root access to the systems it scans . So, you know, it can check them for vulnerabilities, including, in due course if not already, a 'vulnerability' invented by some bad actor who has got control of Qualys, the 'checking' for which will conveniently cause a compromise on the systems being checked. On all the systems being checked, everywhere. Which is probably every *nix system in every bank.

Because that will never happen, right? Qualys is so secure you should just trust them with root access to all your systems because that will be just fine. And, well, if it did happen it wouldn't be very bad: does it matter so much if all the money is sucked out of your bank account? Of everyone's bank account?

Well, either the world just dodged a bullet, or it didn't but we don't know yet. Either way I hope Qualys just dies.

(I'm kind of annoyed that I was about 10% of the way through a blog posting on this though: couldn't they have waited so I could have said 'I told you so' at least?)

[1] https://qualys-secure.force.com/discussions/s/article/000006220

You will stop at nothing to reach your objective, but only because your
brakes are defective.