News: 1619628312

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ransomware crooks who broke into Merseyrail used director's email address to brag about it – report

(2021/04/28)


Brit railway company Merseyrail is understood to have suffered a ransomware attack – and the crooks responsible reportedly pwned a director's Office 365 account to email employees and journalists about it.

News of the breach was [1]reported by BleepingComputer, which received one of those emails.

[2]

A spokesperson for the rail operator told us in a statement: “Merseyrail was recently subject to a cyber-attack. A full investigation has been launched and relevant authorities notified. This does not affect the operation of our services, which will continue to run as advertised.”

Merseyrail's network covers 68 stations around Liverpool, Birkenhead and Southport, stretching as far south as Chester.

[3]

It was claimed that the group responsible was the Lockbit gang, a relatively new organisation. Darktrace reckoned it was first seen in 2019 and leveraged tools such as PowerShell to compromise its victims. Darktrace reckoned that Lockbit's average ransom demand was $40,000.

Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs [4]READ MORE

Describing a previous infection of one of its clients, Darktrace [5]said : "The attack commenced when a cyber-criminal gained access to a single privileged credential – either through a brute-force attack on an externally facing device, as seen in previous LockBit ransomware attacks, or simply with a phishing email."

Sophos carried out a [6]technical analysis of Lockbit back in 2020, noting that the crew refuses to target victims from the Commonwealth of Independent States (basically the old Soviet Union). When deployed it tries to kill Windows processes, including products from Norton, Symantec, Sophos, and Qihoo360 as well as backup suites. It also persists after shutdown through a registry key.

[7]

The Information Commissioner's Office said it was aware of the ransomware attack at Merseyrail, which was last voted, for the second year running, as the UK's [8]most reliable train operator . ®

Get our [9]Tech Resources



[1] https://www.bleepingcomputer.com/news/security/uk-rail-network-merseyrail-likely-hit-by-lockbit-ransomware/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIna@EUcotajLkw7UPqN1gAAAJE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIna@EUcotajLkw7UPqN1gAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/04/26/emotet_sunday_25_april_killswitch_date/

[5] https://www.darktrace.com/en/blog/lock-bit-ransomware-analysis-rapid-detonation-using-a-single-compromised-credential/

[6] https://news.sophos.com/en-us/2020/04/24/lockbit-ransomware-borrows-tricks-to-keep-up-with-revil-and-maze/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIna@EUcotajLkw7UPqN1gAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.railadvent.co.uk/2020/01/merseyrail-named-best-rail-operator-in-uk.html

[9] https://whitepapers.theregister.com/

Ha Ha

FlamingDeath

This is hilarious

Have they considered paying the CEO more money to solve the problem?

Re: Ha Ha

FlamingDeath

“I like money”

- Frito

Re: Ha Ha

FlamingDeath

Was it the IT director? Tell me it wasn’t hahaha

Re: Ha Ha

Anonymous Coward

Good grief man, stop laughing at your own comments.

This does not affect the operation of our services,

Yet Another Anonymous coward

To be fair, the explosion of a thermonuclear device wouldn't affect the operation of the services of many rail franchises

Re: This does not affect the operation of our services,

WolfFan

The traibs might actually move.

Paul Herber

Maybe they infiltrated MerseyRail with a sleeper.

Bendacious

Just me or does the phrase "leveraged tools such as PowerShell to compromise its victims" sound a bit odd. Bit like saying "they used operating system commands to make the computer do things". I did try to make this not sound snarky but I failed.

A total abstainer is one who abstains from everything but abstention,
and especially from inactivity in the affairs of others.
-- Ambrose Bierce, "The Devil's Dictionary"