News: 1660197550

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cisco admits corporate network compromised by gang with links to Lapsus$

(2022/08/11)


Cisco disclosed on Wednesday that its corporate network was accessed by cyber-criminals in May after an employee's personal Google account was compromised – an act a ransomware gang named "Yanluowang" has now claimed as its work.

The world's largest networking vendor disclosed the months-old compromise after a list of files accessed during the incident appeared on the dark web.

A Cisco [1]statement asserts the company "did not identify any impact to [its] business as a result of this incident, including Cisco products or services, sensitive customer data or sensitive employee information, intellectual property, or supply chain operations."

[2]

Cisco Security Incident Response (CSIRT) and the company's cybersecurity intelligent group Cisco Talos [3]specified the only successful data exfiltration was from an account with cloud storage locker Box that was associated with a compromised employee's account.

[4]

[5]

But the attacker did manage to spend some time inside Cisco's IT.

According to Talos's post, the attacker obtained access to Cisco networks, enrolled a series of devices for MFA and authenticated successfully to the Cisco VPN.

[6]

The attacker "then escalated to administrative privileges, allowing them to login to multiple systems." That action alerted the Cisco Security Incident Response Team (CSIRT), which swooped in with "extensive IT monitoring and remediation capabilities" to "implement additional protections, block any unauthorized access attempts, and mitigate the security threat." Efforts were also made to improve "employee cybersecurity hygiene."

The infiltration occurred after attackers stole Cisco credentials from an employee by gaining control of a personal Google account.

The attacker then employed voice-phishing techniques that saw operatives call using various accents and posing as various trusted organizations, seeking to help the Cisco staffer, until he or she cracked and accepted a bogus MFA notification that gave the hackers access to the VPN.

[7]

Once inside, they spread laterally to Citrix servers – eventually obtaining privileged access to domain controllers. As domain admin, they operated tools like ntdsutil, adfind and secretsdump to exfiltrate data and install a backdoor and other payloads.

[8]Ex-CISA chief Krebs calls for US to get serious on security

[9]Twilio customer data exposed after its staffers got phished

[10]Cisco compresses Catalyst switches to compact size

[11]Kaspersky cracks Yanluowang ransomware, offers free decryptor

Cisco was able to revoke the attacker's access, but that did not discourage them. They tried to re-establish entry multiple times, preying on employees' weak password rotation hygiene. The attacker then attempted to establish email communication with Cisco execs, showing off directory listings of their loot – an alleged 2.75GB of data containing around 3,700 files – and suggesting Cisco could pay to avoid disclosure.

"Based upon artefacts obtained, tactics, techniques, and procedures (TTPs) identified, infrastructure used, and a thorough analysis of the backdoor utilized in this attack, we assess with moderate to high confidence that this attack was conducted by an adversary that has been previously identified as an initial access broker (IAB) with ties to both UNC2447 and Lapsus$," said Cisco, adding activity was also linked to the Yanluowang ransomware gang.

Yanluowang has claimed credit for the breach.

[12]#yanluowang ransomware has posted [13]#Cisco to its leaksite. [14]#cybersecurity [15]#infosec [16]#ransomware [17]pic.twitter.com/kwrfjbwbkT — CyberKnow (@Cyberknow20) [18]August 10, 2022

The [19]Yanluowang ransomware , named after a Chinese deity, is typically used against financial institutions, but has been known to infect companies in manufacturing, IT services, consultancy and engineering.

Interestingly, no ransomware appears to have been deployed in the attack on Cisco.

"While we did not observe ransomware deployment in this attack, the TTPs used were consistent with 'pre-ransomware activity' – activity commonly observed leading up to the deployment of ransomware in victim environments," Cisco stated.

The company also revealed that its reason for disclosing the incident now – more than three months after the compromise – was that it had been "actively collecting information about the bad actor to help protect the security community." But once files from the incident were posted to the dark web, Cisco felt it had to reveal the attack. ®

Get our [20]Tech Resources



[1] https://tools.cisco.com/security/center/resources/corp_network_security_incident

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YvTTR2e5kEkuz8Hsq1@-9AAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] http://blog.talosintelligence.com/2022/08/recent-cyber-attack.html

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvTTR2e5kEkuz8Hsq1@-9AAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvTTR2e5kEkuz8Hsq1@-9AAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvTTR2e5kEkuz8Hsq1@-9AAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvTTR2e5kEkuz8Hsq1@-9AAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/08/10/krebs_black_hat/

[9] https://www.theregister.com/2022/08/08/twilio_phishing_attack/

[10] https://www.theregister.com/2022/06/28/catalyst_9200_compact/

[11] https://www.theregister.com/2022/04/19/kaspersky_yanluowang_ransomware/

[12] https://twitter.com/hashtag/yanluowang?src=hash&ref_src=twsrc%5Etfw

[13] https://twitter.com/hashtag/Cisco?src=hash&ref_src=twsrc%5Etfw

[14] https://twitter.com/hashtag/cybersecurity?src=hash&ref_src=twsrc%5Etfw

[15] https://twitter.com/hashtag/infosec?src=hash&ref_src=twsrc%5Etfw

[16] https://twitter.com/hashtag/ransomware?src=hash&ref_src=twsrc%5Etfw

[17] https://t.co/kwrfjbwbkT

[18] https://twitter.com/Cyberknow20/status/1557419082210676736?ref_src=twsrc%5Etfw

[19] https://www.theregister.com/2022/04/19/kaspersky_yanluowang_ransomware/

[20] https://whitepapers.theregister.com/



Once again

Pascal Monett

Somebody clicked on a stupid attachment, and miscreants walked all over Cisco's IT.

I would say kudos to Cisco's security team for at least detecting them, but unfortunately they still got off with data.

Ideally, they should have been blocked before that.

Now the question is : why on God's Green Earth didn't they deploy an encryption tool ?

Did they save that for next time ?

Home centers are designed for the do-it-yourselfer who's willing to
pay higher prices for the convenience of being able to shop for lumber,
hardware, and toasters all in one location. Notice I say "shop for," as
opposed to "obtain." This is the major drawback of home centers: they are
always out of everything except artificial Christmas trees. The home center
employees have no time to reorder merchandise because they are too busy
applying little price stickers to every object -- every board, washer, nail
and screw -- in the entire store ...

Let's say a piece in your toilet tank breaks, so you remove the
broken part, take it to the home center, and ask an employee if he has a
replacement. The employee, who has never is his life even seen the inside
of a toilet tank, will peer at the broken part in very much the same way
that a member of a primitive Amazon jungle tribe would look at an electronic
calculator, and then say, "We're expecting a shipment of these sometime
around the middle of next week."
-- Dave Barry, "The Taming of the Screw"