News: 1662573608

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

US school year opens with reading, writing, and ransomware

(2022/09/07)


The Vice Society threat group is ramping up ransomware attacks on US school districts just as students around the country return to the classroom, the FBI and other federal agencies are warning.

The FBI, Cybersecurity and Infrastructure Agency (CISA), and Multi-State Information Sharing and Analysis Center (MS-ISAC) said in a [1]joint advisory this week that the Vice Society, which first appeared in the summer of 2021, recently began to disproportionately target the US education sector with ransomware attacks and they expect such attacks to increase as the school year rolls on.

"School districts with limited cybersecurity capabilities and constrained resources are often the most vulnerable; however, the opportunistic targeting often seen with cyber criminals can still put school districts with robust cybersecurity programs at risk," the agencies wrote.

[2]

"K-12 institutions may be seen as particularly lucrative targets due to the amount of sensitive student data accessible through school systems or their managed service providers."

[3]

[4]

Educational institutions, from local school districts to universities, are coming under increasing numbers of ransomware attacks fueled in large part by the rise of ransomware-as-a-service (RaaS), which lowers the skill level needed for launching such campaigns.

According to a July [5]report from cybersecurity vendor Sophos, ransomware attacks on educational entities jumped in 2021, with lower education seeing a 56 percent year-over-year increase and higher education growing 64 percent.

[6]

The education sector is the least able to keep data from being encrypted during an attack and the recovery costs from a ransomware attack are high – lower education last year spent an average $1.58 million and higher education $1.42 million, according to Sophos.

The FBI said the effects of ransomware attacks include restricted access to networks and data, theft of personnel data related to staff and students, delayed exams, and cancelled school days.

Over the Labor Day weekend, the Los Angeles Unified School District (LAUSD) came under a [7]ransomware attack that temporarily shut down email, computer systems, and applications. Emsisoft threat analyst Brett Callow said in a series of [8]tweets that the LAUSD was the 50th US education organization to be hit with a ransomware attack this year.

[9]

Vice Society is much like other ransomware groups these days. Rather than encrypt the data found on victims' networks, it exfiltrates the files and threatens to publicly release the data if the ransom isn't paid. The group also doesn't use a ransomware variant it developed. Instead, it deploys versions of such ransomware families as HelloKitty/Five Hand and Zeppelin. The group also may use other variants in the future, according to the advisory.

Threat researchers with cybersecurity vendor Sekoia said in a July [10]report that Vice Society – which they believe is operated by English speakers – uses Zeppelin to target Windows systems while HelloKitty was used to target Linux systems at the end of 2021.

[11]Cyberattack brings down InterContinental Hotels' booking systems

[12]Ransomware gang hits second-largest US school district

[13]Unhappy about excluding nation-state attacks from cyberinsurance? Get ready to pay

[14]LockBit gang hit by DDoS attack after threatening to leak Entrust ransomware data

As of June, the group had claimed 88 victims. Just over 26 percent of those listed on its leak site are educational-related entities, according to Sekoia. Vice Society is also known for targeting the healthcare industry and was behind the attack earlier this year on accounting company [15]Optionis Group .

Among its recent education victims are the Linn-Mar Community School District in Iowa and the Medical University of Innsbruck.

The federal agencies suspect that Vice Society attackers get initial access to a target's network by exploiting internet-facing applications and stealing compromised credentials. They then spend time moving through the network to identify ways to increase access and exfiltrating data that will be used in their double-extortion tactics.

Just as the group employs various ransomware variants in its attacks, it also uses a range of tools to move laterally through the network, including SystemBC, PowerShell Empire, and Cobalt Strike.

"They have also used 'living off the land' techniques targeting the legitimate Windows Management Instrumentation (WMI) service and tainting shared content," the agencies wrote in their advisory.

Vice Society also has exploited the [16]PrintNightmare vulnerability – a remote code execution (RCE) flaw that can enable cybercriminals to take control of a PC – to escalate privileges and leverage scheduled tasks, create undocumented autostart Registry keys, and point legitimate services to its own malicious dynamic link libraries via the DLL side-loading tactic.

The group evades detection by masking their malware as legitimate files, process injection, and leveraging tools to defeat dynamic analysis.

"Vice Society actors have been observed escalating privileges, then gaining access to domain administrator accounts, and running scripts to change the passwords of victims' network accounts to prevent the victim from remediating," the agencies wrote.

As part of their advisory, they listed the indications of compromise (IoC) and a laundry list of steps school districts can take to protect themselves against ransomware attacks, including maintaining offline backups, reviewing the security posture of third-party vendors, developing a recovery plan, requiring multifactor authentication for all services, segment networks, and keeping all systems up to date. ®

Get our [17]Tech Resources



[1] https://www.cisa.gov/uscert/ncas/alerts/aa22-249a

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YxkUdQXtlgD7TZvklq9LKgAAANY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxkUdQXtlgD7TZvklq9LKgAAANY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxkUdQXtlgD7TZvklq9LKgAAANY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://news.sophos.com/en-us/2022/07/12/the-state-of-ransomware-in-education-2022/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxkUdQXtlgD7TZvklq9LKgAAANY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/09/06/lausd_ransomware_fbi_cisa_los_angeles/

[8] https://twitter.com/BrettCallow/status/1567141518460473344

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxkUdQXtlgD7TZvklq9LKgAAANY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group/

[11] https://www.theregister.com/2022/09/06/ihg_hotels_data_breach/

[12] https://www.theregister.com/2022/09/06/lausd_ransomware_fbi_cisa_los_angeles/

[13] https://www.theregister.com/2022/09/06/lloyds_cyber_insurance_policy/

[14] https://www.theregister.com/2022/08/22/entrust_lockbit_ddos_ransomware/

[15] https://www.theregister.com/2022/02/11/optionis_stolen_data/

[16] https://www.theregister.com/2022/03/16/russia-attack-ngo-mfa-printnightmare/

[17] https://whitepapers.theregister.com/



Firewalls needed, not little "security options"

Version 1.0

Everywhere needs to install and configure firewalls, maybe one configured to allow data through it for "users" but the firewall for the internal email support and access needs to be configured to block everything except the ports they actually must have to use and the internal network must be isolated from everyone's internet access network.

Burning Bridges (Lost Forevermore?)

An_Old_Dog

This is just another incident which underlines how administrators and technicians have thrown away their fallback technologies and methods after they've built systems based on, and dependent upon , always-working, networked-to-everything computers.

When I was in college, there were many non-computers-networked-to-the-entire-world ways of doing things. We had scheduled local-cable TV broadcasts of videotaped lectures, photocopies of professors' overhead-projector sheets (these days, called "slide decks"), mark-sense test sheets (fill in the correct circle with a #2 pencil), "announcement" messages on some phone lines, etc. The campus didn't screech to a halt if email wasn't working, because we had the postal service and land-line telephones. If the electricity failed, guess what? The buildings had large windows to let in daylight, some of us had manual typewriters, the school had some mechanical mimeograph machines, some of us had slide-rules, and we had trigonometry- and logarithm tables in books. It was slow and aggravating to do things using some of those methods, but we did have them as fallbacks .

Our local convenience store had no power one day due to an auto accident (power pole damage). Their PC-based point-of-sale system was useless. They were still open for business, though, using a battery-powered adding machine to print sales slips. They were able to do this because they had labelled the packages with the prices. A major retail-chain store just up the road simply closed for the day, because without the abiity to read bar codes on packages, and to access the price database in their store computers, they couldn't do business. (Why no battery backups for the major store's POS systems and back-end computers?! Good question!)

Business continuity. That's an actual thing.

...I would go so far as to suggest that, were it not for our ego and
concern to be different, the African apes would be included in our
family, the Hominidae.
-- Richard Leakey