SQL Server admins warned about Fargo ransomware
(2022/09/26)
- Reference: 1664208011
- News link: https://www.theregister.co.uk/2022/09/26/sql_server_fargo_ransomware/
- Source link:
Organizations are being warned about a wave of attacks targeting Microsoft SQL Server with ransomware known as Fargo, which encrypts files and threatens victims that their data may be published online if they do not pay up.
The warning comes in a [1]blog posting from analysts at the AhnLab Security Emergency Response Center (ASEC), which says that Fargo is one of the most prominent ransomware strains targeting vulnerable SQL Server instances, and was previously also known as Mallox because it used the file extension .mallox for encrypted files in an earlier wave of attacks.
According to ASEC, a Fargo attack starts with the SQL Server process on a compromised machine being used to download a .net file via the cmd.exe and powershell.exe consoles. This payload fetches and runs additional malware code which generates and executes a BAT file that then shuts down some processes and services.
[2]
The next step in the attack is to inject .net code into AppLaunch.exe, which then attempts to delete the registry key for Raccine, an open source tool designed to provide some protection against ransomware attacks.
[3]
[4]
Fargo proceeds to execute the recovery deactivation command, and deletes all shadow copies using vssadmin (which is what Raccine is supposed to prevent), before shutting down various database-related processes to make the content of database files available for encryption.
If successful, the encrypted files have their filename appended with ".Fargo3" and a ransom note is generated with the filename "RECOVERY FILES.txt". The latter informs the victim how to contact the attackers in order to pay the ransom, and threatens: "In case of non-payment of the ransom, your data may be published on the public domain."
[5]Noberus ransomware gets info-stealing upgrades, targets Veeam backup software
[6]ChromeLoader, what took you so long? Malvertising irritant now slings ransomware
[7]Been hit by LockerGoga ransomware? A free fix is now out
[8]Ransomware gang threatens 1m-plus medical record leak
But how are the attackers getting access to SQL Server instances to deploy the ransomware in the first place? According to ASEC, this will typically take the form of brute force attacks and dictionary attacks on systems where account credentials are being poorly managed. Attacks may also seek to exploit systems that have not been fully patched and may thus be vulnerable to known exploits.
The ASEC blog offers the advice that SQL Server admins should use strong passwords that are difficult to guess for their accounts, and change them periodically to protect the database server from brute force attacks and dictionary attacks, which any IT pro worth their name will have been doing already. It also offers the usual recommendation that organizations should apply security patches to guard against exploits using known vulnerabilities.
[9]
The threat posed by ransomware remains one of the biggest security headaches for organizations, accounting for 25 percent of observed security incidents and present in 70 percent of all malware infections, according to a Verizon [10]report published earlier this year. ®
Get our [11]Tech Resources
[1] https://asec.ahnlab.com/en/39152/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/09/25/noberus_ransomware_symantec/
[6] https://www.theregister.com/2022/09/21/vmware_microsoft_chromeloader_threat/
[7] https://www.theregister.com/2022/09/19/lockergoga_ransomware_decryptor/
[8] https://www.theregister.com/2022/09/14/ransomware_medical_groups/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/05/26/verizon-cybersecurity-report-ransomware/
[11] https://whitepapers.theregister.com/
The warning comes in a [1]blog posting from analysts at the AhnLab Security Emergency Response Center (ASEC), which says that Fargo is one of the most prominent ransomware strains targeting vulnerable SQL Server instances, and was previously also known as Mallox because it used the file extension .mallox for encrypted files in an earlier wave of attacks.
According to ASEC, a Fargo attack starts with the SQL Server process on a compromised machine being used to download a .net file via the cmd.exe and powershell.exe consoles. This payload fetches and runs additional malware code which generates and executes a BAT file that then shuts down some processes and services.
[2]
The next step in the attack is to inject .net code into AppLaunch.exe, which then attempts to delete the registry key for Raccine, an open source tool designed to provide some protection against ransomware attacks.
[3]
[4]
Fargo proceeds to execute the recovery deactivation command, and deletes all shadow copies using vssadmin (which is what Raccine is supposed to prevent), before shutting down various database-related processes to make the content of database files available for encryption.
If successful, the encrypted files have their filename appended with ".Fargo3" and a ransom note is generated with the filename "RECOVERY FILES.txt". The latter informs the victim how to contact the attackers in order to pay the ransom, and threatens: "In case of non-payment of the ransom, your data may be published on the public domain."
[5]Noberus ransomware gets info-stealing upgrades, targets Veeam backup software
[6]ChromeLoader, what took you so long? Malvertising irritant now slings ransomware
[7]Been hit by LockerGoga ransomware? A free fix is now out
[8]Ransomware gang threatens 1m-plus medical record leak
But how are the attackers getting access to SQL Server instances to deploy the ransomware in the first place? According to ASEC, this will typically take the form of brute force attacks and dictionary attacks on systems where account credentials are being poorly managed. Attacks may also seek to exploit systems that have not been fully patched and may thus be vulnerable to known exploits.
The ASEC blog offers the advice that SQL Server admins should use strong passwords that are difficult to guess for their accounts, and change them periodically to protect the database server from brute force attacks and dictionary attacks, which any IT pro worth their name will have been doing already. It also offers the usual recommendation that organizations should apply security patches to guard against exploits using known vulnerabilities.
[9]
The threat posed by ransomware remains one of the biggest security headaches for organizations, accounting for 25 percent of observed security incidents and present in 70 percent of all malware infections, according to a Verizon [10]report published earlier this year. ®
Get our [11]Tech Resources
[1] https://asec.ahnlab.com/en/39152/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/09/25/noberus_ransomware_symantec/
[6] https://www.theregister.com/2022/09/21/vmware_microsoft_chromeloader_threat/
[7] https://www.theregister.com/2022/09/19/lockergoga_ransomware_decryptor/
[8] https://www.theregister.com/2022/09/14/ransomware_medical_groups/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YzIg@pn4OWf56EFaFBX8VgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2022/05/26/verizon-cybersecurity-report-ransomware/
[11] https://whitepapers.theregister.com/
Re: Changing Passwords is NOT good practice
richardcox13
Edit: "blokequote" seems a thing that HTML shouldn't have, so I'm glad that didn't work!
Its a SQL server not a web server
Lorribot
Might just be me but "a Fargo attack starts with the SQL Server process on a compromised machine being used to download a .net file via the cmd.exe and powershell.exe consoles" would seem to indicate that the best course of action is to not allow your SQL servers access to anything on the internet.
I am sure someone will point me to a valid reason but personally I am at a loss.
Changing Passwords is NOT good practice
and change them periodically to protect the database server from brute force attacks and dictionary attacks, which any IT pro worth their name will have been doing already
This goes against best practice, and only helps if your password later appears in password lists: which is won't if it was good enough in the first place (20+ chards from random password generator) and not reuse.
Just repeating this bad advice makes me question the source.
NCSC: https://www.ncsc.gov.uk/blog-post/problems-forcing-regular-password-expiry