News: 1699603207

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

ICBC hit by ransomware impacting global trades

(2023/11/10)


China's largest bank, ICBC, was hit by ransomware that resulted in disruption of financial services (FS) systems on Thursday Beijing time, according to a notice on its website.

"Immediately upon discovering the incident, ICBC FS disconnected and isolated impacted systems to contain the incident," said the bank’s financial services division, which added that it was both investigating and progressing recovery efforts.

ICBC detailed that its FS business and email systems operate independently from the bank itself, and that domestic and overseas affiliates were not affected.

[1]

The incident has disrupted US Treasury markets, according to the [2]Financial Times , which first reported the story. The US Securities Industry and Financial Markets Association (SIFMA) reportedly told its members that the incident could prevent the settling of trades on behalf of other market players.

[3]

[4]

Malware research group vx-underground [5]revealed it was aware of equity traders that were unable to place or clear trades though ICBC.

Some had received an emergency notice stating that ICBC was unable to connect to the Depository Trust and Clearing – an issue that was impacting all of ICBC's clearing customers – and that due to the attack orders were not being accepted.

[6]LockBit alleges it boarded Boeing, stole 'sensitive data'

[7]Get your very own ransomware empire on the cheap, while stocks last

[8]LockBit victims in the US alone paid over $90m in ransoms since 2020

[9]Boeing acknowledges cyberattack on parts and distribution biz

"We successfully cleared US Treasury trades executed Wednesday (11/08) and Repo financing trades done on Thursday (11/09)," stated ICBC FS in the notice on its website Friday.

According to [10]Reuters , LSEG data showed the Treasury market functioning normally.

[11]

As [12]spotted by Recorded Future, cyber security expert Kevin Beaumont [13]deduced that ransomware gangs had exploited a Citrix Netscaler box that was unpatched for a bug known as CitrixBleed, which allows the bypass of authentication.

Beaumont noted that over 5,000 orgs were yet to patch CitrixBleed, which is tracked as CVE-2023-4966.

Citrix initially [14]issued a patch for the vulnerability on October 10. Two weeks later, the collaboration giant [15]urged admins to apply a fix immediately after it had received "reports of incidents consistent with session hijacking, and have received credible reports of targeted attacks exploiting this vulnerability."

[16]

The Register understands the hack is suspected to come from ransomware gang LockBit.

The prolific threat actor is believed to have [17]raked in more than $90 million in over 1,700 attacks between 2020 and mid-2023. The gang has a large number of affiliates which pay fees, including subscriptions, in exchange for a cut of the ransom payments.

Last month LockBit [18]took out Boeing's parts and distribution [19]website , which is still "down due to technical issues."

In the past it has also been known to hit [20]hospitals and [21]government orgs .

"Ransomware is disrupting everything from hospitals to financial markets. The problem is as bad as it's ever been, and governments' current counter-ransomware strategies are very clearly not working," Emsisoft threat analyst Brett Callow told The Register.

"In my opinion, the time has come for serious consideration to be given to a prohibition on the payment of demands, or at least severely restricting the circumstances in which they can be paid. That may be the only way we can bring an end to this constant barrage of financially motivated attacks," he added. ®

Get our [22]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZU4NVlVCSkg3zO2C1h4bQgAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.ft.com/content/8dd2446b-c8da-4854-9edc-bf841069ccb8

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU4NVlVCSkg3zO2C1h4bQgAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU4NVlVCSkg3zO2C1h4bQgAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://twitter.com/vxunderground/status/1722686306709393720

[6] https://www.theregister.com/2023/10/30/security_in_brief/

[7] https://www.theregister.com/2023/11/01/ransomedvc_owner_sells_operation/

[8] https://www.theregister.com/2023/06/14/lockbit_joint_advisory/

[9] https://www.theregister.com/2023/11/02/boeing_cyber_incident/

[10] https://www.reuters.com/world/china/chinas-largest-bank-icbc-hit-by-ransomware-software-ft-2023-11-09/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZU4NVlVCSkg3zO2C1h4bQgAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://therecord.media/icbc-dealing-with-ransomware-attack

[13] https://cyberplace.social/@GossiTheDog/111382300885477489

[14] https://www.theregister.com/2023/10/10/october_2023_patch_tuesday/

[15] https://www.theregister.com/2023/10/24/citrix_critical_patch/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZU4NVlVCSkg3zO2C1h4bQgAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.theregister.com/2023/06/14/lockbit_joint_advisory/

[18] https://www.theregister.com/2023/11/02/boeing_cyber_incident/

[19] https://www.theregister.com/2023/11/02/boeing_cyber_incident/

[20] https://www.theregister.com/2023/01/04/lockbit_sickkids_ransomware/

[21] https://www.theregister.com/2022/12/13/california_finance_department_lockbit/

[22] https://whitepapers.theregister.com/



‘Financial services (FS) Treasury market Trades’ be like

t245t

This fintech stuff reminds me of a David Attenborough documentary shown on BBC long ago. Depicting an Island society in the Pacific. Where the denizens used large rocks to trade for goods and services. Like some family throwing a wedding party. One rock could be worth a few hundred goats or sheep. The rocks were considered valuable as they had to be harvested from an island miles away. They stopped making such documentaries as the woke Taliban decided to get offended on behalf of indigenous peoples everywhere.

[1]Non paywalled Full Text

[1] https://justpaste.it/icbc

Say no, then negotiate.
-- Helga