News: 1704368714

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

As lawmakers mull outlawing poor security, what can they really do to tackle online gangs?

(2024/01/04)


Comment In some ways, the ransomware landscape in 2023 remained unchanged from the way it looked in previous years. Vendor reports continue to show a rise in attacks, major organizations are still getting hit, and the inherent issues that enable it as a business model remain unaddressed.

Yet what 2023 may be remembered for is how law enforcement (LE) bookended it with a showing of progress and intolerance, making good on promises to bring down gangs that were once showpieces for the cybercriminal world.

Lawyer guilty of arrogance after ignoring tech support [1]READ MORE

The [2]demise of RagnarLocker and Qakbot followed that of Hive at the start of the year, and partial success was enjoyed in the attempts to [3]end AlphV/BlackCat in December. While the latter still lives on and has continued to breach victims, LE was able to release a decryptor for hundreds of previous cases, and that alone shouldn't detract from what has been a huge year for counter-ransomware ops.

AlphV/BlackCat might have squirmed their way out of authorities' clutches for now, but the action from national security agencies this year has given the industry reasons to be cheerful after a barren year for good news on this front.

2022 saw a rare drop in ransomware attacks but it was short-lived and still plagued by major incidents, even if there weren't quite as many of them. LE also failed to register a single significant bust, with the previous one being REvil's shuttering in late 2021.

[4]

Conti died off, but only its brand. And LE had no hand in the matter. The group ravaged organizations and governments for years before splitting off into smaller cells.

[5]

[6]

Indeed, 2023 was something of a statement sent by authorities. For years, various agencies repeated renditions of 'ransomware can no longer be tolerated', but the disruptions from the past 12 months feel like genuine steps in the right direction.

However, there are still missing pieces of the puzzle, and the lack of arrests remains a concern. Dismantling an operation is no mean feat and should be commended, however, in the grand scheme of things, it stops essentially nothing if the criminals continue to run free.

[7]

The need for robust intervention here is undeniable. LE's takedowns are impactful but not preventative. The industry needs governments to insert themselves into the crisis and take decisive action to stop ransomware from becoming even more out of hand than it already is.

Take AlphV/BlackCat, for example. It was arguably the scummiest of all the ransomware groups in 2023. In the space of 12 months, its leaders – believed to be based in Russia – signed off on some of the worst acts ever seen in ransomware, including the [8]leaking of breast cancer patients' nudes . Despite being known for freely targeting hospitals, charities, schools, and other similarly sensitive targets, the attack on Lehigh Valley Health Network was a new low.

The crew also continued to push the boundaries of extortion, even going so far as to weaponize the Securities and Exchange Commission (SEC). In November it allegedly [9]filed a regulatory complaint over a target's failure to report a breach within the mandated four-day window. It then repeated the trick in December. Both were brazen attempts to hurry along ransom payment negotiations. No wonder the feds tore it down.

[10]

If the authorities are serious about disrupting ransomware for good, and ensuring criminals like those behind the worst operations are left without a job, then the approach must change. If takedowns alone aren't working, and they aren't working, other solutions are required.

Governments will have crucial roles in the fight against ransomware. Industry will no doubt pray that 2024 will be the year in which state influence finally exerts itself into cybercrime in the way it needs to. Introducing impactful legislation, however, will be far from straightforward.

Step up, lawmakers

It goes without saying that the private sector must do better while it waits for higher powers to enact the required change. Building better, more secure products will ease the burden of applying the countless patches released every month – a relentless function of security gigs that shouldn't be as disruptive as it is.

Law enforcement is doing a solid job at disrupting ransomware within its powers, and cybersecurity awareness in organizations is increasing gradually to mitigate the threat. The next step in the fight against ransomware, however, must come from the legislature. 2024 can and should be the year that's remembered not just for the biggest takedowns, but for the impactful policy decisions that help quell the threat for good.

That said, there aren't any perfect solutions here. There are a few schools of thought when it comes to combating ransomware through legislation, the most prominent of which is to ban ransom payments entirely, both from the public and private sectors.

Politicians have wrestled with implementing a ransom ban for years, but have taken no serious steps to introduce one. The closest we've come on a global scale is with the International Counter Ransomware Initiative's (CRI) [11]pledge to refuse ransom payments, but without any private sector implications, it means fairly little.

Despite it being a solution that would almost certainly deliver the desired outcome in the long term, the short-term consequences of banning ransom payments would likely be dire. The organizations hit with ransomware in the first months, years, or however long it takes for ransomware gangs to abandon their craft, after such a law's enactment will have their futures jeopardized. There is also the genuine possibility that the hard work infosec has done to promote a culture of transparency is wholly undone. Attacks could once again be hidden from the public and authorities, and payments continue to flow, but more quietly.

Another approach is to outlaw poor security practices. The idea is that organizations which leave themselves open to targeting by cybercriminals ensure there are always individuals willing to exploit them, perpetuating the issue.

Neither this approach, nor one that involves a ban on payments, is actually ideal or even productive when we consider potential victims like hospitals. These types of underfunded institutions that provide critical services cannot afford any downtime, let alone a SOC staffed with world-class talent. When they get hit, the only priority is to get systems back online so people don't die. Do we punish the overstretched hospital IT teams here?

[12]Spanish phisherfolk caught in cops' net in multi-million-euro catch

[13]Admin behind E-Root stolen creds souk extradited to US

[14]US officials close to persuading allies to not pay off ransomware crooks

[15]A tale of 2 casino ransomware attacks: One paid out, one did not

An area to explore further is placing greater responsibilities on organizations involved in the trading of cryptocurrencies to disrupt the flow of funds to known cybercrime rings. It's one of the intentions of the CRI and can already be seen in action today.

The UK's Financial Conduct Authority (FCA), for example, already has the power to audit crypto firms, like exchanges, for anti-money laundering (AML) and terrorist procedures. Part of the CRI's pledge is to also implement the Financial Action Task Force (FATF)'s Recommendation 15, which essentially stipulates that similar checks should be carried out at the government level across all 50 of its members.

However, given that I've been requesting briefings with the FCA to discuss this very matter, and its plans to stem the flow of illicit funds, for months now, only for it to ignore every contact, I have little confidence this is considered a priority at the regulatory level.

Ensuring the legislative approach that's taken is both effective and doesn't threaten the futures of organizations is going to be a difficult task. What's incontrovertible though is that legislation is required in some capacity.

What we have seen in the past year though is Western governments' willingness to keep fighting and refusal to back down against the threat. The concrete action of LE in 2023 not only delivers admirable disruption to cybercrime but serves as a constant reminder that ransomware will never be accepted, even though it has become somewhat normalized.

It's a precarious road ahead but here's hoping 2024 builds on the progress of 2023. ®

Get our [16]Tech Resources



[1] https://www.theregister.com/2023/11/17/on_call/

[2] https://www.theregister.com/2023/10/19/europol_knocks_ragnarlocker_offline/

[3] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZbkPjoFZTNmWSs9I6LLnQAAABg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZbkPjoFZTNmWSs9I6LLnQAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZbkPjoFZTNmWSs9I6LLnQAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZbkPjoFZTNmWSs9I6LLnQAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/

[9] https://www.theregister.com/2023/11/16/clorox_ciso_washes_out/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZbkPjoFZTNmWSs9I6LLnQAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/

[12] https://www.theregister.com/2023/10/25/spanish_phishing_arrests/

[13] https://www.theregister.com/2023/10/20/eroot_admin_extradited/

[14] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/

[15] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

[16] https://whitepapers.theregister.com/



Headley_Grange

Make it illegal to pay fines.

Make it illegal to insure against it.

Make it mandatory to report the measures you're taking.

Put board members, directors and shareholders in prison when their main countermeasure is a pre-prepared "We take security extremely seriously" statement.

That's just me brainstorming on my own and ignoring the ones relating to judicial killings of the perps.

Version 1.0

How much more secure Hospitals would be if they stop using the internet and return to exchanging data via faxes - back in the days before the internet was available outside the military we only occasionally got a letter or fax theft attempt. They were easy to immediately put in the trash can in those days. Abandoning the internet would be miserable but being safe would keep the medical world working well - if data is hard to exchange then workers at both ends will look at it well.

jmch

"Make it illegal to insure against it."

The way to do that would be, enforce that companies treating personal data MUST (a) pay each person whose data is lost a fine (to the individual not a fine levied by the government!!) and (b) have cyber-insurance that specifically covers such payment in full. The market will ensure that insurers will audit the security of prospective clients and only accept to insure the ones they find safe and/or have exclusions that will make the company bear the costs if it is hacked because of shoddy security.

There needs to be the same sort of arrangement that banks have with their insurers around the physical security of cash and digital security of online banking

"Another approach is to outlaw poor security practices"

Mike 137

Not really practicable, as no developer, vendor or organisation actually intends to deliver poor security -- it's always an accidental outcome of insufficient understanding, expertise, attention or some mix of all three. The fundamental contributor to better security which nobody seems willing to discuss is improved education for all concerned -- including robust validation of competence against common standards (provided of course that those standards are adequate).

However pretty much all current standards are based on a consensus of current common practice ,which in many cases does not equate to objectively best practice. As training (and thus current common practice) is generally based on those standards, we're in a closed feedback loop that inhibits (or at worst prevents) improvement. I've been working towards improved infosec education and improved standards for around two decades, but because of this closed feedback loop the resistance to change is ferocious. That's the first and hardest nut we have to crack.

Re: "Another approach is to outlaw poor security practices"

elsergiovolador

as no developer, vendor or organisation actually intends to deliver poor security -- it's always an accidental outcome of insufficient understanding, expertise, attention or some mix of all three.

No. This is not accidental, but can be attributed to the mix of stupidity, ego and greed. Most businesses don't want to spend on IT. After all this is just some bloke browsing TheReg whole day doing nothing, why pay him six figures? Just get a nephew to install fairywall or whatever this is called, job done.

Re: "Another approach is to outlaw poor security practices"

Headley_Grange

When I worked on a large project that included some works that were classified as construction we all (directors included) got a full day's lecture on the legal implications of Health and Safety legislation including the fact that we had individual as well as corportate responsibility and that we could be personally prosecuted, put in prison and have our assests seized to pay fines and compensation. The first thing the directors did was put a CDM consultant on a retainer. Everyone got a handbook and it was consulted regularly. Anyone in doubt went and asked for help. The directors didn't ask us to take stupid shortcuts that risked an H&S breach. It worked fine - but only because people knew they could go to prison.

Ditto when I ran a project under ITAR - the threat (whether real or not) of extradition to the US was enough to make everyone take ITAR seriously.

If the same rules applied for cyber security then I assure you things would change pretty quickly and the "accidental outcomes" would disappear because the threat of prison and losing your house really focuses people on understanding, expertise and attention.

Re: "Another approach is to outlaw poor security practices"

stiine

You're naive. There's always going to be someone* who's going to break the rules for a profit.

* - and they're never alone.

Re: "Another approach is to outlaw poor security practices"

Bitsminer

This.

It just needs doing.

Nonsense

elsergiovolador

when we consider potential victims like hospitals. These types of underfunded institutions that provide critical services cannot afford any downtime, let alone a SOC staffed with world-class talent

This is pure nonsense. Given hospitals are totally fine hiring useless managers at high six figures or paying inflated rates to agencies bringing in temp workers, there is certainly money to be found for proper security.

But first thing that needs to happen is proper dealing with corruption at those places.

Hospitals? Underfunded? Are you serious?

Gene Cash

You start out paying $6.99 for a single q-tip and it goes up from there.

Hospitals get hit because doctors consider themselves above security and above learning how to use a computer.

Logging in and passwords are something the vulgar plebeians have to do... doctors won't put up with that nonsense!

Send them an email with a link saying "click this to give me ownership of your car and house" and they'll click it faster than a Helium-5 half-life, then blame everyone else for having to walk to a hotel.

Now wait a minute

Pascal Monett

" There is also the genuine possibility that the hard work infosec has done to promote a culture of transparency is wholly undone. Attacks could once again be hidden from the public and authorities, and payments continue to flow, but more quietly. "

Didn't they say the same thing about it being illegal to pay kidnapper's ransom ?

They still made it illegal.

It worked.

DeathSquid

I never understood the fuss. Just run Linux and it won't happen. And if it does, just restore from backup.

I hope the ``Eurythmics'' practice birth control ...