{"id":8125,"date":"2021-07-06T09:22:35","date_gmt":"2021-07-06T08:22:35","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=8125"},"modified":"2021-07-07T11:02:18","modified_gmt":"2021-07-07T10:02:18","slug":"kaseya-resolving-major-cybersecurity-attack","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2021\/07\/06\/kaseya-resolving-major-cybersecurity-attack\/","title":{"rendered":"Kaseya resolving major cybersecurity attack"},"content":{"rendered":"\n<p>IT company Kaseya has been hit by a major ransomware attack and is working to resolve its aftermath. It is working with FireEye Mandiant to resolve the incident and to assess the manner and impact of the attack and identify and mitigate the vulnerability.<\/p>\n\n\n\n<p>A statement from the company said: \u201cKaseya\u2019s VSA\u202fproduct\u202fhas unfortunately\u202fbeen\u202fthe victim of a sophisticated cyberattack.\u202f\u202fDue to our\u202fteams\u2019\u202ffast response, we believe that this has been localized to a very small number of on-premises\u202fcustomers\u202fonly.<\/p>\n\n\n\n<p>\u201cOur security, support, R&amp;D, communications and customer teams continue to work around the clock in all geographies to resolve the issue and restore our customers to service.\u201d<\/p>\n\n\n\n<p>Charl van der Walt, Head of Security Research, Orange Cyberdefense, said: \u201cThese so-called \u2018supply chain attacks\u2019 are the consequence of several diverse factors that have colluded to make a compromise of this kind almost inevitable. One of these factors is \u2018IT Interdependence\u2019 &#8211; IT systems and the businesses that use them do not operate in isolation. As a result, the impact of a breach or compromise is never restricted to the primary target alone.<\/p>\n\n\n\n<p>\u201cWe simply cannot afford to think of our own security as isolated or separate from the security of our technology product or service providers, or from the myriad of other business entities or government agencies we share technology with. A shared dependency on core technologies, vendors, protocols or core Internet systems like DNS or CDNs bind businesses together just as tightly as fibre links and IP networks. Businesses in turn also bind together the suppliers who depend on them, the industries they belong to, the countries they operate in and, eventually, the entire global economy.<\/p>\n\n\n\n<p>\u201cBy their very nature, supply chain attacks provide the attacker with vast scope and scale, even if they take more resources and time to perpetrate. The frequency of these attacks is therefore not as important as their impact. Given the persistence of the systemic forces that enable these attacks, we anticipate that they will increase in both frequency and impact.<\/p>\n\n\n\n<p>\u201cWhen we consider when, where and how much to invest in security, we must think beyond the single-dimensional risk we are addressing for our business and consider the impact of the secondary and tertiary effects on the broader economy when breaches and compromises happen. We need to recognise that what\u2019s bad for society generally, is also bad for us as businesses.\u201d<\/p>\n\n\n\n<p>James Shank, Ransomware Task Force Committee Lead for Worst Case Scenarios and Chief Architect, Community Services for Team Cymru, said: \u201cVendors and supply chains enable business growth and efficiency, but they also create high value targets for attackers. With SolarWinds, CodeCov, and now Kaseya being some of the recent software and IT system supply chain attacks that enabled attackers to hit their customers, the writing on the wall is crystal clear: Attackers are looking for ways to compromise supply chain vendors to amplify their reach into victims.<\/p>\n\n\n\n<p>\u201cThis is not the first and it won\u2019t be the last. It is time to add another item to the already overwhelmed corporate security teams: audit suppliers and integrations with your supply chain providers. Limit exposure to the absolute minimum while still enabling business operations.<\/p>\n\n\n\n<p>\u201cDuring the Ransomware Task Force Worst Case Scenarios thought experiment, this exact scenario was identified as a critical weakness. It isn\u2019t clear how best to respond, as the world &#8211; and enterprise operations &#8211; becomes more and more connected and co-dependent every day. Each of these connections can be a pathway for massively good things, but also opens the door to a shared fate scenario, where a security incident at your supplier is likely to also become an incident on your network.<\/p>\n\n\n\n<p>\u201cThe new security operations paradigm must consider suppliers as part of their extended perimeter to defend. Being able to see exposures and threats beyond the traditional network perimeter needs to become part of best in class security practice.\u201d<\/p>\n\n\n\n<p>Chris Grove, Product Evangelist, Nozomi Networks, said: \u201cThis type of a supply chain attack, similar to the SolarWinds attack, goes straight to the jugular of organisations looking to recover from a breach.<\/p>\n\n\n\n<p>\u201cThese types of technology management solutions can have high concentrations of risk due to their large collection of enterprise accounts with elevated privileges, unrestricted firewall rules needed for them to operate, and a cultural \u2018trust\u2019 that the traffic to\/from them is legitimate and should be allowed.<\/p>\n\n\n\n<p>\u201cOnce a breach happens, the victim would generally reach for these tools to work their way out of a bad situation, but when the tool itself is the problem, or is unavailable, it adds complexity to the recovery efforts.<\/p>\n\n\n\n<p>\u201cAt times like this, when we don\u2019t fully understand the scope and tactic used, or which versions are affected, visibility into the blast radius of the attacker is crucial. Knowing which systems were impacted, which were used for lateral movement, or where the attackers may be hiding, ensures defenders can make educated decisions on the ground. When it comes to defending critical infrastructure, that visibility could make all the difference between the power being on or off.\u201d<\/p>\n\n\n\n<p>Ross McKerchar, Sophos Vice President and Chief Information Security Officer, said: &#8220;This is one of the farthest reaching criminal ransomware attacks that Sophos has ever seen. At this time, our evidence shows that more than 70 managed service providers were impacted, resulting in more than 350 further impacted organizations.<\/p>\n\n\n\n<p>\u201cWe expect the full scope of victim organizations to be higher than what\u2019s being reported by any individual security company. Victims span a range of worldwide locations with most in the United States, Germany and Canada, and others in Australia, the U.K. and other regions.&#8221;<\/p>\n\n\n\n<p>&nbsp;Mark Loman, Sophos Director of Engineering, said: \u201cSophos is actively investigating the&nbsp;attack on Kaseya, which we see as a supply chain distribution attack. The adversaries are using MSPs as their distribution method to hit as many businesses as possible, regardless of size or industry type.<\/p>\n\n\n\n<p>\u201cThis is a pattern we\u2019re starting to see as attackers are constantly changing their methods for maximum impact, whether for financial reward, stealing data credentials and other proprietary information that they could later leverage, and more. In other widescale attacks we\u2019ve seen in the industry, such as WannaCry, the ransomware itself was the distributor \u2013 in this case, MSPs using a widely used IT management are the conduit.&nbsp;<\/p>\n\n\n\n<p>&nbsp;\u201cSome successful ransomware attackers have raked in millions of dollars in ransom money, potentially allowing them to purchase highly valuable zero-day exploits. Certain exploits are usually only deemed attainable by nation-states. Where \u2018nation-states\u2019 would sparingly use them for a specific isolated attack, in the hands of cybercriminals, an exploit for a vulnerability in global&nbsp;platform can disrupt many businesses at once and have impact on our daily lives.&nbsp;<\/p>\n\n\n\n<p>\u201cA day after the attack, it became more evident that an affiliate of the REvil Ransomware-as-a-Service (RaaS) leveraged a zero-day exploit that allowed it to distribute the ransomware via Kaseya\u2019s Virtual Systems Administrator (VSA) software. Usually, this software offers a highly trusted communication channel that allows MSPs unlimited privileged access to help many businesses with their IT environments.\u201d<\/p>\n\n\n\n<p>Based on Sophos threat intelligence,&nbsp;REvil has been active in recent weeks, including in the JBS attack, and is currently the dominant ransomware gang involved in Sophos\u2019 defensive managed threat response cases.<\/p>\n\n\n\n<p>Mark Manglicmot, VP of Security Services, Arctic Wolf, said: \u201cThe Kaseya VSA supply chain ransomware campaign is a sophisticated and intentional attack, the scope of which will not be fully understood for many weeks or possibly months. Any organization using Kaseya VSA should treat this as a critical risk to their business and immediately shut down their Kaseya VSA server. They should also follow&nbsp;CISA guidance&nbsp;to ensure that back-ups are up-to-date and air-gapped, manual patching is implemented, multi-factor authentication (MFA) is turned on, and then await&nbsp;<a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__helpdesk.kaseya.com_hc_en-2Dgb_articles_4403440684689&amp;d=DwMGaQ&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=EfMGYBONq4GOU40r5lw3FZlyx0SWRp3WzbtC2K29pjo&amp;m=McNA-kykUyiSb9F8qu3OcX4-uSc-kdfrXP6nq11wm3A&amp;s=m22Y7LaezhilqLCc15n3YFrfumQlJSoCL79lOLIwWqM&amp;e=\" target=\"_blank\" rel=\"noreferrer noopener\">a<\/a>dditional instructions from Kaseya&nbsp;for next steps.&nbsp;<\/p>\n\n\n\n<p>\u201cWith supply chain attacks able to cascade across thousands of organizations within a matter of hours, those looking to protect themselves against future incidents must deploy world-class security operations with 24&#215;7 monitoring capable of detecting, managing and mitigating any threat. Often, users are seen as the weakest link, and adversaries will continue to exploit the human element to reach their objectives, which means establishing a stronger security posture is the first and best approach organizations can take in avoiding future supply chain compromises.\u201d<\/p>\n\n\n\n<p>Craig Sanderson, VP of Product Management, Infoblox, said: \u201cThe Kaseya attack, which paralyzed companies such as the supermarket chain Coop in Sweden, shows that anyone can be targeted. Instead of being blackmailed by cyber-criminals, organizations need to proactively prepare defenses to mitigate against paying a painful ransom and reputation loss among customers and partners.<\/p>\n\n\n\n<p>\u201cTo prevent such damages, companies should make their security strategies as proactive as possible and keep back-ups in case a system reset is needed. Because attackers commonly use DNS for communicating with malicious domains, DNS security can help block those communications while providing indispensable visibility into the activity of impacted machines, helping customers understand the scope of a breach for quick response.\u201d<\/p>\n\n\n\n<p>Charles Carmakal, SVP and CTO, Mandiant, said: \u201cOn July 2, 2021, an affiliate of REvil\/Sodinokibi exploited&nbsp;multiple&nbsp;vulnerabilities in the Kaseya VSA product to distribute a ransomware encryptor to connected endpoints. Kaseya VSA is a remote monitoring and management solution used by managed service providers (MSPs) and organizations to remotely manage computer systems.<\/p>\n\n\n\n<p>\u201cThe number of impacted organizations is not currently known, but Kaseya estimates that the number of organizations impacted by the REvil ransomware disruption&nbsp;is under 1,500 organizations.&nbsp;Many of the impacted organizations are very small family businesses who are only now discovering the impacts because of the holiday weekend.&nbsp;<\/p>\n\n\n\n<p>\u201cREvil ransomware-as-a-service (RaaS) has been marketed in Russian-language underground forums since May 2019. In the RaaS business model, a central group develops ransomware, communicates with victims and runs back-end infrastructure, while partners, or affiliates, carry out intrusions and deploy the ransomware.<\/p>\n\n\n\n<p>\u201cThe RaaS is operated by the actor \u2018UNKN\u2019 (aka \u2018Unknown\u2019) who does not accept English-speaking partners and does not allow partners to target CIS countries, including Ukraine. While the known affiliates are Russian speaking, it is probable that some of the operators may not physically reside in Russia. Notably, following the Colonial Pipeline incident, UNKN made an effort to restrict targeting of REvil affiliates, insisting on vetting targets prior to ransomware deployment.&nbsp;<\/p>\n\n\n\n<p>\u201cREvil took credit for the operation on the evening of July 4, claiming to have impacted over a million systems. They are asking US$70 million for a universal decryptor which could be used to unlock any system affected by this incident. This exorbitant demand is the largest on record. In private conversations, REvil has proactively decreased their demands, and they have been known to exaggerate the scope and impact of their intrusions. Furthermore, at this time, REvil has not leaked data from their intrusions, a scheme they often use to pressure victims into paying ransoms. As long as criminals can demand ransoms in the tens of millions of dollars, and are unlikely to face jail, this problem will continue to grow from bad to worse. These actors are well-funded and highly-motivated and only dramatic, collaborative action is going to turn back the tide.\u201d<\/p>\n\n\n\n<p>Matthew Sanders, Director of Security, LogRhythm, said: \u201cThis is unfortunately a major reminder that ransomware attacks continue to be an increasing threat to companies, critical infrastructure organizations and government agencies at all levels. This attack is especially dangerous because Kaseya is used by many Managed Service Providers that businesses trust to handle their IT functions such as endpoint inventory, patching and software deployment. With up to 1,500 possible businesses affected from the Kaseya ransomware attack, the impacts from the attack will be felt for months to come.\u00a0<\/p>\n\n\n\n<p>\u201cRecovering from a ransomware attack takes time, and a well-rehearsed incident response plan will prove invaluable should the worst happen. Aside from planning their response to a successful attack, organizations should keep their prevention and detection technologies top of mind by ensuring that they have the appropriate protective controls in place, as well as visibility into what is happening across their environment. A properly configured security monitoring solution that has full visibility into the environment with robust automated response capability would help organizations such as Kaseya identify malicious activity and thwart bad actors before ransomware can take hold.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT company Kaseya has been hit by a major ransomware attack and is working to resolve its aftermath. It is working with FireEye Mandiant to resolve the incident and to assess the manner and impact of the attack and identify and mitigate the vulnerability. A statement from the company said: \u201cKaseya\u2019s VSA\u202fproduct\u202fhas unfortunately\u202fbeen\u202fthe victim of [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":8126,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17,512,43,514],"tags":[217,2162,1088,2164,322,2163],"class_list":["post-8125","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-main-story-newsletter","category-top-stories","category-used","tag-fireeye","tag-kaseya","tag-nozomi-networks","tag-orange-cyberdefense","tag-ransomware","tag-team-cymru"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/8125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=8125"}],"version-history":[{"count":11,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/8125\/revisions"}],"predecessor-version":[{"id":8175,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/8125\/revisions\/8175"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/8126"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=8125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=8125"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=8125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}