Triple Threat: Insecure Economy, Cybercrime Recruitment and Insider Threats

So far in 2023, layoffs have resulted in tens of thousands of tech workers losing their jobs. And that’s just in tech. Across sectors, employees are feeling the ramifications of economic uncertainty. Ransomware attacks are continuing and growing more sophisticated. And it’s not only the attacks that are growing more sophisticated; so are cybercrime recruitment efforts. All the while, the cybersecurity skills gap persists for most organizations.

All of these factors have the potential to create a perfect storm in terms of insider risks. Here’s what you need to be doing to stay protected against them.

The cost of insider threats

A cyberattack precipitated by an individual who is employed by a company or has permission to access its networks or systems constitutes an insider threat. Insider threats can be malevolent or unintentional, and they might come from current or former employees, business partners, board members or consultants.

Insider threats are increasingly prevalent and more costly for organizations. According to the Ponemon Institute’s 2022 Cost of Insider Threats report, insider threat incidents have risen 44% over the past two years, with costs per incident up more than a third, to $15.38 million.

Employees who are laid off but still have access to inside resources can pose a risk; sometimes it’s unintentional, but sometimes it’s retaliatory. Bad actors are well aware of this and are bound to start trying to recruit from these ranks.

Cybercrime recruitment efforts are rampant

Advertisement. Scroll to continue reading.

As cybercrime becomes more organized and sophisticated, we’re seeing these syndicates behave much like legitimate businesses. They have organized departments, job roles and hierarchies, as well as recruitment strategies.

When the Conti ransomware group’s files were leaked in early 2022, it became clear that the organization was functioning very much like any other business. There was even a human resources lead and a recruitment director on the payroll. Also, we’ve observed evidence of bad actors actively seeking insider assistance for their goals, using phone calls, social media and email.

More recently, an international bust of the Russian-linked group behind Doppelpaymer

found that recruitment was a key part of the group’s strategy. The group was even offering paid vacation and requested references to verify past cybercrimes.

And on the Dark Web, cybercrime syndicates are ramping up their efforts, offering competitive salaries and benefits. Some jobs paid $20,000 per month, and some groups offer PTO, paid sick leave, bonuses and employee referral programs. Roles vary from full-time and part-time jobs to traineeships and partnerships.

How to stay vigilant and protected

To start addressing insider threats, ask these questions:

  • Are users trying to access files that they shouldn’t?
  • Are there attempts to move or copy confidential content?
  • Do you notice users logging on during non-business hours?
  • Can you create a baseline of regular activity carried out by suspicious users?
  • Can you mark user behaviors that deviate from accepted norms as alerts?
  • Are analytics tools receiving database logs?
  • Are there any automated responses in place to revoke access and stop data loss if data is compromised?

There is no quick fix to solve the insider threat problem. At a time when many businesses are struggling with visibility issues brought on by digital transformation and vendor sprawl, what’s needed is planning, using and reusing technologies as well as having a comprehensive perspective across your network. Reducing the risk associated with insider threats requires a multifaceted approach.

Employees should be trained to recognize and report suspicious activities. This should be part of everyone’s ongoing cyber hygiene training and must be conducted regularly, rather than treated as a one-and-done type of thing. This should go without saying, but any employee who is receiving special access to sensitive digital resources should undergo a background check.

From a technological standpoint, organizations and their security leaders should:

  • Use deception technology to quickly create a fake network that automatically deploys decoys and lures that are indistinguishable from the traffic and resources used in the real network. This is one of the most effective ways to address insider threats.
  • Segment the network to confine activity to certain areas. A zero trust approach may be particularly useful for operations that require greater discretion.
  • Encrypt data at all points: at rest, in use and in transit. Buy tools that can quickly and efficiently decrypt data.
  • Use configuration management tools to examine and rapidly spot devices that are not configured correctly.
  • Use solutions that can track user activity and behavior, including any infractions of policies, and use machine learning to spot anomalous behavior.
  • Use file tracking tools and keep an eye on data access and file transfers.
  • Enhance identity and access management (IAM), using multi-factor authentication (MFA), for example.

Defeating insider threats

The economic downturn and its subsequent layoffs did nothing to strengthen organizations’ security posture. On the contrary, the skills gap has only widened during a time of increasingly sophisticated cyber-attacks, both from without and from within. Defeating insider threats involves asking the right questions and finding the right solutions. Use the information outlined above to create or strengthen your defenses and keep your digital assets safe from insider attack.

https://www.securityweek.com/triple-threat-insecure-economy-cybercrime-recruitment-and-insider-threats/




US Offering $10M Reward for Russian Man Charged With Ransomware Attacks

Mikhail Pavlovich Matveev, a 30-year-old Russian national, has been charged by the US Justice Department for his alleged role in numerous ransomware attacks, including ones targeting critical infrastructure. 

Matveev — known online as Wazawaka, m1x, Boriselcin, and Uhodiransomwar — has been charged with conspiring to transmit ransom demands, conspiring to damage protected computers, and intentionally damaging protected computers.

He faces over 20 years in prison, but he is unlikely to be arrested and convicted any time soon considering that he is believed to be living in Russia. While law enforcement cooperation between Russia and the US seemed to be improving before the start of the Ukraine war, it’s unlikely that Russia will hand over any cybercriminals to the United States given their current relations. 

According to the US Justice Department, Matveev has been affiliated with several major ransomware operations, including LockBit, Hive and Babuk. He and other members of these operations allegedly targeted thousands of entities in the United States and elsewhere, including hospitals, schools, airlines, businesses, law enforcement, and other government organizations. 

The specific examples shared by authorities include the LockBit attack on a Passaic County (NJ) police department, a Hive attack on a healthcare organization in Mercer County (NJ), and a Babuk attack on the Washington DC Metropolitan Police Department. 

Prosecutors pointed out that the three ransomware operations in which Matveev was involved demanded as much as $400 million from their victims, and they are believed to have received up to $200 million. 

Matveev was revealed to be Wazawaka by Brian Krebs in early 2022, which the Russian confirmed shortly after. In August 2022, he gave an interview to The Record in which — using his real name — detailed his hacking activities. 

Advertisement. Scroll to continue reading.

In addition to the charges brought against him, Matveev has been added to the FBI’s Most Wanted list, and the Treasury Department announced sanctions against him. The Department of State announced that it’s prepared to award up to $10 million for information that leads to the man’s arrest.

The LockBit ransomware operation continues to be highly active, but Hive has been shut down by law enforcement. In the case of Babuk, its source code was leaked in 2021, which has led to the creation of several new ransomware families. 

The FBI described Matveev as one of the “developers/administrators behind the Babuk ransomware variant”.

Related: Russian Man Who Laundered Money for Ryuk Ransomware Gang Sentenced

Related: Russian National Arrested in Canada Over LockBit Ransomware Attacks

https://www.securityweek.com/us-offering-10m-reward-for-russian-man-charged-with-ransomware-attacks/




La 11a Cyber-Crime Conference si è conclusa tra applausi e apprezzamenti

Il grande successo registrato dalla Cyber Crime Conference, svoltasi l’11 e 12 maggio all’Auditorium della Tecnica di Roma, segna il ritorno alla tradizione del nostro storico evento sulle minacce informatiche.

Per gli oltre 1000 partecipanti è stata un’occasione unica per ascoltare specialisti di fama mondiale e confrontarsi con altri professionisti – tutti di altissimo livello – sulle questioni poste da un panorama di criminalità cyber in crescita apparentemente inarrestabile.

Organizzate per la prima volta insieme alle prestigiose associazioni CYBER 4.0 e SOCINT, le due giornate hanno visto il consueto alternarsi tra personalità pubbliche, rappresentanti accademici ed esponenti dell’IT Industry. Una collaudata formula tesa a restituire la complessità caratterizzante lo scenario di rischio e, di conseguenza, anche le strategie difensive che organizzazioni e istituzioni devono mettere in campo per contrastare attacchi informatici sempre più insidiosi.

Ecco cosa si sono detti

Moltissimi gli argomenti affrontati: dalle tradizionali esigenze di messa in sicurezza dei dati alle novità regolamentari, passando per gli scenari inediti del Cyber Warfare e arrivando a temi attualissimi quali la Quantum Security o le ultime sfide della Digital Forensics.

Tra le numerose figure istituzionali, il vertice della Cybercrime Division presso il Consiglio d’Europa (CoE) Alexander Seger, l’esponente dell’Autorità di Cybersicurezza Nazionale (ACN) Gianluca Galasso e lo specialista INTERPOL Dong Uk Kim hanno illustrato le odierne sfide normative e investigative alla luce delle norme internazionali di riferimento, tra cui l’atteso Trattato ONU sul cybercrime.

Foto: GIANLUCA GALASSO, Head of Operations Directorate and CSIRT Italia, National Cybersecurity Agency, Italy

Nell’appassionante tavola rotonda “The criminal justice action in Europe and beyond” Francesco Cajani, Jan Kerkhofs e Jana Ringwald, con la moderazione di Matteo Lucchetti, si sono poi confrontati su diversi casi di successo nella prosecuzione giudiziaria dei reati informatici transfrontalieri.

Foto: Tavola Rotonda Cyber-Crime Conference 2023

Presenti anche due rappresentanti dello Stato ucraino – Ivan Kalabashkin e Mykola Hovorukha – che hanno sintetizzato le attività sul fronte cyber tipiche della “guerra ibrida” condotta dalla Russia in Ucraina.

Foto: IVAN KALABASHKIN, Deputy Head of the Directorate, Security Service of Ukraine
Foto: MYKOLA HOVORUKHA, Head of Unit, War Crimes Department, Prosecutor General’s Office, Ukraine

La costante attenzione del pubblico e la soddisfazione espressa tanto dai relatori quanto dalle aziende partecipanti, che nell’Expo Area dedicata hanno potuto presentare le loro migliori soluzioni di sicurezza, nonché attivare nuove collaborazioni B2B, rappresentano la miglior conferma circa il buon esito dell’iniziativa.

Per tutti gli iscritti alla Cyber Crime Conference o alla newsletter di ICT Security Magazine, a breve saranno disponibili i materiali post-evento: foto, video, slides delle relazioni e molto altro.

Continuando sulla strada della formazione gratuita e della condivisione di esperienze, il prossimo appuntamento è il 25 e 26 ottobre al 21° Forum ICT Security, immancabile incontro autunnale dedicato alla sicurezza informatica a tutto tondo.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/la-11a-cyber-crime-conference-si-e-conclusa-tra-applausi-e-apprezzamenti/




PharMerica Discloses Data Breach Impacting 5.8 Million Individuals

National pharmacy network PharMerica last week started sending out notification letters to more than 5.8 million individuals to disclose a data breach that occurred in March.

Owned by BrightSpring Health, a provider of home and community-based health services, PharMerica operates over 2,500 facilities across the US and offers more than 3,100 pharmacy and healthcare programs.

On Friday, PharMerica informed the Maine Attorney General’s Office that the personal information of more than 5.8 million individuals was compromised after an unauthorized party accessed its computer systems in March.

The data breach, the company says in notification letters sent to the impacted individuals, occurred between March 12 and March 13.

Personal information compromised during the incident includes names, addresses, birth dates, Social Security numbers, health insurance, and medication information.

In some cases, the compromised information belongs to deceased individuals, and PharMerica encourages executors or surviving spouses to contact the national credit reporting agencies to notify them of the situation.

PharMerica’s letter does not provide details on the type of cyberattack that it suffered, but it appears that the Money Message ransomware group is responsible for the incident.

Advertisement. Scroll to continue reading.

In April, the group started leaking personally identifiable information (PII) and protected health information (PHI) allegedly stolen from PharMerica.

Last month, the ransomware operators told DataBreaches.net that they encrypted almost the entire PharMerica infrastructure and that they had engaged in negotiations with the company.

SecurityWeek has emailed BrightSpring Health for confirmation on the ransomware group’s claims and will update this article as soon as a reply arrives.

Related: 1 Million Impacted by Data Breach at NextGen Healthcare

Related: T-Mobile Says Personal Information Stolen in New Data Breach

Related: Capita Confirms Data Breach After Ransomware Group Offers to Sell Stolen Information

https://www.securityweek.com/pharmerica-discloses-data-breach-impacting-5-8-million-individuals/




Philadelphia Inquirer Hit by Cyberattack Causing Newspaper’s Largest Disruption in Decades

The Philadelphia Inquirer experienced the most significant disruption to its operations in 27 years due to what the newspaper calls a cyberattack.

The company was working to restore print operations after a cyber incursion that prevented the printing of the newspaper’s Sunday print edition, the Inquirer reported on its website.

The news operation’s website was still operational Sunday, although updates were slower than normal, the Inquirer reported.

Inquirer publisher Lisa Hughes said Sunday “we are currently unable to provide an exact time line” for full restoration of the paper’s systems.

“We appreciate everyone’s patience and understanding as we work to fully restore systems and complete this investigation as soon as possible,” Hughes said in an email responding to questions from the paper’s newsroom.

The attack was first detected when employees on Saturday morning found the newspaper’s content-management system was not working.

The Inquirer “discovered anomalous activity on select computer systems and immediately took those systems off-line,” Hughes said.

Advertisement. Scroll to continue reading.

The cyberattack has caused the largest disruption to publication of Pennsylvania’s largest news organization since a massive blizzard in January 1996, the Inquirer reported.

The cyberattack precedes a mayoral primary election scheduled for Tuesday. Hughes said the operational disruption would not affect news coverage of the election, although journalists would be unable to use the newsroom on election night.

Hughes said other Inquirer employees will not be allowed to use offices through at least Tuesday, and the company was looking into coworking arrangements for Tuesday, the Inquirer reported.

An investigation was ongoing into the extent and specific targets of the attack, and the company has contacted the FBI, Hughes said.

The FBI in Philadelphia declined to comment in response to questions from Inquirer journalists, the newspaper reported.

https://www.securityweek.com/philadelphia-inquirer-hit-by-cyberattack-causing-newspapers-largest-disruption-in-decades/




Spain Arrests Hackers in Crackdown on Major Criminal Organization

Spanish authorities this week announced the arrest of 40 individuals for their roles in a criminal organization that performed bank fraud, document forgery, identity theft, and money laundering.

Two of the individuals, the authorities say, were in charge of carrying out online bank fraud, while 15 others were involved in other illegal activities.

Called ‘Trinitarians’, the criminal organization employed phishing and smishing (SMS phishing) to distribute malicious links that took unsuspecting victims to fake bank login pages where they were prompted to enter their credentials.

Using hacking tools purchased from cybercriminals, the gang monitored in real time the credentials their victims entered on the fake pages. They used the obtained login information to access the victims’ real accounts and request loans or link the victim’s cards to virtual wallets on attacker-controlled phones.

The gang also bought cryptocurrency coupons that were then exchanged in a wallet functioning as a ‘common box’ for the organization, and contracted point-of-sale (PoS) devices in the name of fake companies to make false purchases.

According to the authorities, the group also relied on an extensive network of money mules that received money transfers to their accounts and withdrew cash at ATMs.

Some of the proceeds were sent to bank accounts abroad and used to purchase real estate in the Dominican Republic, the Spanish authorities say.

Advertisement. Scroll to continue reading.

The gang raked in more than €700,000 (~$760,000) from the schemes and used proceeds to pay for lawyer fees for gang members in prison, buy drugs to resell, and acquire weapons.

During the takedown operation, the Spanish police made 13 house searches in Madrid, Guadalajara, and Seville, and seized computer equipment, lock picks and other instruments for opening doors, padlocks, cash, and documents describing the group’s structure.

Related: Spanish, US Authorities Dismantle Cybercrime Ring That Defrauded Victims of $5.3 Million

Related: US Disrupts Russia’s Sophisticated ‘Snake’ Cyberespionage Malware

Related: Australia Dismantles BEC Group That Laundered $1.7 Million

https://www.securityweek.com/spain-arrests-hackers-in-crackdown-on-major-criminal-organization/




Former Ubiquiti Employee Who Posed as Hacker Sentenced to Prison

Nickolas Sharp, the former Ubiquiti employee who posed as a hacker and attempted to extort nearly $2 million from the company, has been sentenced to six years in prison.

In addition to the prison sentence, Sharp will be under supervised release for three years and will have to pay more than $1.5 million in restitution. 

Sharp was employed by the US-based communications and IoT device maker between August 2018 and April 2021. 

According to authorities, in December 2020, he abused his access to Ubiquiti systems to download gigabytes of confidential information while interviewing for another company. 

The next month, while part of a team tasked with responding to the incident, the man sent a ransom note to the company, claiming to be a hacker who had breached the company’s systems. 

He instructed Ubiquiti to pay 50 bitcoin (at the time worth roughly $1.9 million) to prevent the data from getting leaked. The company refused to pay up and Sharp made public some of the stolen files. 

In the meantime, the FBI traced the hacking activities back to Sharp and executed a search warrant at his residence in Portland, Oregon. During the search, which resulted in several devices being seized, the man lied to agents.

Advertisement. Scroll to continue reading.

Days after, Sharp, claiming to be a whistleblower working for Ubiquiti, contacted investigative journalist Brian Krebs and provided false information, claiming that a hacker had gained root administrator access to Ubiquiti’s AWS accounts. This led to the publication of several news articles, which resulted in Ubiquiti’s shares falling roughly 20%, representing losses of more than $4 billion. 

Charges against Sharp were announced in late 2021 and he pleaded guilty in February 2023. 

It’s worth noting that Ubiquity is not actually named in the indictment or the press releases published by the DoJ throughout this case.

“Nickolas Sharp was paid close to a quarter million dollars a year to help keep his employer safe,” said Damian Williams, the US Attorney for the Southern District of New York.

“He abused that trust by stealing a massive amount of sensitive data, attempting to implicate innocent employees in his attack, extorting his employer for ransom, obstructing law enforcement, and spreading false news stories that harmed the company and anyone who invested into the company.  Sharp now faces serious penalties for his callous crimes,” Williams added,

Related: Russian Man Who Laundered Money for Ryuk Ransomware Gang Sentenced

Related: Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach Cover-Up

https://www.securityweek.com/former-ubiquiti-employee-who-posed-as-hacker-sentenced-to-prison/




ECCC, apre il centro di competenze cyber dell’Ue. R. Viola (DG Connect): “La cybersicurezza la chiave per garantire una Europa digitale”

Prende ufficialmente il via il centro europeo di competenza in materia di cibersicurezza (ECCC), il centro con cui l’Unione mira a sostenere l’innovazione e la politica industriale in materia di cibersicurezza, nonché a sviluppare e coordinare i progetti di sicurezza informatica dell’UE. Oggi è stata inaugurata la sua nuova sede a Bucarest, in Romania, presso il Campus Building dell’Università Politecnica.

Il Centro mira ad aumentare le capacità, l’innovazione e la competitività della sicurezza informatica in Europa, lavorando con una rete di Centri di coordinamento nazionali (NCC) e la comunità della sicurezza informatica in tutta l’UE. L’ECCC decide sui finanziamenti dell’UE per la sicurezza informatica nell’ambito dei programmi di lavoro DIGITAL Europe e Orizzonte Europa e gestisce progetti, riunendo risorse dall’UE, dagli Stati membri e da altri attori. Il centro ha recentemente adottato un’agenda per gli investimenti strategici sulla sicurezza informatica e aprirà presto nuovi bandi per i progetti dell’UE sulla sicurezza informatica.

Roberto Viola: “La cybersicurezza è la chiave per garantire una Europa digitale”

“Il Centro di Competenza Europeo per la Cybersecurity (ECCC) garantirà il funzionamento del Cyber Shield a livello dell’UE”, ha affermato Roberto Viola, Direttore Generale del Dipartimento della Commissione Europea per le Reti di Comunicazione, i Contenuti e la Tecnologia (DG CNECT).

“È stato un lungo percorso, inaugurato più di quattro anni fa durante la Presidenza rumena del Consiglio dell’Unione europea, ha detto Viola. “Il sentimento di instabilità che stiamo affrontando solleva la questione di quanto siamo adeguati e preparati di fronte a queste sfide di sicurezza. Per questo motivo, in queste circostanze, la proposta della Commissione è stata quella di creare una rete di cooperazione tra i centri, fornendo uno scudo di sicurezza che continui a monitorare l’ambiente, al fine di identificare quelle debolezze in modo che possiamo, in qualsiasi momento, identificare e combattere un attacco, se si verifica, per proteggere i nostri beni e i cittadini. Il Centro europeo guiderà questo sviluppo. È uno sforzo che comporterà miliardi di euro di finanziamenti. Il Centro sarà responsabile dell’acquisizione, dell’operatività e della rete di questi centri operativi individuali, ha aggiunto il Dg.

“Il centro garantirà che questo scudo di protezione cibernetica funzioni in tutta Europa, e non si tratta solo di avere centri operativi, ma anche di avere squadre di intervento tecnico rapido che possono intervenire ovunque in Europa, che possono rilevare e proteggere durante un attacco cibernetico, analizzarlo e quindi, sulla base delle conclusioni, migliorare i nostri sistemi, capire cosa è stato fatto, dove sono stati commessi errori e come le cose possono essere migliorate per il futuro. La creazione di questa squadra di esperti in grado di reagire rapidamente farà parte della missione del centro, lavorando con esperti provenienti da tutta Europa. Questo campus, ha concluso Viola, diventerà un punto di riferimento per la cybersecurity non solo a livello europeo ma anche a livello globale, perché l’Europa è un pilastro di stabilità a livello globale dal punto di vista della cybersecurity”.

https://www.key4biz.it/eccc-apre-il-centro-di-competenze-cyber-dellue-roberto-viola-dg-connect-la-cybersicurezza-e-la-chiave-per-garantire-una-europa-digitale/445421/




US Announces Takedown of Card-Checking Service, Charges Against Russian Operator

The US Department of Justice this week announced the takedown of card-checking platform ‘Try2Check’ and charges against its Russian administrator.

The individual, Denis Gennadievich Kulkov, 43, created the platform in 2005 and operated it until the takedown. The US is offering a $10 million reward for information leading to his capture.

According to the indictment (PDF), Try2Check was created as a service for cybercriminals who sold and purchased stolen credit cards in bulk, allowing them to check whether the cards were valid and active. Cybercriminals then used the results to advertise the valid credit card numbers they had for sale.

Authorities estimate that the platform was processing tens of millions of card numbers on a yearly basis, enabling the illicit credit card trade through major card shops. The platform charged $0.20 per check, in Bitcoin.

Also known as Try2Services, Try2Check relied on unauthorized access to a US-based payment processing company’s servers to perform the checks, the indictment alleges.

The US took the card-checking platform’s websites offline this week, working together with German and Austrian authorities.

According to the indictment, Kulkov made over $18 million in Bitcoin, which he used to purchase luxury items, including a Ferrari. However, it is unclear how much he made from the scheme, as he also received proceeds through other payment systems.

Advertisement. Scroll to continue reading.

Kulkov was charged with access device fraud, computer intrusion, and money laundering. If found guilty, he faces up to 20 years in prison.

Related: Cybercrime Marketplace Leaks Over 2.1 Million Payment Cards

Related:Russian Operator of Cybercrime Marketplace Indicted in US

Related: Underground Carding Marketplace Joker’s Stash Announces Shutdown

https://www.securityweek.com/us-announces-takedown-of-card-checking-service-charges-against-russian-operator/




FIN7 Hackers Caught Exploiting Recent Veeam Vulnerability

Russian cybercrime group FIN7 has been observed exploiting unpatched Veeam Backup & Replication instances in recent attacks, cybersecurity company WithSecure reports.

Around since at least 2015 and also referred to as Anunak, and Carbanak, FIN7 is a financially motivated group mainly focused on credit card information theft. Security researchers believe there are numerous sub-groups operating under the FIN7 umbrella.

Over the past years, some of the threat actors overlapping with FIN7 operations were seen transitioning to ransomware, including REvil, DarkSide, BlackMatter, Alphv, and Black Basta.

At the end of March 2023, WithSecure caught FIN7 attacks that exploited internet-facing servers running Veeam Backup & Replication software to execute payloads on the compromised environment.

The cybersecurity firm observed a Veeam Backup process executing a shell command to download and execute a PowerShell script that turned out to be the Powertrash in-memory dropper known to be used by FIN7.

The dropper was used to drop Diceloader, a backdoor also known as Lizar, which enables attackers to perform various post-exploitation operations, and which has been linked to FIN7 before.

“The exact method used by the threat actor to invoke the initial shell commands remains unknown but was likely achieved through a recently patched Veeam Backup & Replication vulnerability, CVE-2023-27532, which can provide unauthenticated access to a Veeam Backup & Replication instance,” WithSecure says.

CVE-2023-27532 (CVSS score of 7.5) was disclosed and patched in early March. Roughly two weeks later, proof-of-concept (PoC) exploitation code targeting the vulnerability was released publicly.

According to Veeam, successful exploitation of the bug allows an attacker to obtain encrypted credentials that are stored in the configuration database. However, penetration testing firm Horizon3.ai, which released the PoC, says that the flaw allows attackers to obtain cleartext credentials.

As part of the observed FIN7 attacks, WithSecure identified suspicious activity targeting the exploited Veeam backup instances days before payloads were dropped, likely to probe and identify vulnerable servers.

The threat actor was seen performing network reconnaissance, stealing information from the Veeam backup database, exfiltrating stored credentials, achieving persistence for the Diceloader backdoor, and moving laterally using the stolen credentials.

“WithSecure Intelligence has so far identified two instances of such attacks conducted by FIN7. As the initial activity across both instances were initiated from the same public IP address on the same day, it is likely that these incidents were part of a larger campaign. However, given the probable rarity of Veeam backup servers with TCP port 9401 publicly exposed, we believe the scope of this attack is limited,” WithSecure notes.

CVE-2023-27532 was addressed with the release of Veeam Backup & Replication versions 12 (build 12.0.0.1420 P20230223) and 11a (build 11.0.1.1261 P20230227), which organizations need to install on the Veeam Backup & Replication server.

Vulnerabilities in Veeam’s product have been exploited in previous attacks and organizations are advised to update their Backup & Replication instances as soon as possible.

Related:CISA Warns Veeam Backup & Replication Vulnerabilities Exploited in Attacks

Related: New ‘Domino’ Malware Linked to FIN7 Group, Ex-Conti Members

Related:FIN7 Cybercrime Operation Continues to Evolve Despite Arrests

https://www.securityweek.com/fin7-hackers-caught-exploiting-recent-veeam-vulnerability/