new enterprise ransomware - sri lankan case studies · 2020. 9. 9. · case 01 year : 2019...

14
APNIC – FIRST Security 2 Track 01 Enterprise Ransomware: Sri Lankan Case Studies by TechCERT

Upload: others

Post on 11-Oct-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

APNIC – FIRST Security 2 Track 01

Enterprise Ransomware: Sri Lankan Case Studies

by TechCERT

Page 2: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

2

Kalana Guniyangoda

Lead Security Engineer – Digital Forensic Investigations

[email protected]

Who am I?

Page 3: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

3

Outline

Enterprise Ransomware

Case studies

Takeaways

Page 4: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

4

Enterprise Ransomware

Prior to 2018 it’s only a gullible user.

Cre

dit: Jo

hn

Klo

ssn

er,

jklo

ssn

er.

co

m

Page 5: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

5

Enterprise Ransomware

Prior to 2018

o It’s just one or two computers

o More user awareness sessions recommended

o Can become nasty with wormable vulnerability:

WannaCry

Page 6: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

6

Enterprise Ransomware

But after 2018…

o Starts with a sophisticated targeted attack on your network.

o Longer dwell time

o Infiltrate the network as much as possible

o Data exfiltration used to force victims into paying the ransom

Page 7: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

7

Case 01

Year : 2019 Ransomware: GandCrab Network : Critical network segment

Initial Access : RDP brute forcing

o Weak password o FW rule change exposed the server

Not in a Domain o Reuse password for a privileged account o Attacker jumped from server to server

Attack only lasted for two days

Page 8: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

8

Case 02

Year : 2020 Ransomware: Sodinokibi Network: IT Operations

Initial Access : Citrix VDI account compromise

WFH restrictions kicks in

Unclear how the passwords leak

Gain access to Domain Account

Used Mimikatz & Bloodhound

Lateral movement through RDP

Goal was to own Domain Controller

Page 9: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

9

Case 02 – Continued…

Domain Controller

o Used for network enumeration

o Had Internet connection

o Pushed a scheduled task to download and run ransomware

Dwell time : 5 days

Alerts from security controls

o No one noticed

Page 10: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

10

Case 03

Year : 2020 Ransomware: Sodinokibi Network : IT Operations

Initial Access : Web server compromise

o Development errors/ Lack of VA

o Network not segmented properly

Lateral Movement

o Use of ‘BlueKeep’ vulnerability

o AV server capability to deploy executable

Page 11: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

11

Case 03 – Continued…

Alerts from security control o Attacker created an account in DC

Weeks long IR battle ensues o Attacker switched to Living of the Land techniques

Persistence o Backdoor malware o Web Shells

Issues o Poor network segmentation o Internet access (even Domain Controller?)

Outcome o Attacker only able to execute on leaf nodes

Page 12: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

12

Takeaways…

Hackers are always probing your network

o Sooner or later they will find a way in

Get your security controls in line.

o Proper configuration is essential

o Do red team exercises and check effectiveness

o Consider the possibility of 24/7 monitoring

Conduct VA/PT

o Helps to identify loop holes

Network segmentation

o Idea is to stop lateral movement

Page 13: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

13

Takeaways…

Offline backups are a must

o Attackers actively search for backups and deletes

Security hardening for critical servers

o Internet access for DC?

o Remote administration service?

o Application whitelisting

o Privilege separation

o Patch management

Threat hunting/ Compromise assessment

o Your network already compromised?

Incident Response Plan

Page 14: New Enterprise Ransomware - Sri Lankan Case studies · 2020. 9. 9. · Case 01 Year : 2019 Ransomware: GandCrab Network : Critical network segment Initial Access : RDP brute forcing

Helping You Secure Your Information Assets