We all know that ransomware is very bad for our IT infrastructure and also bad for our money. But cyber criminals have various techniques to inject it into IT infrastructure of various companies as well as government infrastructure.
ransomware is a type of malware that prevents or restricts users from accessing their systems. By encrypting their files and demanding ransom payment for decryption key, paying ransom is the easiest and cheapest way to regain access to their files.
The cost can range from a few thousand dollars to millions of dollars depending on how cyber criminals set ransom according to an organization and its data, and the ransom to be paid should be in cryptocurrency like Bitcoin, Ethereum etc.
Ransomware attacks are all too common these days. Large companies in North America, Europe and Asia have fallen victim to it. Cyber criminals target any consumer or business, and victims come from all industries.
Generally, this type of attack exploits human, system, network, and software vulnerabilities to infect the victim’s device, which may be a computer, printer, smartphone, wearable, point-of-sale (POS) terminal, or a other electronic device may be .
The COVID-19 pandemic also contributed to the rise of ransomware. As companies quickly transitioned to remote work, gaps in their cyber defenses emerged. Cyber criminals have exploited these vulnerabilities to proliferate ransomware, resulting in a spate of ransomware attacks.
Breaking News – Ransomware entered corporate network via Mitel MiVoice VOIP
Lorenz ransomware exploited a vulnerability in a popular VoIP device to gain access to a victim’s corporate network.
Security researchers at Arctic Wolf Labs discovered this new tactic after observing significant overlap with tactics, techniques and procedures (TTPs) associated with ransomware attacks that exploited the CVE-2022-29499 first access bug, such as Crowdstrike reported in June.
Security researchers also revealed that the unnamed organization was hit by the Lorenz ransomware.
“Lorenz exploited CVE-2022-29499, a remote code execution vulnerability that affected the Mitel Service Appliance component of MiVoice Connect to obtain a reverse shell, and then used Chisel as a tunneling tool to in swing into the environment.”
After waiting almost a month after initial access, the group proceeded with lateral movement, data exfiltration via FileZilla, and encryption with BitLocker and Lorenz ransomware on ESXi systems.
Mitel Voice over IP (VoIP) products are deployed by organizations in critical sectors worldwide (including government agencies), with over 19,000 devices currently exposed to attacks over the Internet, according to security expert Kevin Beaumont.
Mitel addressed the vulnerability by releasing security patches in early June 2022 after releasing a fix script for affected MiVoice Connect versions in April.
The case underscores the need for organizations to gain visibility and control across their entire distributed attack surface, Arctic Wolf argued.
Continue reading
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.