ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Akira ransomware attackers are wiping NAS and tape backups

highRansomwareimportance 60CVE-2023-20269

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20269
Unauthenticated Brute-Force VPN Access in Cisco ASA and Firepower Threat Defense

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an authentication weakness (CWE-288) that allows an unauthenticated, remote attacker to conduct brute-force attacks against the SSL VPN login interface to guess valid username and password combinations, and to establish a clientless SSL VPN session as an unauthorized user under certain configurations. The attack is triggered simply by sending repeated or crafted authentication attempts to an internet-facing remote-access VPN endpoint, and vendor guidance centers on the group-lock and vpn-simultaneous-logins settings. A successful attempt gives the attacker VPN access, typically allowing them to reach the internal network as a legitimate user, which makes the flaw a common foothold for follow-on attacks including ransomware. Any organization operating a Cisco ASA or FTD with remote-access/clientless SSL VPN exposed to the internet is affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-13 with known ransomware use, and EPSS assigns it a 25.6% probability of exploitation within 30 days (98th percentile).

Do: Apply the mitigations in the Cisco advisory: configure group-lock and per-user vpn-simultaneous-logins restrictions as directed, and update ASA/FTD to the fixed releases listed there; if the device is end-of-support/unsupported, discontinue or isolate it. Prioritize internet-facing VPN concentrators given the KEV listing and known ransomware use, and review VPN logs for unusual failed-login bursts and unexpected clientless SSL VPN sessions.

9.125% KEV ransomware
  • Cisco Adaptive Security Appliance (ASA)
  • Cisco Firepower Threat Defense (FTD)
masshundreds of thousands of internet-exposed ASA/FTD VPN devices
Full article316 words · extracted from helpnetsecurity.com · click to collapse

“The Akira ransomware malware, which was first detected in Finland in June 2023, has been particularly active at the end of the year,” the Finnish National Cybersecurity Center (NCSC-FI) has shared on Wednesday.

NCSC-FI has received 12 reports of Akira ransomware hitting Finnish organizations in 2023, and three of the attacks happened during Christmas vacations.

“Of the ransomware malware cases reported to the Cybersecurity Center in December, six out of seven involved Akira family malware,” they added.

Finland Akira ransomware

Attackers’ tactics

The attackers pinpointed and targeted organizations with vulnerable internet-facing Cisco ASA or FTD devices and found and wiped target organizations’ backups before deploying the ransomware.

They got in either by using leaked credentials or identifying them via a brute force attack by exploiting CVE-2023-20269, a vulnerability affecting Cisco firewalls that’s due to improper separation of authentication, authorization, and accounting between the remote access VPN feature and the HTTPS management and site-to-site VPN features.

Apparently, those accounts weren’t additionally secured with multi-factor authentication.

Once in, they scanned the network, deleted backups and encrypted physical and virtual servers.

“In all cases, careful efforts have been made to destroy the backups, and the attacker makes an effort to achieve this,” the agency noted.

“NAS (network-attached storage) servers that are often used for backups on the network have been hacked and wiped, as have automatic tape backup devices, and in almost every case we know of, all backups have been lost.”

Recommendations

The NCSC-FI emphasizes the importance of implementing MFA to protect login credentials and upgrading Cisco devices to the available fixed versions.

They also recommend creating offline backups and storing them at different physical locations.

“For the most important backups, it would be advisable to follow the 3-2-1 rule. That is, keep at least three backups in two different places and keep one of these copies completely off the network,” NCSC-FI information security expert Olli Hönö pointed out.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/01/12/finland-akira-ransomware/