Hackers are using developing countries for ransomware practice
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-29201 | JumpServer is an open source bastion host and an operation and maintenance security audit system. JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers could steal sensitive information from all hosts or manipulate the database. This vulnerability is fixed in v3.10.7. NVD description · AI analysis pending | 9.9 | 6% | PoC |
| — |
Full article416 words · extracted from arstechnica.com · click to collapse
Security teams would pick up on alerts about a pending attack, but the average user would only become aware of one when they were locked out of their computer system, said Hanah-Marie Darley, director of threat research from cyber security firm Darktrace.
A file, with the subject line !!!READ_ME_MEDUSA!!!.txt., would instruct the user to log on to the dark web and start ransom negotiation with the gang’s “customer service.” If victims refuse, the cyber attackers publish the stolen data.
Cyber security companies monitor the dark web for information and then set up “honeypots”—fake websites that mimic attractive targets—in developing nations to catch experimental attacks at an early stage.
When a group of cyber attackers this year began discussing a new vulnerability, named CVE-2024-29201, they “specifically targeted a few [exposed servers] in third world countries to test out how reliable the exploit was,” said Izrael from Armis, whose analysts were monitoring the gang’s conversations on the dark web.
Attacks on Armis’ honeypots 11 days later confirmed the suspicions: The gang only hit Southeast Asia, before using the techniques at a later stage more widely.
Sherrod DeGrippo, the director of threat intelligence strategy at Microsoft, however, said some cyber gangs were too “opportunistic” to test new attacks so methodically.
Rather, developing countries had experienced increased activity as hackers in poorer countries could buy cheap ransomware and stage their own small attacks, DeGrippo said.
Gangs such as Medusa had begun selling their inventions to less sophisticated hackers, said Darktrace director Darley. Those smaller-scale hackers often did not know how the tech works and used it against easier targets, she said.
Any attackers taking the time to “sandbox their techniques”—to experiment in relatively unguarded cyber zones in developing countries—were more sophisticated, she added.
Teresa Walsh, chief intelligence officer at global cyber threat intelligence body FS-ISAC, said gangs would work within the local environment to “perfect” attack methods, she said, and then “export” their schemes to countries where the same language might be spoken: Brazil to Portugal, for example.
The speed of digital adoption in Africa is “outpacing the development of robust cyber security measures, and general awareness of cyber threats is low,” said Brendan Kotze, cyber analyst at Performanta.
“Combined, this creates a worrying, widening gap in defenses cyber criminals are exploiting,” he added.
Ellesheva Kissin is a reporter at Banking Risk and Regulation, a service from FT Specialist.
© 2024 The Financial Times Ltd. All rights reserved. Not to be redistributed, copied, or modified in any way.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/04/hackers-are-carrying-out-ransomware-experiments-in-developing-countries/