ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

INC Ransom Claims Cyber

criticalRansomwareimportance 60CVE-2023-4966

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-4966
Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation.

Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts.

7.5100% KEV ransomware
  • Citrix NetScaler ADC and NetScaler Gateway
masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal…
Full article316 words · extracted from infosecurity-magazine.com · click to collapse

An infamous ransomware group has claimed to have compromised sensitive data from a children’s hospital in Liverpool, UK.

On November 28, INC Ransom posted on its data leak site that it has obtained large-scale data patient records, donor reports and procurement data for 2018-2024 from Alder Hey Children’s NHS Foundation Trust.

INC Ransom claim on its leak site. Source: Ransomware.live
INC Ransom claim on its leak site. Source: Ransomware.live

The Trust quickly acknowledged the claim and said in a November 28 statement: “We are aware that data has been published online and shared via social media that purports to have been obtained illegally from systems shared by Alder Hey and Liverpool Heart and Chest Hospital NHS Foundation Trust.”

Alder Hey staff members are working with the UK’s National Crime Agency (NCA) and other partners to verify the data and understand the impact of the alleged attack.

The organization said that its services are operating normally and patients should attend appointments as usual.

“We are taking this issue very seriously […] to secure our systems and take further steps in line with law enforcement advice as well as our statutory duties relating to patient data,” the Trust added.

This incident is not linked to the recent incident at Wirral University Teaching Hospitals, also around Liverpool.

Speaking to Infosecurity, Will Thomas, SANS Instructor and CTI researcher, said that while it is still unknown if the claim by INC Ransom is legitimate, a Citrix instance from Alder Hey NHS Foundation Trust’s IT systems has stopped responding.

He noted that the cyber defenders at Alder Hey have likely taken the Citrix instance down while they investigate.

He added that INC Ransom is known to use CitrixBleed (CVE-2023-4966), a critical software vulnerability found in 2023 in Citrix NetScaler ADC and NetScaler Gateway appliances. This vulnerability allows threat actors to bypass multifactor authentication (MFA) and hijack legitimate user sessions.

INC Ransom has targeted UK public organizations in the past.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/inc-ransom-cyberattack-uk-children/