ZeroHour
The Recordpublished ()ingested

CISA: Cuba ransomware group has stolen $60 million from at least 100 organizations

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1472
Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllers

CVE-2020-1472, widely known as "Zerologon," is an elevation-of-privilege flaw in how the Netlogon secure channel is established over the Netlogon Remote Protocol (MS-NRPC) on Microsoft domain controllers. An unauthenticated attacker with network reachability to a domain controller sends specially crafted Netlogon messages to establish a vulnerable secure channel and then runs a specially crafted application on the network to obtain domain administrator access. Successful exploitation yields domain administrator privileges, effectively full compromise of the Active Directory environment, and the flaw is known to be used in ransomware operations. Any organization running affected Windows Server versions (2008 through 20H2) as domain controllers is exposed, along with environments using Netlogon implementations from Samba and distributions or products from Fedora, openSUSE, Canonical (Ubuntu), Debian, Synology, and Oracle. Exploitation is highly active: a public Zerologon PoC/exploit is available, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Apply the vendor updates on all domain controllers and other affected systems immediately, following Microsoft's two-phase Netlogon secure channel guidance (the enforcement phase of the phased rollout began in Q1 2021). Audit Netlogon secure-channel connections and event logs for clients still using vulnerable connections before enabling full enforcement, and install updated packages for Samba and other Netlogon implementations from Fedora, openSUSE, Ubuntu, Debian, Synology, and Oracle. Given known ransomware use, prioritize patching any domain controller reachable from user networks, VPNs, or the internet.

5.599% KEV ransomware PoC
  • Microsoft Windows Server (when acting as a domain controller)
  • Samba (Netlogon secure channel implementation)
  • Fedora Project Fedora Linux
  • +5 more
massmillions of domain controllers worldwide (essentially every Active Directory domain), with hundreds of thousands of domain controllers/RPC endpoints…
CVE-2022-24521
Out-of-bounds Write Privilege Escalation in Microsoft Windows CLFS Driver

CVE-2022-24521 is an elevation-of-privilege flaw in the Windows Common Log File System (CLFS) driver, a kernel component, caused by an out-of-bounds write (CWE-787). A local attacker who already has limited privileges on an affected Windows machine can trigger the bug and gain elevated (SYSTEM/administrator) rights without any user interaction. Because the CLFS driver is part of the operating system, every user and service on an unpatched host is exposed to post-compromise escalation, which ransomware operators use to move from an initial foothold to full control. Affected products per the data include Windows 10 releases 1507, 1607, 1809, 1909, 20H2, 21H1, and 21H2, Windows 11 21H2, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 2008. The flaw was patched in Microsoft's April 2022 Patch Tuesday, added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-13, and is known to be used in ransomware campaigns, with public reporting tying exploitation to Cuba ransomware activity.

Do: Apply the April 2022 Microsoft security updates (Patch Tuesday, released April 12, 2022) to all affected Windows 10/11, Windows 7/8.1/RT 8.1, and Windows Server 2008 systems immediately, per the CISA KEV required action; note that Windows 7/8.1/RT 8.1 and Server 2008 may require Extended Security Updates to receive the fix. Because this is a local privilege escalation, prioritize hosts reachable for initial access, review endpoint telemetry for suspicious limited-user-to-SYSTEM activity, and watch for indicators associated with Cuba ransomware campaigns exploiting this flaw.

7.87% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7 all supported editions
  • +3 more
mass≈1 billion+ Windows devices (the CLFS driver ships in all supported Windows 10/11 and legacy client releases)
Full article541 words · extracted from therecord.media · click to collapse

The Cuba ransomware group has launched attacks against 100 organizations around the world and brought in $60 million between December 2021 and August 2022, according to a new advisory from the Cybersecurity and Infrastructure Security Agency (CISA) and FBI.

The two agencies also said there is no indication that the group is based in or has any connection to the Republic of Cuba.

The advisory follows a December 2021 release from the FBI that found the group earned at least $43.9 million from ransom payments after attacks on at least 49 entities in five critical infrastructure sectors.

CISA said that since the FBI flash report, the number of U.S. entities attacked by the Cuba ransomware group has doubled and the amount of ransoms demanded and paid has increased.

The group has continued to target the same five critical infrastructure sectors: financial services, government facilities, healthcare and public health, critical manufacturing, and information technology.

Cuba ransomware actors have demanded at least $145 million in payments over the last 9 months, according to CISA data. 

The notice also links the ransomware actors to people behind other malicious tools like the RomCom Remote Access Trojan and the Industrial Spy ransomware. 

Much of the advisory included information spotlighted by the FBI in December 2021, including the fact that the group distributes the Cuba ransomware through Hancitor — a loader known for dropping or executing stealers, such as Remote Access Trojans (RATs) and other types of ransomware, onto victims’ networks.

CISA cited a report from Palo Alto Networks that found Cuba ransomware actors typically exploit vulnerabilities like CVE-2022-24521 – a vulnerability affecting Windows Common Log File System Driver that CISA said in April was being exploited – and CVE-2020-1472, one of the most routinely exploited vulnerabilities in 2020

The Palo Alto Networks report added that the group used a variety of tools to evade detection, including a tool that “terminates security products.”

The group typically extorts victims by threatening to leak stolen data and since May 2022, has moved from marketing the stolen information on their own leak site to selling it on the Industrial Spy online market – a platform rife with stolen data. 

The group was previously implicated in a wide-ranging ransomware attack on the government of Montenegro that crippled the country for weeks in September.

The report comes on the same day that the group claimed to have attacked German media firm Landau Media. The company confirmed it had been attacked in a notice on its website, warning visitors not to engage with anything on the site. 

"We have been the victim of a targeted cyberattack. We do not know whether our customers' systems are also at risk from the cyberattack. We therefore ask you to be careful when using our online services and environments," the company said on Thursday.

"Unfortunately, our production systems are also partially affected. We are working on a solution as soon as possible!"

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-cuba-ransomware-group-has-stolen-60-million-from-at-least-100-organizations