Multiple ransomware gangs pounce on 'PrintNightmare' vulnerability
Full article641 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
For the second time in a week, security researchers have warned that extortionists exploited the critical flaw.
The so-called PrintNightmare vulnerability in Microsoft software is turning into a dream for ransomware gangs.
For the second time this week, security researchers have warned that extortionists exploited the critical flaw in an attempt to lock files and shake down victims. It shows how, more than a month after Microsoft disclosed the bug and urged users to update their software, a new round of exploitation is under way against vulnerable organizations.
A ransomware group dubbed Vice Society recently seized on the PrintNightmare bug to move through an unnamed victim’s network and attempt to steal sensitive data, Talos, Cisco’s threat intelligence unit, said Thursday. A day earlier, cybersecurity firm CrowdStrike said that hackers using another type of ransomware had tried to use PrintNightmare to infect victims in South Korea. Neither Talos nor CrowdStrike named the targeted organizations.
The PrintNightmare vulnerability affects how Windows’ Print Spooler manages interactions between computers and printers. The severity of the vulnerability forced Microsoft to change the default settings on the software to make them more secure. Given how ubiquitous the software is in corporate environments, the remote code execution flaw is a boon for ransomware gangs.
“PrintNightmare has been useful to ransomware groups because, despite Microsoft advising against it, many organizations use their Active Directory controller as a print server and AD access is critical to most modern ransomware attacks,” said Allan Liska, an intelligence analyst at the threat intelligence company Recorded Future.
Vice Society, which emerged earlier this year, has previously claimed responsibility for ransomware attacks on school districts and health care systems, including an incident in May that hindered non-urgent care at multiple hospitals in New Zealand. The Magniber ransomware used in the incident flagged by CrowdStrike has been around since 2017 and has typically featured in intrusions in the Asia Pacific.
The PrintNightmare situation mirrors that of another set of critical bugs in Microsoft Exchange Server software revealed in March.
In both cases, a dire vulnerability was revealed, some organizations were slow to patch their software despite exploit code being publicly available and eventually ransomware gangs pounced on the bugs. And in both cases, the U.S. Cybersecurity and Infrastructure Security Agency issued emergency directives requiring civilian agencies to update their software because of the “unacceptable risk” the vulnerabilities posed to federal networks.
“Multiple, distinct threat actors view this vulnerability as attractive to use during their attacks,” Talos researchers said, meaning that the vulnerability could “continue to see more widespread adoption and incorporation by various adversaries moving forward.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/printnightmare-microsoft-ransomware/