Ransomware Attack Via MSP Locks Customers Out of Systems

  /     /     /  
Publicated : 23/11/2024   Category : security


Ransomware Attack Via MSP Locks Customers Out of Systems


Vulnerable plugin for a remote management tool gave attackers a way to encrypt systems belonging to all customers of a US-based MSP.



An attacker this week simultaneously encrypted endpoint systems and servers belonging to all customers of a US-based managed service provider by exploiting a vulnerable plugin for a remote monitoring and management tool used by the MSP.
The attack resulted in some 1,500 to 2,000 systems belonging to the MSPs clients getting cryptolocked and the MSP itself facing a $2.6 million ransom demand.
Discussions this week on an MSP forum on Reddit over what appears to be the same — or at least similar — incident suggest considerable anxiety within the community over such attacks, with a few describing them as a nightmare scenario.
From the MSPs standpoint, the tool they use to manage everything was just used against them to inflict damage on customers, says Chris Bisnett, chief architect at Huntress Labs. Everyone is looking at the attack and saying, This could have been me.
Huntress provides managed detection and response services to the MSP that was attacked and to numerous others like it. Bisnett says one of the companys MSP clients reported the ransomware attack on Monday. After an initial investigation showed that the MSPs systems itself had not been compromised, researchers from Huntress did some further digging and eventually linked the attack to a vulnerable plugin for a remote management tool from Kaseya.
Many MSPs use Kaseyas VSA RMM tool to remotely monitor and manage client systems and servers. The vulnerable plugin for Kaseya that was exploited in the MSP attack itself was from ConnectWise and is used to manage support tickets raised in Kaseya, Bisnett says.
The vulnerability basically gave the attackers a way to run remote commands that allowed them complete access to the Kaseya VSA database. They were able to task the RMM tool as if they were an administrator at the MSP, Bisnett says. They said, Take this executable and put it out on every system the MSP is managing.
In this case, the executable was Gandcrab, a widely distributed ransomware tool that has been used in numerous previous attacks. All customer systems that the MSP was managing via the Kaseya RMM tool were encrypted simultaneously, locking users out of them.
A poster on
Reddit
 on Tuesday described a similar incident impacting a local MSP in which all client systems were encrypted. Its unclear, however, whether the incident mentioned in the Reddit report is the same one reported by the Huntress MSP customer.
Previously, attackers have installed cryptomining tools on business systems and stolen data from organizations in various sectors by gaining access to their networks via MSP connections. There have also been incidents where MSPs have reported one or two clients getting hit with ransomware. But this was extra alarming because all customer systems were encrypted at the same time, Bisnett notes.
Rising Concerns
Attacks on MSPs are a growing concern. Recently, threat actors, some sponsored by nation states, have begun targeting MSPs in an attempt to get to the networks of their clients. APT10, a threat group believed to be working for the Chinese Ministry of State Securitys Tianjin State Security Bureau, is one of the best-known operations targeting MSPs. For the past few years, the group has been conducting a broad cyberespionage operation called
Cloud Hopper
to steal data from organizations in banking, manufacturing, consumer electronics, and numerous other sectors by attacking their MSPs.
In fact, concerns over such attacks are so high that the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security 
scheduled to brief
MSPs on Chinese malicious activity later this month.
The vulnerability that the threat actor exploited in the latest attack exists in ManagedITSync, a ConnectWise plugin for Kaseya VSA. A security researcher from Australia first reported the vulnerability in November 2017 and posted details, along with proof of concept code, on 
GitHub
.
ConnectWise issued an update addressing the issue sometime later, but for some reason the bug and the update patching it appear to have received little attention until now, Bisnett says. The bug was assigned a formal
CVE
number only this week after Huntress Lab informed MITRE about the issue, he says. The CVE was backdated to 2017 to reflect the fact it was first reported at that time.
In a
note
that appears to have been posted six days ago and updated yesterday, Kaseya urged customers using the ConnectWise plugin for VSA to upgrade to the patched version immediately or, alternatively, to remove the plugin altogether.
This only impacts ConnectWise users who have the plugin installed on their on-premises VSA, the company said, adding that only a very small number of customers appear vulnerable to the threat.
We are lucky enough not to be directly in the path of this particular storm, says Joshua Liberman, president of Net Sciences, a New Mexico-based MSP. The only way well survive this as an industry, short of stopping the threat at its source, which is well beyond our scope, is to tighten our own defenses, share information with each other, and create an offensive defense posture, he says.
Related Content:
APT10 Indictments Show Expansion of MSP Targeting, Cloud Hopper Campaign
China-Based Threat Actor APT10 Ramps Up Cyber Espionage Activity
Stealthy New DDoS Attacks Target Internet Service Providers
8 Threats That Could Sink Your Company
 
 
 
Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industrys most knowledgeable IT security experts. Check out the
Interop agenda
here.
 

Last News

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security

▸ Website hacks happened during World Cup final. ◂
Discovered: 23/12/2024
Category: security

▸ Criminal Possession of Government-Grade Stealth Malware ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Ransomware Attack Via MSP Locks Customers Out of Systems