{"id":4529,"date":"2023-02-14T21:22:21","date_gmt":"2023-02-14T21:22:21","guid":{"rendered":"https:\/\/osintme.com\/?p=4529"},"modified":"2024-09-20T20:21:06","modified_gmt":"2024-09-20T20:21:06","slug":"ransomwary-february","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2023\/02\/14\/ransomwary-february\/","title":{"rendered":"Ransomwary February"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4529\" class=\"elementor elementor-4529\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6d78bd3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6d78bd3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-277de16\" data-id=\"277de16\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c1b09cf elementor-widget elementor-widget-text-editor\" data-id=\"c1b09cf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>&#8220;There are decades where nothing happens; and\u00a0there are weeks where decades happen&#8221;<\/em><\/p><p>&#8211; Lenin<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7875c53 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7875c53\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5cd16e0\" data-id=\"5cd16e0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8eeca55 elementor-widget elementor-widget-text-editor\" data-id=\"8eeca55\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>As unusual as it feels for me to post a bolshevik quote on my blog, I can&#8217;t think of a better phrase to sum up what a strange and busy month it has been (and we&#8217;re only half way there).<\/p><p>A lot has happened on the ransomware front so far in February, and I mean it, A LOT.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1d47659 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1d47659\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-953c6d7\" data-id=\"953c6d7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-684d969 elementor-widget elementor-widget-heading\" data-id=\"684d969\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">1. ESXiArgs ransomware<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-983bcce elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"983bcce\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-63cda10\" data-id=\"63cda10\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-91957ed elementor-widget elementor-widget-text-editor\" data-id=\"91957ed\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A two-year old vulnerability <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-21974\">CVE-2021-21974<\/a> was exploited on unpatched VMware ESXi servers.<\/p><p>CVE Mitre described it as follows: &#8220;A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution&#8221;.<\/p><p>Relying on unpatched software for <strong>OVER 2 YEARS<\/strong> when the relevant fix is easily available sounds incredible, yet these things happen all the time. To make this scenario even worse, several days well into this widely reported ransomware attack, <a href=\"https:\/\/www.rapid7.com\/blog\/post\/2023\/02\/09\/nearly-19-000-esxi-servers-still-vulnerable-to-cve-2021-21974\/\">Rapid 7 estimated<\/a> close to 19,000 vulnerable servers that still remain vulnerable.<\/p><p>Luckily, a recovery guide for VMware ESXi has been published by security researchers Enes Sonmez &amp; Ahmet Aykac from YoreGroup Tech Team. It can be accessed <a href=\"https:\/\/enes.dev\/\">here<\/a>.<\/p><p>Separately, CISA released their own recovery script on <a href=\"https:\/\/github.com\/cisagov\/ESXiArgs-Recover\/blob\/main\/recover.sh\">their GitHub page<\/a>.<\/p><p>Currently there are over 2,000 online, compromised VMware servers out there, with nearly half of them located in Germany and France. Majority of those belong to OVH SAS.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-78abb41 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"78abb41\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f1a1f07\" data-id=\"f1a1f07\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1e6d679 elementor-widget elementor-widget-text-editor\" data-id=\"1e6d679\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Affected servers can be found using this Shodan query:<\/p><p><a href=\"https:\/\/www.shodan.io\/search?query=http.title%3A%22how+to+restore+your+files%22\">http.title:&#8221;how to restore your files&#8221;<\/a><\/p><p>&#8230; or try out <a href=\"https:\/\/search.censys.io\/search?resource=hosts&amp;virtual_hosts=EXCLUDE&amp;q=%28%22how+to+restore+your+files%22%29+and+services.software.product%3D%60VMware+ESXi+Server%60\">Censys and their search<\/a> (results vary slightly from Shodan).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4dc2391 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4dc2391\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-81a58b0\" data-id=\"81a58b0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-80acf1a elementor-widget elementor-widget-image\" data-id=\"80acf1a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ESXiArgs-ransomware-Osint.png?ssl=1\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"ESXiArgs ransomware Osint\" data-elementor-lightbox-description=\"ESXiArgs ransomware Osint\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NDUzMSwidXJsIjoiaHR0cHM6XC9cL29zaW50bWUuY29tXC93cC1jb250ZW50XC91cGxvYWRzXC8yMDIzXC8wMlwvRVNYaUFyZ3MtcmFuc29td2FyZS1Pc2ludC5wbmcifQ%3D%3D\">\n\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"506\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ESXiArgs-ransomware-Osint.png?fit=1024%2C506&amp;ssl=1\" class=\"attachment-large size-large wp-image-4531\" alt=\"ESXiArgs ransomware Osint\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ESXiArgs-ransomware-Osint.png?w=1118&amp;ssl=1 1118w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ESXiArgs-ransomware-Osint.png?resize=300%2C148&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ESXiArgs-ransomware-Osint.png?resize=1024%2C506&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ESXiArgs-ransomware-Osint.png?resize=768%2C379&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-68b1d55 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"68b1d55\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4594bc3\" data-id=\"4594bc3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-708cc35 elementor-widget elementor-widget-heading\" data-id=\"708cc35\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">2. LockBit and Royal Mail<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-dfe4064 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"dfe4064\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0fd8398\" data-id=\"0fd8398\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8f1ff48 elementor-widget elementor-widget-text-editor\" data-id=\"8f1ff48\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The LockBit ransomware group officially claimed responsibility for the late January attack on Royal Mail and set the deadline for 9th February, threatening to release the UK&#8217;s postal service&#8217;s stolen data if the ransom demand was not met.<\/p><p>As of today, 14th February, LockBit claims to have &#8220;released all data&#8221;. However, no link to the alleged records was released and Royal Mail claimed that the attackers did not get their hands on any personal data belonging to their customers.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f3b04b1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f3b04b1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2b796af\" data-id=\"2b796af\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5af4afe elementor-widget elementor-widget-image\" data-id=\"5af4afe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-osint.png?ssl=1\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"lockbit royal mail osint\" data-elementor-lightbox-description=\"lockbit royal mail osint\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NDUzOCwidXJsIjoiaHR0cHM6XC9cL29zaW50bWUuY29tXC93cC1jb250ZW50XC91cGxvYWRzXC8yMDIzXC8wMlwvbG9ja2JpdC1yb3lhbC1tYWlsLW9zaW50LnBuZyJ9\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"768\" height=\"540\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-osint.png?fit=768%2C540&amp;ssl=1\" class=\"attachment-medium_large size-medium_large wp-image-4538\" alt=\"lockbit royal mail osint\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-osint.png?w=945&amp;ssl=1 945w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-osint.png?resize=300%2C211&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-osint.png?resize=768%2C540&amp;ssl=1 768w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1210aa7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1210aa7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-432b05e\" data-id=\"432b05e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b298c7c elementor-widget elementor-widget-text-editor\" data-id=\"b298c7c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>What LockBit did &#8211; true to their established MO &#8211; was to release the negotiations chat between them and Royal Mail \/ UK&#8217;s NCSC.<\/p><p>The chat offers a unique insight into the dynamics of how ransom payments are negotiated, and how in this case the ransomware group was confused between Royal Mail and Royal Mail International.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c7a5649 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c7a5649\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fa93a61\" data-id=\"fa93a61\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-97bb6b3 elementor-widget elementor-widget-image\" data-id=\"97bb6b3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1024\" height=\"172\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-chat-osint.png?fit=1024%2C172&amp;ssl=1\" class=\"attachment-large size-large wp-image-4539\" alt=\"lockbit royal mail chat osint\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-chat-osint.png?w=1712&amp;ssl=1 1712w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-chat-osint.png?resize=300%2C50&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-chat-osint.png?resize=1024%2C172&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-chat-osint.png?resize=768%2C129&amp;ssl=1 768w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/lockbit-royal-mail-chat-osint.png?resize=1536%2C257&amp;ssl=1 1536w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1e94573 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1e94573\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0434c19\" data-id=\"0434c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-365723e elementor-widget elementor-widget-heading\" data-id=\"365723e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">3. UK sanctions on ransomware actors<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4468630 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4468630\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f4afeec\" data-id=\"f4afeec\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8c092e7 elementor-widget elementor-widget-text-editor\" data-id=\"8c092e7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The UK government issued a sanctions notice (in coordination with their US counterparts) against seven Russian nationals who had &#8220;assets frozen and travel bans imposed&#8221;.<\/p><p>The individuals in question are linked to the Ryuk and Conti ransomware campaigns, which links them in some portion to the infamous May 2021 HSE attack.<\/p><p>See the BBC article on the matter <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-64586361\">here<\/a>.<\/p><p>The official UK Gov <a href=\"https:\/\/www.gov.uk\/government\/news\/uk-cracks-down-on-ransomware-actors\">press release<\/a> states that:<\/p><ul><li><em>it is almost certain that the Conti group were primarily financially motivated and chose their targets based on the perceived value they could extort from them<\/em><\/li><li><em>key group members highly likely maintain links to the Russian Intelligence Services from whom they have likely received tasking. The targeting of certain organisations, such as the International Olympic Committee, by the group almost certainly aligns with Russian state objectives<\/em><\/li><li><em>it is highly likely that the group evolved from previous cyber organised crime groups and likely have extensive links to other cyber criminals, notably EvilCorp and those responsible for Ryuk ransomware<\/em><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c60713d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c60713d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fa71af0\" data-id=\"fa71af0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-08401bd elementor-widget elementor-widget-heading\" data-id=\"08401bd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">4. Ransomware attack on MTU in Ireland<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c56f624 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c56f624\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-175fba5\" data-id=\"175fba5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e8c79e2 elementor-widget elementor-widget-text-editor\" data-id=\"e8c79e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Last week four campuses of Munster Technological University in Cork were turned into digital crime scenes by a ransomware attack attributed to the BlackCat threat actor group.<\/p><p>Disruption to lectures and full closure of the facilities were the results, but the university administration stated they would not be paying the ransom and would rely on restoring services using backups.<\/p><p>The timing of this attack can be coincidental, but similar attacks were reported around the same time across Europe and further afield, from Finland to Israel.<\/p><p>The indicators of compromise in the MTU attack have not been disclosed publicly, however there is an observable increasing trend of using trojanized Microsoft OneNote files to deliver malicious payloads disguised as links to legitimate documents.<\/p><p>I had the opportunity to offer some insights into profiling the BlackCat ransomware group <a href=\"https:\/\/www.irishtimes.com\/crime-law\/2023\/02\/14\/munster-technological-university-cyberattack-the-work-of-sophisticated-ransomware-group\/\">here.<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b94097a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b94097a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-614f971\" data-id=\"614f971\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b8a7daf elementor-widget elementor-widget-heading\" data-id=\"b8a7daf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">5. Eurostat - 22% of EU enterprises had ICT security incidents in 2021\n<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9608da1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9608da1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8a4e8ad\" data-id=\"8a4e8ad\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-967a151 elementor-widget elementor-widget-text-editor\" data-id=\"967a151\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A freshly released <a href=\"https:\/\/ec.europa.eu\/eurostat\/web\/products-eurostat-news\/w\/edn-20230214-1\">report from Eurostat<\/a> for 2021 states that 22.2% of businesses with 10 or more employees experienced ICT security incidents and suffered destruction, corruption or disclosure of data.<\/p><p>Over 6% of those incidents were caused by ransomware, DDoS, intrusions or other malicious software, while ransomware type attacks specifically accounted for 3.5%.<\/p><p>Surprisingly (or not?), the most common causes of all ICT incidents were hardware or software failures.<\/p><p>So it seems those backups are indeed useful, for more than one reason.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c2152e6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c2152e6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5c9e718\" data-id=\"5c9e718\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-79c496d elementor-widget elementor-widget-image\" data-id=\"79c496d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ICT-incidents-eurostat-osint.png?ssl=1\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"ICT incidents eurostat osint\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NDU2NCwidXJsIjoiaHR0cHM6XC9cL29zaW50bWUuY29tXC93cC1jb250ZW50XC91cGxvYWRzXC8yMDIzXC8wMlwvSUNULWluY2lkZW50cy1ldXJvc3RhdC1vc2ludC5wbmcifQ%3D%3D\">\n\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"581\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ICT-incidents-eurostat-osint.png?fit=1024%2C581&amp;ssl=1\" class=\"attachment-large size-large wp-image-4564\" alt=\"ICT incidents eurostat osint\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ICT-incidents-eurostat-osint.png?w=1516&amp;ssl=1 1516w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ICT-incidents-eurostat-osint.png?resize=300%2C170&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ICT-incidents-eurostat-osint.png?resize=1024%2C581&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2023\/02\/ICT-incidents-eurostat-osint.png?resize=768%2C436&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>A quick summary of notable ransomware related incidents and updates from the last 2 weeks.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[18],"tags":[76,101,56,61,134,15],"class_list":["post-4529","post","type-post","status-publish","format-standard","hentry","category-digital-privacy-security","tag-cybercrime","tag-encryption","tag-ireland","tag-malware","tag-ransomware","tag-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/4529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=4529"}],"version-history":[{"count":52,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/4529\/revisions"}],"predecessor-version":[{"id":5244,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/4529\/revisions\/5244"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=4529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=4529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=4529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}