BECOME A CORE MEMBER HERE

Author Topic: Network server hacked  (Read 511 times)

Offline Trailabite

  • GATR STAFF
  • *
  • Posts: 7627
  • KARMA : +12/-21
  • Need more parts!
    • Trailabite
Network server hacked
« on: January 27, 2020, 10:20:00 AM »
Our corporate server has been hacked this morning by some sort of ransomware. All of our files have been encrypted. They did leave us a letter with a process on how to recover our files. It's an actual ransome letter demanding a payment.

This pisses me off but at the same time I'm amazed at the technology.

Sent from my SM-G975U using Tapatalk

Chuck & Sherry

*GET OUT OF KEVIN'S YARD*

Offline BigMike

  • Visitor
  • Posts: 4224
  • KARMA : +31/-79
Re: Network server hacked
« Reply #1 on: January 27, 2020, 10:28:05 AM »
@BigPrince can chime in as this is his wheel-house.  It may come back to a DFU clicking on a phishing email, but if someone came through your firewall and hacked a server, that is a serious gap in IT Security. 

Is it a single server or has it spread to workstations?  Hope the company has good/recent backups.  I think public executions of people that create this shit would help curb it.

Offline Trailabite

  • GATR STAFF
  • *
  • Posts: 7627
  • KARMA : +12/-21
  • Need more parts!
    • Trailabite
Re: Network server hacked
« Reply #2 on: January 27, 2020, 10:42:15 AM »
They got through our corporate firewall in New York and it looks like it has spread to all of our servers (other offices) across the US. So far, all files on our laptops are safe. I instructed our office to either turn their laptops off or disconnect them from our network.

Sent from my SM-G975U using Tapatalk

Chuck & Sherry

*GET OUT OF KEVIN'S YARD*

Offline BigMike

  • Visitor
  • Posts: 4224
  • KARMA : +31/-79
Re: Network server hacked
« Reply #3 on: January 27, 2020, 10:47:08 AM »
They got through our corporate firewall in New York and it looks like it has spread to all of our servers (other offices) across the US. So far, all files on our laptops are safe. I instructed our office to either turn their laptops off or disconnect them from our network.

Sent from my SM-G975U using Tapatalk



Wouldn't want to be the CISO in NY today.  Yikes.  Hope that he has recently performed a penetration test and has documentation.
« Last Edit: January 27, 2020, 10:47:51 AM by BigMike »

Offline Trailabite

  • GATR STAFF
  • *
  • Posts: 7627
  • KARMA : +12/-21
  • Need more parts!
    • Trailabite
Re: Network server hacked
« Reply #4 on: January 27, 2020, 10:55:02 AM »
Here's the note they left on the servers.

Sent from my SM-G975U using Tapatalk

Chuck & Sherry

*GET OUT OF KEVIN'S YARD*

Offline Trailabite

  • GATR STAFF
  • *
  • Posts: 7627
  • KARMA : +12/-21
  • Need more parts!
    • Trailabite
Re: Network server hacked
« Reply #5 on: January 27, 2020, 11:06:29 AM »
It's called Maze Ransomware. The same people that attacked Southwire here in GA back in December.

Sent from my SM-G975U using Tapatalk

Chuck & Sherry

*GET OUT OF KEVIN'S YARD*

Offline tjsahara00

  • GATR STAFF
  • *
  • Posts: 7721
  • KARMA : +52/-44
  • Staying on the porch now days!
Re: Network server hacked
« Reply #6 on: January 27, 2020, 12:14:45 PM »
Last extrusion company I worked at (15 years ago) named
Sapa Extrusions was hi-jacked last year. It hurt then pretty
bad getting back going. They never paid the ransom....

Update
I forgot they had changed the name to Hydro Extrusion and
now I heard they they did pay in December.
« Last Edit: January 27, 2020, 12:33:47 PM by tjsahara00 »
Kevin Pool
2016 JKU Sport
2000 TJ Sahara (RIP)

Offline patman

  • C.O.R.E MEMBER
  • *
  • Posts: 6609
  • KARMA : +39/-69
Re: Network server hacked
« Reply #7 on: January 27, 2020, 12:18:24 PM »
"We understand your stress and worry"
Lol. These guy sound like pretty nice salesmen. How much are they asking?

Offline Trailabite

  • GATR STAFF
  • *
  • Posts: 7627
  • KARMA : +12/-21
  • Need more parts!
    • Trailabite
Re: Network server hacked
« Reply #8 on: January 27, 2020, 12:53:19 PM »
"We understand your stress and worry"
Lol. These guy sound like pretty nice salesmen. How much are they asking?
I don't know yet. I know they hit up Southwire for $6M and they wanted payment in bitcoins.

There was an FBI warning about this group on January 2, 2020.

Apparently, Railworks didn't listen lol


Sent from my SM-G975U using Tapatalk

Chuck & Sherry

*GET OUT OF KEVIN'S YARD*

Offline BigPrince

  • Visitor
  • Posts: 1650
  • KARMA : +54/-122
Re: Network server hacked
« Reply #9 on: January 27, 2020, 08:16:10 PM »
Yeah... so... sorry to hear. At this point I'm sure your IT folks are freaking out and well into responding.  It's up to your executives if they wish to involve the FBI / other feds, pay/not pay, etc.  There are a lot of devil in the details but this one is particularly nasty with their willingness to leak data not just encrypt it.  Without knowing the environment, data, etc, my suggestion would be to determine if the folks in house can handle it and if not retain an incident response team like Mandiant or SecureWorks, etc.  If it's one system/set of systems, hopefully your backups are good and recent.  Once you identify how it happened you can restore from backups.  If your prevention controls fail that is the most prevalent way to restore business continuity in a ransomeware situation.  Hopefully your company has good incident response, business recovery and continuity plans.  Working offline and NOT opening any phishy emails, questionable attachments, or clicking on funky links is email,  is a good strategy while IT eradicates, contains, and restores the rest. Hopefully if it has a large impact you have good Cyber Insurance as well.
« Last Edit: January 27, 2020, 08:16:57 PM by BigPrince »

Offline jc79

  • Visitor
  • Posts: 3805
  • KARMA : +26/-44
Re: Network server hacked
« Reply #10 on: January 28, 2020, 03:45:44 AM »
Chuck, given the industry you’re in, be thinking what access your systems might have to your customers systems. If you have folks with remote access into your customers to do maintenance or troubleshooting you should think about whether there’s a risk of you spreading it to them.

I don’t know enough about it to know if you have that scenario but wanted to bring it up.


Sent from my iPhone using Tapatalk
Jared

2004 TJ Unlimited (LJ)

Offline Trailabite

  • GATR STAFF
  • *
  • Posts: 7627
  • KARMA : +12/-21
  • Need more parts!
    • Trailabite
Re: Network server hacked
« Reply #11 on: January 28, 2020, 08:13:51 AM »
Chuck, given the industry you’re in, be thinking what access your systems might have to your customers systems. If you have folks with remote access into your customers to do maintenance or troubleshooting you should think about whether there’s a risk of you spreading it to them.

I don’t know enough about it to know if you have that scenario but wanted to bring it up.


Sent from my iPhone using Tapatalk

Yeah, this group (MAZE) kind of helped us with that. We go through Citrix for anything outside of the company and right now we can't even access that. It's files have been encrypted as well. We did get our email service running through mime-cast so there is some communication that can take place.

For me, its just like working back in the 80's again lol, working from my C drive and making actual phone calls!
Chuck & Sherry

*GET OUT OF KEVIN'S YARD*

 



BECOME A CORE MEMBER HERE

CHECK OUT OUR CLUB WEBSITE

JOIN US ON FACEBOOK

JOIN US ON INSTAGRAM