The mantra about the crucial role of data backups in digital security has some solid reasoning behind it. Not only is this a way to minimize the damage in a hardware failure scenario, but its also a fundamental element of mitigating the impact of a ransomware attack. This issue has escalated amid todays global healthcare emergency because cybercriminals are busier than ever orchestrating Coronavirus-themed phishing and spam campaigns that parasitize peoples fears to spread ransom Trojans on a large scale.
Organizations are predictably the juiciest prey being hunted down in ransomware raids. Moreover, malefactors continue to target hospitals in these hard times, as if the challenge tackling the COVID-19 outbreak werent arduous enough for these facilities. The dramatic increase in telework is an extra stimulus for crooks to find and exploit loopholes in VPN tools and cloud services used for remote workplace implementation.
With that said, maintaining backups of the most valuable data assets is growingly important for individuals and businesses alike. However, it turns out that a crudely configured backup can do your company a disservice instead of strengthening its security posture. If you are curious about how this could possibly be the case, keep reading to learn the whys and wherefores.
The wakeup call
According to recent findings of security researchers, an incorrectly implemented data backup poses an opportunity for an adversary to amass an organizations valuable files the easy way, no matter how counterintuitive it may sound. Before I proceed, its worth clarifying a few things to give you an idea of the current state of the ransomware ecosystem.
A game-changing trend in this context is that some attackers now steal victims data prior to encrypting it. Several examples of the ransomware families that employ this tactic are Sodinokibi, Maze, DoppelPaymer, and Nemty. Once the criminals retrieve data, they use it as additional leverage to coerce the victim into paying the ransom. If a company refuses to cough up the specified amount of Bitcoin, ransomware operators switch to plan B and publish sensitive information for everyone to see.
Essentially, the attack isnt only about malicious encryption anymore its also about the risk of data breaches and huge reputational damages. To top it off, some cybercriminal groups have launched special websites where they leak the data stolen from non-paying businesses.
You might be wondering what this narrative has to do with backups well, the ties are closer than you probably think. The threat actors behind the above-mentioned DoppelPaymer ransomware recently updated their leak site with an entry listing credentials for the Veeam backup solution used by one of the compromised organizations.
Analysts at Bleeping Computer security outlet who looked into the incident argue that the attackers intention wasnt to punish the organization for rejecting the ransom demands. Instead, it was proof of unlimited access to the victims digital infrastructure, including backups. This way, the felons tried to pressure the company into paying up.
To dot the is and cross the ts, the researchers tried to contact the operators of two very active ransomware strains, DoppelPaymer and Maze, and ask them about this facet of their nefarious activity. On a side note, the experts had previously communicated with these black hats who didnt mind explaining some of their tactics, techniques, and procedures (TTP). The perpetrators response to this particular matter was very surprising.
The cybercrooks described their common attack chain and the role of data backups in it. First, they contaminate a single machine on a network through phishing, auxiliary malware, or remote desktop protocol (RDP) exploitation. As soon as the computer is infiltrated, the offenders move laterally across the network in an attempt to get hold of admin credentials and access the domain controller.
If the attackers succeed in gaining a foothold in the enterprise environment, they leverage a post-exploitation application such as Mimikatz to dump the entirety of authentication data from the active directory database. The consequences of this activity can be hugely disruptive because the obtained information may allow the malefactors to access backup tools used by the organization. The likelihood of this adverse effect is higher if network admins use Windows session authentication to log in to Veeam or another mainstream backup software.
From there, ransomware operators can easily access the victimized companys cloud backups and download all the data to a malicious server. This way, they take a shortcut because there is no need for them to traverse the whole corporate network in search of potentially valuable information cloud backups typically contain the data that matters the most.
An extra benefit for malicious actors who take this route is that the data theft slips below the radar of automated defenses deployed in the network. Restoring directly from the cloud doesnt give IT teams a heads-up because the servers appear to be functioning properly and the backup software doesnt trigger any alerts either.
Once the attackers download all the important files, they delete the backups to prevent the victim from easily recovering from the incursion. Then, they launch the PSExec command-line utility to unleash the ransomware that will encrypt the organizations data surreptitiously.
At the end of the day, although backups are a critical element of incident response, they can be used against companies unless set up properly. Ransomware distributors piggyback on poor backup hygiene to steal data faster without any red flags being raised along the way. This negligence can fuel the extortionists novel strategy thats increasingly capitalizing on data theft before encryption. Offline backups appear to be more effective in this regard, but they are often outdated.
Luckily, there are methods that can help businesses boost their protection against this exploitation vector and make the attackers efforts futile. The fundamental countermeasure is the so-called 3-2-1 rule. It eliminates the risk of a single point of failure (SPOF) in case hardware crashes or a strain of ransomware poisons the enterprise network. In a nutshell, the logic of this mechanism is as follows: store at least three copies of your valuable data, keep two of them on different storage media, and be sure to store one backup copy offline.
The types of storage media for this diversified backup approach can range from external hard disks or USB thumb drives to SD cards or CDs/DVDs. The choice depends on the amount of data to be kept safe. Prioritizing your information is a worthwhile element of facilitating this activity because it narrows down the scope of data to the items that really matter. When it comes to offline backups, its important to ascertain that they hold the latest versions of your files.
If you adhere to the 3-2-1 principle, there is little to no risk of losing your precious data over a ransomware incident, hardware malfunctions, or things like the vengeance of a disgruntled employee. Essentially, it helps your organization steer clear of the worst-case scenario, making your security posture resilient to a disaster no matter where it may come from.
Experts additionally recommend that businesses resort to whats called immutable storage to further enhance their data integrity. This technique makes it impossible to erase or modify backups for a specified period of time.
Furthermore, the saying prevention is the best cure has never been as relevant as it is nowadays. To defend against ransomware attacks and data breaches proactively, organizations should deploy network monitoring tools, cloud access control instruments based on IP addresses and geolocation, and intrusion detection systems (IDS). This combo will stop criminals in their tracks and save companies the trouble of dealing with the mind-boggling aftermath of a compromise.
Post Views: 73
Follow this link:
How Not to Make Backups - The Union Journal
- Report: NSA building comp to crack encryption types [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Report: NSA looking to crack all encryption with quantum computer [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Sound Advice: Explaining Comcast cable encryption [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- NSA Building Encryption-Busting Super Computer [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- NSA researches quantum computing to crack most encryption [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Advanced Encryption Standard - Wikipedia, the free encyclopedia [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- How Encryption Works - HowStuffWorks "Computer" [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Email Encryption - MB Technology Solutions - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Email Encryption - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Reversible Data Hiding in Encrypted Images by Reserving Room Before Encryption - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Toshiba WT8 Full Disk Encryption, Miracast, Easy Stand - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Australian Encryption | Text encryption software for the protection of your privacy - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- njRAT v0 6 4 server Clean Encryption - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- AlertBoot New Encryption Compliance Reports Prepare Covered Entities For HIPAA Audits [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- BlackBerry denies using backdoor-enabled encryption code [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- What Is Encryption? (with pictures) - wiseGEEK [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- HowStuffWorks "How Encryption Works" [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Gambling with Secrets Part 5 8 Encryption Machines - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- The Benefits of Hosted Disk Encryption - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Quill Encryption - what's that? - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- WhatsApp Encryption - Shmoocon 2014 by @segofensiva @psaneme - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- encryption demo2 - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- encryption demo - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Seven - Encryption Official Lyric Visual - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Quantum Computers - The Ultimate Encryption Backdoor? - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- Eric Schmidt: Encryption will break through the Great Firewall of China [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- From NSA to Gmail: Ex-spy launches free email encryption service [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Tennessee bill takes on NSA encryption-breaking facility at Oak Ridge/SHUT. IT. DOWN. - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Substitute for:Measurements. 1 Episode. Strength of the encryption algorithm - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- RSA Encryption Checkpoint - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Gambling with Secrets 8 8 RSA Encryption 1 - Video [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Google chairman says 'encrypting everything' could end China's censorship, stop NSA snooping [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Ex-spy launches free email encryption service [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- 3 2 The Data Encryption Standard 22 min - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- RSA Encryption step 3 - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- RSA Encryption step 2 - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- aes tutorial, cryptography Advanced Encryption Standard AES Tutorial,fips 197 - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- Townsend Security Release First Encryption Key Management Module for Drupal [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- RSA Encryption step 5 - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Lavabit case highlights legal fuzziness around encryption rules [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- A Beginner's Guide To Encryption: What It Is And How To Set It Up [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- How App Developers Leave the Door Open to NSA Surveillance [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Intro to RSA Encryption step 1 - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- “Honey Encryption” Will Bamboozle Attackers with Fake Secrets [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Encryption - A Life Unlived (DEMO) - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Baffle thy enemy: The case for Honey Encryption [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- New AlertBoot Encryption Reports Make Dental HIPAA Compliance Easier [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Encryption - The Protest - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Encryption - New Life - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Encryption - Intro - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Encryption - Blank Canvas - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Security First SPxBitFiler-IPA encryption pattern for the IBM PureApplication System - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Revolutionary new cryptography tool could make software unhackable [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- viaForensics webinar: Mobile encryption - the good, bad, and broken - Aug 2013 - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- K.OStream 0.2 File Encryption Test - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Tumblr adds SSL encryption option, but not as the default [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Latest Java Project Source Code on Chaotic Image Encryption Techniques - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Encryption - University of Illinois at Urbana–Champaign [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- A Beginner's Guide to Encryption: What It Is and How to ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Real Data Encryption Software is More Important than Ever ... [Last Updated On: February 8th, 2014] [Originally Added On: February 8th, 2014]
- Caesar Cipher Encryption method With example in C Language - Video [Last Updated On: February 8th, 2014] [Originally Added On: February 8th, 2014]
- Hytera DMR 256 bit encryption - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Townsend Security Releases Encryption Key Management Virtual Machine for Windows Azure [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Unitrends Data Backup Webinar: Utilizing The Cloud, Deduplication, and Encryption - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Main menu [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Use of encryption growing but businesses struggle with it – study [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- SlingSecure Mobile Voice Encryption Installation Video for Android - Video [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Data breaches drive growth in use of encryption, global study finds [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Darren Moffat: ZFS Encryption - Part 2 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Darren Moffat: ZFS Encryption - Part 1 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- How do I configure User Local Recovery in Endpoint Encryption Manager 276 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Symmetric Cipher (Private-key) Encryption - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- SafeGuard File Encryption for Mac - Installation and Configuration - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Fundamentals of Next Generation Encryption - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Tutorial: Einrichten der EgoSecure Endpoint Removable Device Encryption - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- 'PGP' encryption has had stay-powering but does it meet today's enterprise demands? [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- Fact or Fiction: Encryption Prevents Digital Eavesdropping [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- RHCSA PREP:answer to question 20 (Central Authentication Using LDAP with TLS/SSL Encryption) - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- Protect+ Voice Recorder with Encryption - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]