Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

2/7/2019
06:15 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Ransomware Attack Via MSP Locks Customers Out of Systems

Vulnerable plugin for a remote management tool gave attackers a way to encrypt systems belonging to all customers of a US-based MSP.

An attacker this week simultaneously encrypted endpoint systems and servers belonging to all customers of a US-based managed service provider by exploiting a vulnerable plugin for a remote monitoring and management tool used by the MSP.

The attack resulted in some 1,500 to 2,000 systems belonging to the MSP's clients getting cryptolocked and the MSP itself facing a $2.6 million ransom demand.

Discussions this week on an MSP forum on Reddit over what appears to be the same — or at least similar — incident suggest considerable anxiety within the community over such attacks, with a few describing them as a nightmare scenario.

"From the MSP's standpoint, the tool they use to manage everything was just used against them" to inflict damage on customers, says Chris Bisnett, chief architect at Huntress Labs. "Everyone is looking at the attack and saying, 'This could have been me.'"

Huntress provides managed detection and response services to the MSP that was attacked and to numerous others like it. Bisnett says one of the company's MSP clients reported the ransomware attack on Monday. After an initial investigation showed that the MSP's systems itself had not been compromised, researchers from Huntress did some further digging and eventually linked the attack to a vulnerable plugin for a remote management tool from Kaseya.

Many MSPs use Kaseya's VSA RMM tool to remotely monitor and manage client systems and servers. The vulnerable plugin for Kaseya that was exploited in the MSP attack itself was from ConnectWise and is used to manage support tickets raised in Kaseya, Bisnett says.

The vulnerability basically gave the attackers a way to run remote commands that allowed them complete access to the Kaseya VSA database. "They were able to task the RMM tool as if they were an administrator at the MSP," Bisnett says. "They said, 'Take this executable and put it out on every system the MSP is managing.'"

In this case, the executable was Gandcrab, a widely distributed ransomware tool that has been used in numerous previous attacks. All customer systems that the MSP was managing via the Kaseya RMM tool were encrypted simultaneously, locking users out of them.

A poster on Reddit on Tuesday described a similar incident impacting a local MSP in which all client systems were encrypted. It's unclear, however, whether the incident mentioned in the Reddit report is the same one reported by the Huntress MSP customer.

Previously, attackers have installed cryptomining tools on business systems and stolen data from organizations in various sectors by gaining access to their networks via MSP connections. There have also been incidents where MSPs have reported one or two clients getting hit with ransomware. "But this was extra alarming because all customer systems were encrypted at the same time," Bisnett notes.

Rising Concerns
Attacks on MSPs are a growing concern. Recently, threat actors, some sponsored by nation states, have begun targeting MSPs in an attempt to get to the networks of their clients. APT10, a threat group believed to be working for the Chinese Ministry of State Security's Tianjin State Security Bureau, is one of the best-known operations targeting MSPs. For the past few years, the group has been conducting a broad cyberespionage operation called Cloud Hopper to steal data from organizations in banking, manufacturing, consumer electronics, and numerous other sectors by attacking their MSPs.

In fact, concerns over such attacks are so high that the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security scheduled to brief MSPs on Chinese malicious activity later this month.

The vulnerability that the threat actor exploited in the latest attack exists in ManagedITSync, a ConnectWise plugin for Kaseya VSA. A security researcher from Australia first reported the vulnerability in November 2017 and posted details, along with proof of concept code, on GitHub.

ConnectWise issued an update addressing the issue sometime later, but for some reason the bug and the update patching it appear to have received little attention until now, Bisnett says. The bug was assigned a formal CVE number only this week after Huntress Lab informed MITRE about the issue, he says. The CVE was backdated to 2017 to reflect the fact it was first reported at that time.

In a note that appears to have been posted six days ago and updated yesterday, Kaseya urged customers using the ConnectWise plugin for VSA to upgrade to the patched version immediately or, alternatively, to remove the plugin altogether.

"This only impacts ConnectWise users who have the plugin installed on their on-premises VSA," the company said, adding that only a very small number of customers appear vulnerable to the threat.

"We are lucky enough not to be directly in the path of this particular storm," says Joshua Liberman, president of Net Sciences, a New Mexico-based MSP. "The only way we'll survive this as an industry, short of stopping the threat at its source, which is well beyond our scope, is to tighten our own defenses, share information with each other, and create an 'offensive defense posture,'" he says.

Related Content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

 
Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ludovic_rembert
50%
50%
ludovic_rembert,
User Rank: Apprentice
5/6/2019 | 4:28:55 AM
Re: The title should have read: Negligent MSP puts customers at risk.
"if the MSP had paid attention this would have been patched 18 months ago and they wouldn't have had a problem."

Following this logic, if millions of Windows users had run automatic updates, they would have avoided ransomware infection from Wannacry. Maybe it's time we shift the burden of responsibility a bit more from from patching updates, and onto the bad actors? 
ShieldHelps
100%
0%
ShieldHelps,
User Rank: Apprentice
2/22/2019 | 3:49:12 PM
The title should have read: Negligent MSP puts customers at risk.
Interesting that the author spent almost zero time pointing out the fact that this was caused by a negligent MSP that didn't patch their systems.  Instead, spread FUD around MSPs and the tools they use.

Here is the real notable item, from the article, buried at the bottom.

"ConnectWise issued an update addressing the issue sometime later, but for some reason the bug and the update patching it appear to have received little attention until now,."

Every update should receive attention, if the MSP had paid attention this would have been patched 18 months ago and they wouldn't have had a problem. This applies to all software and operating systems for all companies, if you aren't patching your systems, then you substantially increase your chances of getting exploited.
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7981
PUBLISHED: 2020-01-25
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
CVE-2019-0141
PUBLISHED: 2020-01-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2020-7596
PUBLISHED: 2020-01-25
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
CVE-2020-7980
PUBLISHED: 2020-01-25
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.
CVE-2012-6613
PUBLISHED: 2020-01-25
D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.