Someone searched for software, clicked the wrong result, and the business was ransomwared in 44 hours
The DFIR Report has published a step-by-step breakdown of an intrusion that began in the least dramatic way imaginable. Somebody searched for a well-known network monitoring package by name, and took one of the results.
The site they landed on was not the real one. It was a convincing copy on a similar address, which passed them along to a download page and handed over an installer. That installer did in fact install the software they wanted – which is precisely why nobody thought twice – and quietly installed something else alongside it.
From there it moved quickly. Within about five hours the machine was talking to the attackers. Over the next two days they created themselves an administrator account, used it to reach the domain controllers and the backup server, and helped themselves to stored passwords. Seventy-seven gigabytes of company data went out to a server abroad. Roughly 44 hours after that first download, Akira ransomware was run across the network, deleting the copies Windows keeps for recovery as it went.
Who this affects
Everyone, and in particular the most capable person in the building. This did not start with somebody clicking a link in a dodgy email. It started with an IT administrator doing his job, fetching a tool he already knew and used.
Poisoned search results work because they invert the usual advice. We tell people to be careful with unexpected emails, and they are. Nobody tells them to be careful with a search they chose to make for software they already wanted. The fake sites are ranked and advertised to be there when you look, and the installer often works exactly as expected, so nothing feels wrong afterwards either.
Cisco Talos reported the same pattern in its review of the incidents it handled last quarter, with phishing and abused remote management tools driving most attack chains.
What to do about it
- Get software from the maker, not from a search. Type the address, or use a bookmark. This one rule would have prevented the whole thing.
- Be most careful about the technical staff. They download the most software, and their accounts open the most doors. If anyone should be fetching installers from a known source, it is them.
- Do not let day-to-day accounts hold administrator rights. The account that opened the installer should not have been able to reach the domain controllers.
- Protect the backups separately. The attackers went for the backup server and its stored passwords deliberately. A backup that the network can delete is not really a backup.
- Watch for the middle bit. There were two days between the download and the ransomware. That window is where an attack gets stopped – but only if somebody is looking.
Two days is a long time to be unnoticed
The encouraging part of a story like this is the gap. Ransomware is the last step, not the first, and there were two days of an unfamiliar account logging into servers at odd hours before anything was encrypted. Every one of those was a chance to catch it.
That is the work our managed detection and response does – real people watching round the clock, so a new administrator account at three in the morning raises a call rather than a log entry. And our backup and disaster recovery keeps copies where an intruder on your network cannot reach them.
Call us on 01202 237 273 or book a call.