Nevada ransomware attack traced back to malware download by employee | Cybersecurity Dive
https://www.cybersecuritydive.com/news/nevada-ransomware-attack-traced-back-to-malware-download-by-employee/805011/
124 points · 10 comments · view on lemmy.world
10 Comments
KindnessIsPunk@lemmy.ca · 20 pts · 299d
It's always phishing.
reddig33@lemmy.world · 17 pts · 299d
“a state employee mistakenly downloaded a malware-laced tool from a spoofed website”
Why is any randomly downloaded software running on government computers to begin with? Why aren’t these systems and networks locked down better?
Monument@lemmy.sdf.org · 3 pts · 299d
The why is sort of at the limits of my knowledge. I can tell you a ‘close enough’ what, though.
By default, Windows tries to install programs to the program files directory, but that requires admin, which triggers user account control. However, apps that do not require admin to install or run can still be installed to the users profile. Clicking cancel from a UAC prompt will just try to install the program locally instead of for all users.
My assumption is that many system administrators believed UAC was enough, or that programs installing locally (as in, just for that user) and not requiring admin were not a big deal.
shalafi@lemmy.world · 2 pts · 299d
Their systems are probably wildly outdated, a monstrous mix-and-match of tech, stuff like that. A private corporation is easier to lock down. With government they have to follow dozens of outdated laws and guidelines, don't have the freedom private enterprise has.
Monument@lemmy.sdf.org · 9 pts · 299d
Everybody hates the government, but that take is not applicable.
Reading the incident report -
A privileged user got spearphished into downloading a compromised system administration tool. After the compromised tool was detected by industry standard (and modern) intrusion detection software and removed, the backdoor it installed, which was not fixed, was (eventually) used to install a keylogger. Shortly thereafter, another privileged user had a keylogger installed. Afterward, the harvested credentials were used to create further compromises in their network and to move laterally throughout it.
The age of the equipment or software is not a factor when your admin accounts get compromised. The user that got compromised should have known better, but they literally failed one thing - double checking the veracity of the download website. They didn’t surrender credentials, or fall for any direct attack. It’s not really a government bad, private industry good sort of thing. Heck, if that had happened to a non-admin user, the attack wouldn’t have been possible.
markstos@lemmy.world · 1 pts · 299d
To categorically prevent that, every computer would need to centrally controlled and managed, which might have been the case here, and the system configuration has to prevent all software that’s not pre-approved from running.
That’s possible too, but could be a pain to tightly manage. It was a privileged user that was spear phished though… the kind of trusted user who might be able to install software on their machine without additional approval.
giyila7033@sh.itjust.works · 4 pts · 299d
zd9@lemmy.world · 3 pts · 299d
I'm always amazed at how dumb and incompetent some employees are. It's really the peak difference between very smart and competent developers making the malware, and the idiots who fall for it.
Thedogdrinkscoffee@lemmy.ca · 7 pts · 299d
You must be new to humanity. It's not really that surprising.
explodicle@sh.itjust.works · 1 pts · 299d
Hey get a load of Dr. Always Competent over here
SlartyBartFast@sh.itjust.works · 1 pts · 298d
Lol what a numpty!