Is your computer being held hostage?
06 July 2021Lately we have been talking a lot about the dangers of vulnerabilities in software and how cybercriminals can exploit them. If you think this is far from your bed, you are mistaken!
On Friday, July 2, many companies worldwide were hit by a ransomware attack, in which computers and servers (systems) were rendered unusable by software that encrypted the data. To regain access to the files, 70 million dollars is demanded!
Infected with software that encrypts data (Ransomware)
It quickly became clear that Kaseya remote management software was dealing with a ransomware infection. Kaseya software is used worldwide by 40,000 IT companies, who use this software to remotely update, manage, back up and monitor customer systems. Infracom also uses this software, in our case to manage Windows systems.
Well secured at Infracom
On Friday evening at 22:00, Kaseya sent out a message that a vulnerability (leak) had been detected, whereby servers could be infected. Many IT companies use Kaseya servers, Infracom does not.
Infracom uses its own servers in its own data center and runs Kaseya software on them. There is no direct connection to Kaseya servers, moreover Kaseya runs behind a firewall and thus everything is well sealed.
Software updates
One of the updates of Kaseya software contained the malicious code, we did not install this update. We only update the security updates that affect our situation, this is often safer than that of other Kaseya users, so many updates are not applicable to us. Our server is not accessible from the internet, so automatic updates cannot be performed. The ransomware (malicious software) has, as far as we have investigated, not been installed on our systems or those of our customers.
Supply chain attack
The ransomware attack is a so-called supply chain attack, this is an advanced way of a ransomware attack, where a company is affected because an attack is carried out from a supplier. Systems are infected through the already present software.
How this attack worked:
- A vulnerability was detected at Kaseya
- Cybercriminals exploited the vulnerability, allowing malicious code onto the systems.
- Customers of Kaseya, the IT companies that use Kaseya software, receive (automatic) updates with malware on their systems
- Customers of the IT companies are infected with the malware/ransomware
- The entire chain is affected.
As a precaution we have currently broken the Supply Chain. We no longer retrieve updates from Kaseya and do not install updates at our customers until we have received further notice from Kaseya.
Protect your company against a supply-chain attack!
- Ensure good backups
- Ensure Anti-ransomware protection
Cyber criminals are becoming increasingly advanced and smarter, be prepared and follow the advice of our ICT specialists.