A new ransomware tactic has been identified in which attackers abuse Windows' disk encryption feature, BitLocker, to encrypt corporations' data and then print a ransom note on office printers.
On the 6th, Kaspersky said that its security services experts, after investigating ransomware attacks targeting corporations in Colombia and Mexico in May–Jun., found cases in which attackers abused BitLocker, a legitimate Windows feature, to encrypt data and then used corporations' printers to print ransom notes.
The attackers infiltrated corporations' internal networks through internet-exposed remote access services or misconfigured systems, then used BitLocker to encrypt key data. They then printed ransom notes via corporations' printers to pressure the victim corporations to pay the expense. Victims became aware of the attack when a padlock icon appeared next to drives in Windows Explorer and they could no longer access files.
In the Colombia case, the attacker broke into an 8TB storage server that held core data via an internet-exposed remote access service. The attacker then changed user account information, encrypted the drive containing financial data with BitLocker, and printed a ransom note using a printer.
In Mexico, attackers who identified themselves as "XEntry Team" was found to have first gained access by obtaining account information leaked from publicly available source code and exploiting a poorly configured Microsoft SQL (MS SQL) server. The attacker then weakened security settings on the web server and maintained internal network access for months. The hacking came to light when employees' PCs displayed a blue screen with the phrase "Hacked by XEntry Team," and logging in with existing accounts became impossible.
Eduardo Chavarro Ovalle, Kaspersky's manager for the Digital Forensics and Incident Response group, said, "Attackers are abusing legitimate administrative tools to encrypt data and pressure corporations to pay the ransom," and noted, "To defend against such attacks, logs must be managed securely from a central location, security alerts continuously monitored, and signs of unauthorized access investigated promptly."
Lee Hyo-eun, head of Kaspersky Korea, said, "Domestic corporations, along with a high level of digital transformation, are continuously exposed to ransomware threats," and added, "Corporations need to shift from post-incident response to a prevention-centered security strategy." She continued, "Regularly inspect system vulnerabilities and configuration errors, continuously monitor for unauthorized access, and build a framework that can detect and respond to threats early."
Kaspersky recommended the following to reduce ransomware damage: building an integrated security platform such as endpoint detection and response (EDR) and extended detection and response (XDR); using managed detection and response (MDR) and incident response (IR) services; strengthening security settings for Remote Desktop Protocol (RDP); and establishing multilayered security that includes application control and monitoring of command-and-control (C2) communications.