Texas Ransomware Responders Urge Remote Access

New Post Public Reply Private Reply Replies (1) Message Board
CyberC
570
Texas Ransomware Responders Urge Remote Access Lockdown
Lessons Learned From Crypto-Locking Malware Attack That Hit 22 Municipalities
Mathew J. Schwartz (euroinfosec) • September 6, 2019
Credit Eligible
Texas Ransomware Responders Urge Remote Access Lockdown
Photo: M&R Glasgow, via Flickr/CC
Three weeks after a ransomware attack slammed 22 Texas municipalities' systems, leaving them crypto-locked, state officials say more than half of the cities have returned to normal operations. The remainder, they say, are continuing to advance their system restoration (see: Texas Says 22 Local Government Agencies Hit by Ransomware).

texas-ransomware-responders-urge-remote-access-lockdown-showcase_image-1-a-13043.jpg


See Also: Webinar | The Future of Adaptive Authentication in Financial Services

Based on the experience, the state's information security leaders have published a series of recommendations - including how to lock down endpoints and infrastructure being remotely managed, for example, by managed service providers.

Although state officials have declined to go into details, based on their lessons learned, it appears that some or all of the affected municipalities' systems may have been managed by a single MSP.

Incident Response Concludes
Texas state officials say their incident response effort was launched just hours after the 22 municipalities got hit by a ransomware attack on Aug. 16.

By Aug. 23, just one week after the attack, all of the victims "had transitioned from assessment and response to remediation and recovery with business-critical services restored," the Texas Department of Information Resources says.

While a federal investigation into the ransomware attack is ongoing, Texas officials characterize the joint federal and state response to this "statewide, multi-jurisdictional cybersecurity event" as being "a tremendous success."


Amanda Crawford, executive director of the Texas Department of Information Resources
Amanda Crawford, executive director of the state's Department of Information Resources, says this success was due in large part to having a response plan already in place.

amanda-crawford-300px.jpg

"I am proud of the work of Department of Information Resources' information security team and grateful for the partnership with the many state and federal agencies who joined in our response to this incident," she says. "I also want to recognize the impacted entities for working with our responders to get this resolved quickly while still protecting the integrity of the federal investigation. It was this team effort along with advanced preparation that allowed a very critical situation to be resolved quickly and with minimal impact for Texans."

State officials have declined to specify which strain of ransomware infected systems or how the systems were infected.

But Gary Heinrich, the mayor of one of the affected municipalities - Keene, Texas, with a population of 6,100 - last month told NPR that the attacker demanded a total ransom worth $2.5 million to restore all crypto-locked systems across the 22 municipalities.

Heinrich also said the city outsources its IT operations. "They got into our software provider, the guys who run our IT systems," Heinrich told NPR. "A lot of folks in Texas use providers to do tha, because we don't have a staff big enough to have IT in house."

State officials have declined to confirm if a single managed service provider served all 22 municipalities that got hit by ransomware. But they did say that to the best of their knowledge, no ransom got paid to the attacker, which they described as being apparently "one single threat actor."

5 Lessons Learned for MSP Users
Nancy Rainosek, the CISO of Texas, has offered five lessons learned from the attack that she says are applicable to any organization that uses remotely administered IT services or managed security providers.

Here are her verbatim recommendations:

"Only allow authentication to remote access software from inside the provider's network;
Use two-factor authentication on remote administration tools and virtual private network tunnels - VPNs - rather than remote desktop protocols;
Block inbound network traffic from Tor exit nodes;
Block outbound network traffic to Pastebin;
Use endpoint detection and response to detect Powershell running unusual processes."
Based on Rainosek's recommendations, it appears that the Texas municipality ransomware attacker was able to remotely access - via the anonymizing Tor network - poorly secured remote-administration tools installed by an MSP on the endpoints of up to 22 Texas municipalities, using PowerShell to move laterally in targeted networks and exfiltrating stolen data or perhaps a list of infected systems to the text-sharing site Pastebin.

Sodinokubi Targets MSPs
Managed security providers are an obvious target for ransomware attackers, because one MSP will manage IT for numerous organizations. If hackers can break into the MSP's infrastructure, they can potentially infect numerous victim organizations with little additional effort. For example, if an MSP has 100 clients, and each client as 100 endpoints, that's potentially 10,000 endpoints that a single attacker might be able to infect.


Bill Siegel, CEO, Coveware
Bill Siegel, CEO of Coveware, a Connecticut-based ransomware incident response firm, says ransomware-as-a-service affiliates will target remote management tools - also known as remote-administration tools - used by MSPs or IT service providers, which get installed on every endpoint they manage.

coveware-bill-siegel-300px.jpg

"It's been devastating, because when they do get into an MSP, they hit hundreds of companies, sometimes simultaneously, [generating] very high return on the attack, rather than just hitting the MSP, which is also a small business," he tells Information Security Media Group. "They're hitting hundreds of small organizations at a time." (See Do Ransomware Attackers Single Out Cyber Insurance Holders?)

MSPs use remote management tools to scale. But some tools have vulnerabilities - several widely used RMM tools have received critical security updates in recent months - and some RMM tools get deployed in a poorly secured manner, for example, without two-factor authentication, Siegel says. As a result, hackers can sometimes remotely push malicious software directly to an RMM tool for immediate installation on an endpoint.

common-industries-coveware-q2-2019.jpg

Common industries targeted with ransomware in Q2 2019 (Source: Coveware)
Siegel says his firm wasn't involved in the Texas municipality investigation. But he says attackers using the Sodinokibi ransomware-as-a-service offering continue to target MSPs, and that it's likely that ransomware strain was used against the Texas municipalities (see Ransomware: As GandCrab Retires, Sodinokibi Rises).


WHAT THEY NEED IS STRIKEFORCE'S OOBA AND GUARDEDID

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

Colson Group Expands with Algood Acquisition

Updated Category News Views 12

A Big Move in Mobility Solutions Put on your seatbelts, because Colson Group is steering into a new lane with its acquisition of Algood Caster Innovations. This ain't just any pickup—it's a smart move that could ramp up their North American manufacturing clout and mobility solutions. You know, mergers like these don't come around by accident. Colson sees something...

Continue Reading
Perkins Rolls Out Mahjong to Revive Family Bonds

Updated Category News Views 8

Perkins Ditches the Phones, Sparks True Connection No doubt about it, folks—Perkins Restaurant & Bakery has cooked up something special to bring families back to the table. Not just for pancakes or pies this time, but for a little classic game action with their limited-edition Mahjong set. Love it or leave it, this is Perkins tapping into the magic of togetherness...

Continue Reading
Primrose Schools App: A Bold Step for Digital Literacy

Updated Category News Views 5

Primrose Schools Delivers a New Era in Child Education Sitting at a crossroads between the tactile charm of hands-on learning and the inevitable march of digital literacy, Primrose Schools has unveiled something that might just rock the boat in early education: their new Balanced Learning® App. This move by Primrose comes at a crucial time when many parents are...

Continue Reading
BLM's Wild Horse Strategy: Fertility Control's Time to Shine

Updated Category News Views 4

Wild Horse Management Gets a Shot in the Arm Amigo, when the federal government throws $30 million dollars at a problem, you'd hope they're not just throwing us a bone. The Bureau of Land Management (BLM) now has this hefty sum courtesy of the U.S. Department of Agriculture, intended to expand wild horse fertility control across the sprawling landscapes they roam. This...

Continue Reading
Understanding Criminal Threat Charges in Kansas

Updated Category News Views 3

The Intricacies of Criminal Threat Cases in Kansas Let's cut straight to it: not all heated exchanges land you in court, but words can slap you with a criminal threat charge in Kansas if mishandled. A simple spat can turn legal nightmare, making it crucial to grasp the nuances of these cases. What sets them apart from other charges is the absence of physical...

Continue Reading
PVOLVE Expands Reach with New Franchises in 2026

Updated Category News Views 12

The PVOLVE Fitness Craze Picks Up Momentum Seriously, if you hadn’t heard of PVOLVE before, now might be the time to get your ears in tune—and maybe consider hitting up one of their studios. They’ve been on an expansion tear, with franchise deals popping up like daisies in Washington and Wisconsin. It's the two new spots in Tacoma and Brookfield that are grabbing...

Continue Reading
Class Action Lawsuit Hits Desert Resort Management

Updated Category News Views 4

Desert Resort Management in Labor Hot Seat Alright, here's a twist that might make your coffee spill—Desert Resort Management, Inc. is caught in a legal whirlwind in Riverside County. The heavy hitters at Blumenthal Nordrehaug Bhowmik De Blouw LLP have slapped a lawsuit right in their face, alleging some grimy labor practices. They're claiming that the company wasn't...

Continue Reading
Janitorial Wages Soar 26.7% Amid High Annual Openings

Updated Category News Views 3

Janitorial Sector Faces Wage Surge and Employment Shifts Look, if you thought the world of janitorial work was all brooms and mops without a paycheck edge, think again. From 2020 to 2025, wages for janitors and building cleaners didn't just tip-toe up the ladder—they practically sprinted, climbing 26.7%. BLS data laid this one out, with hourly pay shooting from $13.98...

Continue Reading
Hyundai Teases 2027 TUCSON: Global Reveal Imminent

Updated Category News Views 3

Hyundai Sets the Stage for the 2027 TUCSON Hyundai’s ready to roll out its shiny new set of wheels, the 2027 TUCSON, and boy, they sure know how to make an entrance. Mark your calendars for October 1—it's happening right in the Big Apple, none other than Long Island City. Expect the spotlight to hit at precisely 5:15 p.m. ET, and don't worry if you can't snag a...

Continue Reading
NUS Unveils eLuminator: A Leap for Robotics & Healthcare

Updated Category News Views 3

Game-Changing Electronic Skin From NUS It's not every day you come across tech that could shake up multiple industries, but that's just what the National University of Singapore has cooked up with their latest brainchild—the eLuminator. This ain't your everyday wearable tech. We're talking a skin-like device that can both detect and show touch in real-time, no fiddly...

Continue Reading

Top 5 Most Recently Viewed Articles

Understanding Market Sentiment Surrounding Xcel Energy Stocks

Updated Category News Views 114

Market Sentiment Analysis for Xcel Energy Xcel Energy's stock, represented by the ticker XEL, has experienced a notable increase in short interest, rising to 12.35% from the last report. The company currently has 9.14 million shares sold short, which constitutes 1.82% of its total publicly available shares. Considering the current trading volumes, it would take...

Continue Reading
Justice Department's Decision Sparks Controversy Over Attorney Dismissal

Updated Category News Views 246

Significant Dismissal of U.S. Attorney in New Jersey The U.S. Attorney for the District of New Jersey, Desiree Leigh Grace, has been dismissed by the Justice Department. This decision has stirred up considerable conversation regarding the interplay between judicial authority and executive decisions. Understanding the Dismissal What Happened: The Justice Department...

Continue Reading
Eesti Energia Plans Voluntary Bid for Enefit Green Shares

Updated Category News Views 214

Intention to Make a Voluntary Takeover Bid Today, a shareholder of Enefit Green AS, Eesti Energia AS, has formally announced its intention to initiate a voluntary takeover bid. This action is aimed at acquiring all shares of Enefit Green AS that have not yet been acquired by the Offeror. Below are the details surrounding this offer. Details of the Takeover Bid Eesti...

Continue Reading
Celebrating Arch11's Recognition as Premier Design Firm 2024

Updated Category News Views 112

Arch11 Wins Prestigious AIA Firm of the Year Award Arch11 is thrilled to announce that it has received the highly regarded 2024 AIA Colorado Firm of the Year Award from the Colorado Chapter of the American Institute of Architects (AIA). This honor celebrates outstanding accomplishments in design, leadership, and practice, underscoring Arch11’s significant influence on...

Continue Reading
Nio Navigates Legal Challenges While Maintaining Strong Operations

Updated Category News Views 171

Nio Addresses Legal Concerns Nio Inc. (NYSE:NIO) saw a drop in premarket trading on a recent Friday as investors reacted to legal news involving Singapore's sovereign wealth fund and reports from short sellers. Despite this, Nio promptly issued a statement reinforcing that the lawsuit does not affect its current operational activities. Understanding the Legal Context The...

Continue Reading