{"exhaustive":{"nbHits":false,"typo":false},"exhaustiveNbHits":false,"exhaustiveTypo":false,"hits":[{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"faurosann"},"comment_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["stairwell","malware"],"value":"In a new joint cybersecurity advisory, U.S. cybersecurity and intelligence agencies have warned about the use of Maui ransomware by North Korean government-backed hackers to target the healthcare sector since at least May 2021.<p>&quot;North Korean state-sponsored cyber actors used Maui ransomware in these incidents to encrypt servers responsible for healthcare services\u2014including electronic health records services, diagnostics services, imaging services, and intranet services,&quot; the authorities noted.<p>The alert comes courtesy of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of the Treasury.<p>Cybersecurity firm <em>Stairwell</em>, whose findings formed the basis of the advisory, said the lesser-known ransomware family stands out because of a lack of several key features commonly associated with ransomware-as-a-service (RaaS) groups.<p>This includes the absence of &quot;embedded ransom note to provide recovery instructions or automated means of transmitting encryption keys to attackers,&quot; security researcher Silas Cutler said in a technical overview of the ransomware.<p>Instead, analysis of Maui samples suggests that the <em>malware</em> is designed for manual execution by a remote actor via a command-line interface, using it to target specific files on the infected machine for encryption.<p>Besides encrypting target files with AES 128-bit encryption with a unique key, each of these keys is, in turn, encrypted with RSA using a key pair generated the first time when Maui is executed. As a third layer of security, the RSA keys are encrypted using a hard-coded RSA public key that's unique to each campaign.<p>What sets Maui apart from other traditional ransomware offerings is also the fact that it's not offered as a service to other affiliates for use in return for a share of monetary profits.<p>In some instances, the ransomware incidents are said to have disrupted health services for extended periods of time. The initial infection vector used to conduct the intrusions is unknown as yet.<p>It's worth noting that the campaign is predicated on the willingness of healthcare entities to pay ransoms to quickly recover from an attack and ensure uninterrupted access to critical services. It's the latest indication of how North Korean adversaries are adapting their tactics to illegally generate a constant stream of revenue for the cash-strapped nation.<p>According to the Sophos' State of Ransomware in Healthcare 2022 report, 61% of healthcare organizations surveyed opted to settle compared with the global average of 46%, with only 2% of those that paid the ransom in 2021 getting their complete data back.<p>That said, the use of a manually operated ransomware family by an APT group also raises the possibility that the operation could be a diversionary tactic designed to act as a cover for other malicious motives, as recently observed in the case of Bronze Starlight.<p>&quot;Nation state-sponsored ransomware attacks have become typical international acts of aggression,&quot; Peter Martini, co-founder of iboss, said in a statement. &quot;Unfortunately, North Korea specifically has shown it is very willing to indiscriminately target various industries, including healthcare, to secure untraceable cryptocurrency that is funding its nuclear weapons program.&quot;"},"story_title":{"matchLevel":"none","matchedWords":[],"value":"[dead]"}},"_tags":["comment","author_faurosann","story_32030117"],"author":"faurosann","comment_text":"In a new joint cybersecurity advisory, U.S. cybersecurity and intelligence agencies have warned about the use of Maui ransomware by North Korean government-backed hackers to target the healthcare sector since at least May 2021.<p>&quot;North Korean state-sponsored cyber actors used Maui ransomware in these incidents to encrypt servers responsible for healthcare services\u2014including electronic health records services, diagnostics services, imaging services, and intranet services,&quot; the authorities noted.<p>The alert comes courtesy of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of the Treasury.<p>Cybersecurity firm Stairwell, whose findings formed the basis of the advisory, said the lesser-known ransomware family stands out because of a lack of several key features commonly associated with ransomware-as-a-service (RaaS) groups.<p>This includes the absence of &quot;embedded ransom note to provide recovery instructions or automated means of transmitting encryption keys to attackers,&quot; security researcher Silas Cutler said in a technical overview of the ransomware.<p>Instead, analysis of Maui samples suggests that the malware is designed for manual execution by a remote actor via a command-line interface, using it to target specific files on the infected machine for encryption.<p>Besides encrypting target files with AES 128-bit encryption with a unique key, each of these keys is, in turn, encrypted with RSA using a key pair generated the first time when Maui is executed. As a third layer of security, the RSA keys are encrypted using a hard-coded RSA public key that&#x27;s unique to each campaign.<p>What sets Maui apart from other traditional ransomware offerings is also the fact that it&#x27;s not offered as a service to other affiliates for use in return for a share of monetary profits.<p>In some instances, the ransomware incidents are said to have disrupted health services for extended periods of time. The initial infection vector used to conduct the intrusions is unknown as yet.<p>It&#x27;s worth noting that the campaign is predicated on the willingness of healthcare entities to pay ransoms to quickly recover from an attack and ensure uninterrupted access to critical services. It&#x27;s the latest indication of how North Korean adversaries are adapting their tactics to illegally generate a constant stream of revenue for the cash-strapped nation.<p>According to the Sophos&#x27; State of Ransomware in Healthcare 2022 report, 61% of healthcare organizations surveyed opted to settle compared with the global average of 46%, with only 2% of those that paid the ransom in 2021 getting their complete data back.<p>That said, the use of a manually operated ransomware family by an APT group also raises the possibility that the operation could be a diversionary tactic designed to act as a cover for other malicious motives, as recently observed in the case of Bronze Starlight.<p>&quot;Nation state-sponsored ransomware attacks have become typical international acts of aggression,&quot; Peter Martini, co-founder of iboss, said in a statement. &quot;Unfortunately, North Korea specifically has shown it is very willing to indiscriminately target various industries, including healthcare, to secure untraceable cryptocurrency that is funding its nuclear weapons program.&quot;","created_at":"2022-07-09T00:46:30Z","created_at_i":1657327590,"objectID":"32030118","parent_id":32030117,"story_id":32030117,"story_title":"[dead]","updated_at":"2024-09-20T11:30:08Z"},{"_highlightResult":{"author":{"matchLevel":"none","matchedWords":[],"value":"notahacker"},"comment_text":{"fullyHighlighted":false,"matchLevel":"full","matchedWords":["stairwell","malware"],"value":"Yup.<p>Reading the article, one would think the idea of using lower cost materials on a construction project was a cunning idea conceived by <em>Margare</em>t Thatcher in 1979. It isn't, people substitute cheaper materials on their own very expensive properties all the time, and if councils are really preoccupied with saving money over all else they wouldn't have spent \u00a39m on refurbishing Grenfell in the first place. (If you've ever lived in a comparable building, you'll understand <i>why</i> fitting insulating cladding was thought to be a good idea...)<p>There are serious questions to be asked about an architectural design which apparently involved flammable lining products in close proximity, a chimney of air and no firegapping between stories should or could have been identified as a fire hazard, there are questions about how it was installed, and questions about whether the council's poor communications with the residents over fire safety contributed to fewer evacuations (one of their big concerns was apparently concerns over a gas pipe in the <em>stairwell</em> which appears to be one of the few things that didn't go seriously wrong). And there are wider questions about whether standard instructions to stay put are appropriate for the building are appropriate and whether regulations ought to be changed to require mineral wool insulation and/or sprinklers on tall buildings in future.<p>It's also not a bad time to raise questions about cutting firemen numbers in London even though it isn't thought that lack of manpower to tackle the blaze was a problem.<p>But crudely reducing it to a &quot;bad neoliberals hate poor people&quot; to score opportunistic political points actually works against learning those lessons. Poor implementation Grenfell's refurbishment programme is no more a scathing indictment of &quot;neoliberalism&quot; than Ronan Point's collapse was a scathing indictment of the desire of the government to take the lead in housebuilding following WWII. The construction industry <i>did</i> learn from that one.<p>(Ironically, to the extent that &quot;neoliberalism&quot;, or Thatcherite housing policy, was <i>particularly</i> relevant to this tower block, it was in having the effect of passing some of the leases into the hands of relatively wealthy private owners who had every interest in the building surviving to make a fortune on selling the flats in a few years' time)"},"story_title":{"matchLevel":"none","matchedWords":[],"value":"London\u2019s Grenfell Tower Fire Was No Ordinary Accident"},"story_url":{"matchLevel":"none","matchedWords":[],"value":"https://www.citylab.com/equity/2017/08/grenfell-was-no-ordinary-accident/536907/"}},"_tags":["comment","author_notahacker","story_15104157"],"author":"notahacker","children":[15104943],"comment_text":"Yup.<p>Reading the article, one would think the idea of using lower cost materials on a construction project was a cunning idea conceived by Margaret Thatcher in 1979. It isn&#x27;t, people substitute cheaper materials on their own very expensive properties all the time, and if councils are really preoccupied with saving money over all else they wouldn&#x27;t have spent \u00a39m on refurbishing Grenfell in the first place. (If you&#x27;ve ever lived in a comparable building, you&#x27;ll understand <i>why</i> fitting insulating cladding was thought to be a good idea...)<p>There are serious questions to be asked about an architectural design which apparently involved flammable lining products in close proximity, a chimney of air and no firegapping between stories should or could have been identified as a fire hazard, there are questions about how it was installed, and questions about whether the council&#x27;s poor communications with the residents over fire safety contributed to fewer evacuations (one of their big concerns was apparently concerns over a gas pipe in the stairwell which appears to be one of the few things that didn&#x27;t go seriously wrong). And there are wider questions about whether standard instructions to stay put are appropriate for the building are appropriate and whether regulations ought to be changed to require mineral wool insulation and&#x2F;or sprinklers on tall buildings in future.<p>It&#x27;s also not a bad time to raise questions about cutting firemen numbers in London even though it isn&#x27;t thought that lack of manpower to tackle the blaze was a problem.<p>But crudely reducing it to a &quot;bad neoliberals hate poor people&quot; to score opportunistic political points actually works against learning those lessons. Poor implementation Grenfell&#x27;s refurbishment programme is no more a scathing indictment of &quot;neoliberalism&quot; than Ronan Point&#x27;s collapse was a scathing indictment of the desire of the government to take the lead in housebuilding following WWII. The construction industry <i>did</i> learn from that one.<p>(Ironically, to the extent that &quot;neoliberalism&quot;, or Thatcherite housing policy, was <i>particularly</i> relevant to this tower block, it was in having the effect of passing some of the leases into the hands of relatively wealthy private owners who had every interest in the building surviving to make a fortune on selling the flats in a few years&#x27; time)","created_at":"2017-08-26T10:45:18Z","created_at_i":1503744318,"objectID":"15104922","parent_id":15104651,"story_id":15104157,"story_title":"London\u2019s Grenfell Tower Fire Was No Ordinary Accident","story_url":"https://www.citylab.com/equity/2017/08/grenfell-was-no-ordinary-accident/536907/","updated_at":"2024-09-20T01:14:47Z"}],"hitsPerPage":20,"nbHits":2,"nbPages":1,"page":0,"params":"query=Stairwell+malware&advancedSyntax=true&analyticsTags=backend","processingTimeMS":15,"processingTimingsMS":{"_request":{"roundTrip":19},"afterFetch":{"merge":{"total":1},"total":2},"fetch":{"query":12,"total":13},"total":15},"query":"Stairwell malware","serverTimeMS":16}
