Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

"The four building blocks of the universe are fire, water, gravel and vinyl." -- Dave Barry


computers / comp.os.linux.misc / Now It's Kaseya Injecting Ransomware

SubjectAuthor
* Now It's Kaseya Injecting Ransomwareskreez214
+- Re: Now It's Kaseya Injecting RansomwareAndrei Z.
+* Re: Now It's Kaseya Injecting RansomwareAragorn
|`* Re: Now It's Kaseya Injecting RansomwareFifthRootOfPi
| `* Re: Now It's Kaseya Injecting RansomwareJohn McCue
|  `* Re: Now It's Kaseya Injecting RansomwareHarold Stevens
|   `- Re: Now It's Kaseya Injecting RansomwareFifthRootOfPi
`- Re: Now It's Kaseya Injecting RansomwareAndrei Z.

1
Now It's Kaseya Injecting Ransomware

<k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5314&group=comp.os.linux.misc#5314

  copy link   Newsgroups: comp.os.linux.misc comp.os.linux
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!4.us.feeder.erje.net!2.eu.feeder.erje.net!feeder.erje.net!news.uzoreto.com!tr1.eu1.usenetexpress.com!feeder.usenetexpress.com!tr2.iad1.usenetexpress.com!border1.nntp.dca1.giganews.com!nntp.giganews.com!buffer1.nntp.dca1.giganews.com!nntp.earthlink.com!news.earthlink.com.POSTED!not-for-mail
NNTP-Posting-Date: Sat, 03 Jul 2021 19:39:54 -0500
Newsgroups: comp.os.linux.misc,comp.os.linux
X-Mozilla-News-Host: news://news.west.earthlink.net:119
From: skr...@tenplat.org (skreez214)
Subject: Now It's Kaseya Injecting Ransomware
Date: Sat, 3 Jul 2021 20:39:52 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.9.1
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Message-ID: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com>
Lines: 25
X-Usenet-Provider: http://www.giganews.com
NNTP-Posting-Host: 98.77.165.195
X-Trace: sv3-n9Lc20p5Zr/OxrMpKvjSSLQ8HGNreKLWoMUrLBIrAKcGBEa9XJrAvsgE5kbQ0a8zjeg7//+H0NKB9Th!K3AgGplMDMGtd3iC8QPG4p1eEDzHd7DSkkxc/8mszcVt7ikJPr9lgirA91jcqVouFBqlxqlxWH0/!/65oKMyUSHVIbiMnSnNE
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 2028
 by: skreez214 - Sun, 4 Jul 2021 00:39 UTC

dw.com

US technology company Kaseya urged customers to shut down their servers
on Friday after cyberattackers smuggled ransomware onto its network
platform.

The REvil gang, a major Russian-speaking ransomware syndicate, appears
to be behind the attack, said John Hammond of the security firm Huntress
Labs. He added that the criminals used Kaseya's network-management
package as a conduit to spread the ransomware through cloud-service
providers.

Huntress Labs said on Saturday that the software was manipulated "to
encrypt more than 1,000 companies."

- - -

Yes, yes, that wonderful remote server-management
software just makes life so GOOD - for the hackers.

Hire real sysadmins - no more software that can
administer a rectal injection of malware into
thousands of systems at once. That's proven
professional malpractice at this point - costing
millions, soon billions.

Re: Now It's Kaseya Injecting Ransomware

<sbrrsp$16tb$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5315&group=comp.os.linux.misc#5315

  copy link   Newsgroups: comp.os.linux.misc comp.os.linux
Path: i2pn2.org!i2pn.org!aioe.org!TwJB94PmHtFGoZ16HY1FNw.user.gioia.aioe.org.POSTED!not-for-mail
From: no-em...@invalid.invalid (Andrei Z.)
Newsgroups: comp.os.linux.misc,comp.os.linux
Subject: Re: Now It's Kaseya Injecting Ransomware
Date: Sun, 4 Jul 2021 11:35:37 +0300
Organization: Aioe.org NNTP Server
Lines: 31
Message-ID: <sbrrsp$16tb$1@gioia.aioe.org>
References: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com>
NNTP-Posting-Host: TwJB94PmHtFGoZ16HY1FNw.user.gioia.aioe.org
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Complaints-To: abuse@aioe.org
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.11.0
Content-Language: en-GB
X-Notice: Filtered by postfilter v. 0.9.2
 by: Andrei Z. - Sun, 4 Jul 2021 08:35 UTC

skreez214 wrote:
> dw.com
>
> US technology company Kaseya urged customers to shut down their servers
> on Friday after cyberattackers smuggled ransomware onto its network
> platform.
>
> The REvil gang, a major Russian-speaking ransomware syndicate, appears
> to be behind the attack, said John Hammond of the security firm Huntress
> Labs. He added that the criminals used Kaseya's network-management
> package as a conduit to spread the ransomware through cloud-service
> providers.
>
> Huntress Labs said on Saturday that the software was manipulated "to
> encrypt more than 1,000 companies."
>
> - - -
>
> Yes, yes, that wonderful remote server-management
> software just makes life so GOOD - for the hackers.
>
> Hire real sysadmins - no more software that can
> administer a rectal injection of malware into
> thousands of systems at once. That's proven
> professional malpractice at this point - costing
> millions, soon billions.

'I scrounged through the trash heaps... now I'm a millionaire:' An
interview with REvil's Unknown

https://therecord.media/i-scrounged-through-the-trash-heaps-now-im-a-millionaire-an-interview-with-revils-unknown/

Re: Now It's Kaseya Injecting Ransomware

<20210704124615.637e603f@nx-74205>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5316&group=comp.os.linux.misc#5316

  copy link   Newsgroups: comp.os.linux.misc comp.os.linux
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: thoron...@telenet.be (Aragorn)
Newsgroups: comp.os.linux.misc,comp.os.linux
Subject: Re: Now It's Kaseya Injecting Ransomware
Date: Sun, 4 Jul 2021 12:46:15 +0200
Organization: A noiseless patient Strider
Lines: 14
Message-ID: <20210704124615.637e603f@nx-74205>
References: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Injection-Info: reader02.eternal-september.org; posting-host="9368d59e0f81a37eb2655ae4936d744c";
logging-data="18603"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18xW9OZIezppFf4terszdVS"
Cancel-Lock: sha1:6V2JTF1m3OsUXnpz0KZ1HoH9yr0=
X-Newsreader: Claws Mail 3.17.8 (GTK+ 2.24.33; x86_64-pc-linux-gnu)
 by: Aragorn - Sun, 4 Jul 2021 10:46 UTC

On 03.07.2021 at 20:39, skreez214 scribbled:

> The REvil gang, a major Russian-speaking ransomware syndicate,
> appears to be behind the attack, said John Hammond of the security
> firm Huntress Labs.

He's in security now? I thought he had already long retired, and
especially after the fiasco with those dinosaurs on that island near
Costa Rica.

--
With respect,
= Aragorn =

Re: Now It's Kaseya Injecting Ransomware

<wpidnfr2H-HZfn79nZ2dnUU7-TvNnZ2d@earthlink.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5317&group=comp.os.linux.misc#5317

  copy link   Newsgroups: comp.os.linux.misc comp.os.linux
Path: i2pn2.org!rocksolid2!news.neodome.net!weretis.net!feeder8.news.weretis.net!news.uzoreto.com!tr2.eu1.usenetexpress.com!feeder.usenetexpress.com!tr3.iad1.usenetexpress.com!border1.nntp.dca1.giganews.com!nntp.giganews.com!buffer1.nntp.dca1.giganews.com!buffer2.nntp.dca1.giganews.com!nntp.earthlink.com!news.earthlink.com.POSTED!not-for-mail
NNTP-Posting-Date: Mon, 05 Jul 2021 23:59:47 -0500
Subject: Re: Now It's Kaseya Injecting Ransomware
Newsgroups: comp.os.linux.misc,comp.os.linux
References: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com> <20210704124615.637e603f@nx-74205>
From: 5thRtOfP...@nowhere (FifthRootOfPi)
Date: Tue, 6 Jul 2021 00:59:46 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.9.1
MIME-Version: 1.0
In-Reply-To: <20210704124615.637e603f@nx-74205>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Message-ID: <wpidnfr2H-HZfn79nZ2dnUU7-TvNnZ2d@earthlink.com>
Lines: 17
X-Usenet-Provider: http://www.giganews.com
NNTP-Posting-Host: 98.77.165.195
X-Trace: sv3-mP9sB8Jof7shtj+lKNYhMRvXNNr67U7meA5PrZgjWFN3vfWO4/b90zQfGEIr4O4E/xwDa9Zu3I4Wnog!PN2wffm04iy71rBWc7Zk7og++7bLw8J0FtmZVfH+L8x7gfez4rKermSDH8T8hSjKfFlPxMhjKSeU!UpOoy9x6/hFPhTyRPSkV
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 1904
 by: FifthRootOfPi - Tue, 6 Jul 2021 04:59 UTC

On 07/04/2021 06:46 AM, Aragorn wrote:
> On 03.07.2021 at 20:39, skreez214 scribbled:
>
>> The REvil gang, a major Russian-speaking ransomware syndicate,
>> appears to be behind the attack, said John Hammond of the security
>> firm Huntress Labs.
>
> He's in security now? I thought he had already long retired, and
> especially after the fiasco with those dinosaurs on that island near
> Costa Rica.

Well, dinosaurs ... bad investment. Too much upkeep :-)

But I'm not kidding about remote-management software.
It's a knife in your back. It is professional malpractice.
Hire HUMANS at the local levels. Have THEM install the
various updates and such.

Re: Now It's Kaseya Injecting Ransomware

<sc1q4m$aq3$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5318&group=comp.os.linux.misc#5318

  copy link   Newsgroups: comp.os.linux.misc comp.os.linux
Path: i2pn2.org!i2pn.org!aioe.org!TwJB94PmHtFGoZ16HY1FNw.user.gioia.aioe.org.POSTED!not-for-mail
From: no-em...@invalid.invalid (Andrei Z.)
Newsgroups: comp.os.linux.misc,comp.os.linux
Subject: Re: Now It's Kaseya Injecting Ransomware
Date: Tue, 6 Jul 2021 17:42:31 +0300
Organization: Aioe.org NNTP Server
Lines: 23
Message-ID: <sc1q4m$aq3$1@gioia.aioe.org>
References: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com>
NNTP-Posting-Host: TwJB94PmHtFGoZ16HY1FNw.user.gioia.aioe.org
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
X-Complaints-To: abuse@aioe.org
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101
Thunderbird/78.11.0
Content-Language: en-GB
X-Notice: Filtered by postfilter v. 0.9.2
 by: Andrei Z. - Tue, 6 Jul 2021 14:42 UTC

skreez214 wrote:
> dw.com
>
> US technology company Kaseya urged customers to shut down their servers
> on Friday after cyberattackers smuggled ransomware onto its network
> platform.
>
> The REvil gang, a major Russian-speaking ransomware syndicate, appears
> to be behind the attack, said John Hammond of the security firm Huntress
> Labs. He added that the criminals used Kaseya's network-management
> package as a conduit to spread the ransomware through cloud-service
> providers.
>
> Huntress Labs said on Saturday that the software was manipulated "to
> encrypt more than 1,000 companies."
>
<snip>

Incident Overview & Technical Details – Kaseya
https://helpdesk.kaseya.com/hc/en-gb/articles/4403584098961

Remote code execution in Kaseya VSA
https://www.cybersecurity-help.cz/vdb/SB2021070501

Re: Now It's Kaseya Injecting Ransomware

<sc1v2c$q0d$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5319&group=comp.os.linux.misc#5319

  copy link   Newsgroups: comp.os.linux.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: jmc...@obsd2.mhome.org (John McCue)
Newsgroups: comp.os.linux.misc
Subject: Re: Now It's Kaseya Injecting Ransomware
Date: Tue, 6 Jul 2021 16:06:36 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 23
Message-ID: <sc1v2c$q0d$1@dont-email.me>
References: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com> <20210704124615.637e603f@nx-74205> <wpidnfr2H-HZfn79nZ2dnUU7-TvNnZ2d@earthlink.com>
Reply-To: jmclnx@SPAMisBADgmail.com
Injection-Date: Tue, 6 Jul 2021 16:06:36 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="50168c2c163053dfa899ddf15db8a4a0";
logging-data="26637"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+DEbnLzqS+WmJW/eMVYJLr"
User-Agent: tin/2.4.4-20191224 ("Millburn") (OpenBSD/6.9 (amd64))
Cancel-Lock: sha1:bljlf7SV2nae3yYFLAhDHYAknZU=
X-OS-Version: OpenBSD 6.9 amd64
 by: John McCue - Tue, 6 Jul 2021 16:06 UTC

trimmed, removed comp.os.linux since that is not on my server

FifthRootOfPi <5thRtOfPi.net> wrote:
> On 07/04/2021 06:46 AM, Aragorn wrote:
<snip>

>But I'm not kidding about remote-management software.
>It's a knife in your back. It is professional malpractice.
>Hire HUMANS at the local levels. Have THEM install the
>various updates and such.

I fully agree, 30 years ago people managed to function
without remote software. All they had to do was hire
people. But that decreases the CEO Bonus, so we all
know this trend will never stop.

Putting critical systems on the internet to save a few
$ is incompetent, but these companies do *not* even get
embarrassed any more, never mind loosing some of their
bottom line. They just make their customers pay to
make up the difference.

Re: Now It's Kaseya Injecting Ransomware

<slrnse9lbs.21b.wookie@debian.localdomain>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5320&group=comp.os.linux.misc#5320

  copy link   Newsgroups: comp.os.linux.misc
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!newsfeed.xs4all.nl!newsfeed8.news.xs4all.nl!news-out.netnews.com!news.alt.net!fdc3.netnews.com!peer01.ams1!peer.ams1.xlned.com!news.xlned.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx07.iad.POSTED!not-for-mail
Newsgroups: comp.os.linux.misc
From: woo...@debian.localdomain (Harold Stevens)
Subject: Re: Now It's Kaseya Injecting Ransomware
References: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com>
<20210704124615.637e603f@nx-74205>
<wpidnfr2H-HZfn79nZ2dnUU7-TvNnZ2d@earthlink.com>
<sc1v2c$q0d$1@dont-email.me>
X-News.Software.Readers: a tiny side-show, Google Groups is the main event.
X-spambot-trap: ** PLEASE SEE SIG ** (Ignoring Posts Via Google)
X-Usenet-Improvement-Project: http://twovoyagers.com/improve-usenet.org/
X-HWJP: How Would Jesus Post? (Thanks, Blinky, and RIP)
X-Slrn: Why use anything else?
User-Agent: slrn/1.0.3 (Linux)
Message-ID: <slrnse9lbs.21b.wookie@debian.localdomain>
Lines: 36
X-Complaints-To: abuse@usenetserver.com
NNTP-Posting-Date: Tue, 06 Jul 2021 22:13:16 UTC
Organization: UsenetServer - www.usenetserver.com
Date: Tue, 6 Jul 2021 17:13:16 -0500
X-Received-Bytes: 2481
 by: Harold Stevens - Tue, 6 Jul 2021 22:13 UTC

In <sc1v2c$q0d$1@dont-email.me> John McCue:

> incompetent, but these companies do *not* even get
> embarrassed any more, never mind loosing some of their
> bottom line. They just make their customers pay to
> make up the difference.

Exactly. The Equifax meltdown was the last straw for me.

It was crystal clear to me Equifax not only didn't care one
iota about system security. They also didn't care about the
havoc they wreaked with customers' livea and finances.

The penalties invovled for the criminal negligence amounted
to ludicrous wrist slaps.

Just for starters, useless "free credit monitoring" is like
insurance companies handing out hammers and nails after the
house burned down.

Victims were left totally on their own in cleaning up their
ruined credit and fending off collection agencies. For some
it took years, and very often was never fully resolved.

Now, malware is moving from purely financial losses, to the
realm of outright physically threatening cyber warfare (the
Colonial Pipeline debacle).

None of these companies will even start to care until their
top dawgs go to jail for deliberately enabling malware.

--
Regards, Weird (Harold Stevens) * IMPORTANT EMAIL INFO FOLLOWS *
Pardon any bogus email addresses (wookie) in place for spambots.
Really, it's (wyrd) at att, dotted with net. * DO NOT SPAM IT. *
I toss GoogleGroup (http://twovoyagers.com/improve-usenet.org/).

Re: Now It's Kaseya Injecting Ransomware

<7NSdnfVHR4cchHj9nZ2dnUU7-T3NnZ2d@earthlink.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5322&group=comp.os.linux.misc#5322

  copy link   Newsgroups: comp.os.linux.misc
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!tr2.eu1.usenetexpress.com!feeder.usenetexpress.com!tr1.iad1.usenetexpress.com!border1.nntp.dca1.giganews.com!nntp.giganews.com!buffer1.nntp.dca1.giganews.com!nntp.earthlink.com!news.earthlink.com.POSTED!not-for-mail
NNTP-Posting-Date: Tue, 06 Jul 2021 22:03:28 -0500
Subject: Re: Now It's Kaseya Injecting Ransomware
Newsgroups: comp.os.linux.misc
References: <k_adnTbvmJfHnnz9nZ2dnUU7-WfNnZ2d@earthlink.com> <20210704124615.637e603f@nx-74205> <wpidnfr2H-HZfn79nZ2dnUU7-TvNnZ2d@earthlink.com> <sc1v2c$q0d$1@dont-email.me> <slrnse9lbs.21b.wookie@debian.localdomain>
From: 5thRtOfP...@nowhere (FifthRootOfPi)
Date: Tue, 6 Jul 2021 23:03:27 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.9.1
MIME-Version: 1.0
In-Reply-To: <slrnse9lbs.21b.wookie@debian.localdomain>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Message-ID: <7NSdnfVHR4cchHj9nZ2dnUU7-T3NnZ2d@earthlink.com>
Lines: 52
X-Usenet-Provider: http://www.giganews.com
NNTP-Posting-Host: 98.77.165.195
X-Trace: sv3-FP7PMpj4Rk5SE4sTX/mfGZTCFppBBnlRTcRAjv7WBsbYsNFTCcKTPQHmDtBsZYpdf2glXvk37Xgx3yR!E8n4OIdz/5t7Jjm7l4Qk+vqh7qPrjWDhnrklDgNFe22Qq4MwjCTZ8FoQySrRm1UNqFbBY8K1+axs!20Qk4gOhpWWdigyACNi9
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 3506
 by: FifthRootOfPi - Wed, 7 Jul 2021 03:03 UTC

On 07/06/2021 06:13 PM, Harold Stevens wrote:
> In <sc1v2c$q0d$1@dont-email.me> John McCue:
>
>> incompetent, but these companies do *not* even get
>> embarrassed any more, never mind loosing some of their
>> bottom line. They just make their customers pay to
>> make up the difference.
>
> Exactly. The Equifax meltdown was the last straw for me.
>
> It was crystal clear to me Equifax not only didn't care one
> iota about system security. They also didn't care about the
> havoc they wreaked with customers' livea and finances.
>
> The penalties invovled for the criminal negligence amounted
> to ludicrous wrist slaps.
>
> Just for starters, useless "free credit monitoring" is like
> insurance companies handing out hammers and nails after the
> house burned down.
>
> Victims were left totally on their own in cleaning up their
> ruined credit and fending off collection agencies. For some
> it took years, and very often was never fully resolved.
>
> Now, malware is moving from purely financial losses, to the
> realm of outright physically threatening cyber warfare (the
> Colonial Pipeline debacle).
>
> None of these companies will even start to care until their
> top dawgs go to jail for deliberately enabling malware.

But these are the people who OWN a pockeful of senators,
congresscritters and judges. With money, and/or some
level of "indespensibility", the chances of these CEOs
and boards facing any serious penalties are very low.
The board will just offer up a human sacrifice or two
and that'll satisfy everybody important.

Re-read your Machiavelli - especially his 'Discourses'.
That's how things REALLY work. Have for thousands of
years. Your only good defense ; become ONE of them.

Unfortunately, it is now essentially impossible to NOT
have a substantial online shadow. I suppose you could
move to Congo or Afghanistan or into the depths of
the Amazon and just disappear off the radar, but it
won't be much of a life. Your best weapon is lawyers
who specialize in gouging those who gouged you. They
WILL take a fat cut though .....

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor