How Did Cl0p Exploit MOVEit for Data Extortion?

1.0K views
•
September 14, 2023
by
RSAC Cybersecurity
YouTube video player
How Did Cl0p Exploit MOVEit for Data Extortion?

TL;DR

Cl0p exploited MOVEit as part of a coordinated attack that reportedly claimed more than 1,000 companies as victims, along with supply-chain organizations and users. The incident reflects a wider shift from encrypting systems toward stealing data for extortion, making exfiltration detection, application security, backups, and controls around cloud and email data increasingly important defensive priorities.

Transcript

Hello, everyone, and welcome to this installment of our RSAC 365 webcast series. I'm your host, Casey Zerkas, and our guest today is Alex Holden, and he'll be discussing the Cl0p malware and diving into some MOVEit breach analysis. So we're excited to have him. I wanna let you know that there will be time for questions at the end of the presentatio... Read More

Key Insights

  • The MOVEit incident was a coordinated attack that reportedly claimed more than 1,000 companies as victims, along with an uncounted number of affected supply-chain organizations and users. Its scale caught defenders off guard and generated both information and disinformation.
  • Progress responded by telling customers to disable MOVEit's HTTP and HTTPS functions. The company indicated that FTP and secure FTP components could remain operational, illustrating how a severe vulnerability can require selectively shutting down exposed parts of a trusted application.
  • Modern ransomware increasingly emphasizes data exfiltration instead of encryption. The presenter reported that 80 percent of ransomware attacks observed in 2023 involved stealing data without encrypting it, compared with 60 percent of gangs avoiding encryption in 2022.
  • Data encryption is less profitable when defenders maintain better backups and monitor internal movement. Attackers seeking to encrypt broadly must move laterally, escalate privileges, and bypass security tools, creating more opportunities for detection and loss of access.
  • Extortion can succeed through access to a single valuable application or mailbox. Attackers do not always need administrative control over file servers when data from MOVEit, cloud services, or an executive email account can provide sufficient leverage.
  • Ransom payments became less routine as governments classified some ransomware gangs as terror groups and restricted payments to them. The presenter said fewer than 50 percent of companies experiencing ransom attacks were paying, although payment remained a common practice.
  • Cl0p is a Russian-speaking ransomware gang whose name means cockroach in Russian. The group chose the name because it viewed cockroaches as able to survive anything, and its continued operation from 2018 through the 2023 webcast supported that self-image.
  • Cl0p maintained a relatively compact structure comprising about six technical members, two or three technically capable coordinators, two main negotiators, and several members who moved in and out. Its relationships with other ransomware groups were stronger earlier in its history.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How did the MOVEit breach affect organizations?

The MOVEit breach was described as an unprecedented and well-coordinated attack that claimed more than 1,000 companies as victims. The impact extended beyond those direct victims to an uncounted number of organizations and users in their supply chains. The scale of the compromise caught many people off guard and produced substantial confusion, information, and disinformation when it became publicly known.

Q: When did the MOVEit breach become publicly known?

The MOVEit breach became publicly known on May 31, 2023. The webcast took place on August 31, 2023, exactly three months later. During the initial disclosure period, defenders were still trying to understand an unusually broad and coordinated event. Progress, the company that owned MOVEit, responded by publishing instructions that reflected the seriousness of the problem.

Q: What did Progress tell MOVEit customers to disable?

Progress instructed customers to turn off the HTTP and HTTPS portion of its MOVEit software. It stated that the FTP and secure FTP components could remain running. The presenter treated a vendor telling customers to disable part of its own product as a strong indication that something was seriously wrong and that immediate defensive action was necessary.

Q: Why are ransomware gangs moving away from data encryption?

Encryption requires attackers to move laterally through an organization's infrastructure, escalate their privileges, and evade security tools that can detect their activity. Better backups also reduce the victim's dependence on a decryption key. These defensive improvements make encryption less reliable and profitable, so attackers increasingly steal unencrypted information and threaten to release or sell it instead.

Q: What are the three components of ransomware extortion?

The first component is encrypting data after gaining access to a system. The second is exfiltrating an unencrypted copy and threatening to release it if the victim does not pay. The third, still practiced by many groups, is attempting to sell the stolen information to the highest bidder when the victim refuses to make a ransom payment.

Q: What ransomware trend was observed from 2020 to 2023?

In 2020 and 2021, about 50 percent of ransomware attacks included encryption, usually alongside data exfiltration. In 2022, the presenter observed that 60 percent of ransomware gangs did not bother with encryption and focused on exfiltration. In 2023, the reported pattern rose to 80 percent of attacks using data theft without encryption, making exfiltration testing particularly important.

Q: Who is the Cl0p ransomware gang?

Cl0p was described as a Russian-speaking ransomware operation active since 2018. Its name means cockroach in Russian, chosen because the group believed cockroaches could survive anything. It began primarily as an encryption gang and collaborated with groups including DarkSide, Conti, and Trickbot. Its early operations were considered relatively unremarkable and suffered several technical failures.

Q: How is the Cl0p gang organized?

Cl0p reportedly maintained a core technical team of about six people, supported by two or three coordinators who also possessed significant technical skills. The operation appeared to have two principal negotiators, one primary and one secondary, plus several additional members who moved in and out. Its cooperation with other ransomware groups was stronger during its earlier years.

Summary & Key Takeaways

  • The MOVEit breach became publicly known on May 31, 2023, and was described as an unprecedented, coordinated attack affecting more than 1,000 companies, plus supply-chain organizations and users. Progress instructed customers to disable the software's HTTP and HTTPS functions while allowing its FTP and secure FTP components to continue running.

  • Ransomware tactics were shifting from encryption toward direct data theft. The presenter reported that about 50 percent of attacks included encryption in 2020 and 2021, while 60 percent of gangs avoided it in 2022. In 2023, the observed pattern was that 80 percent relied on exfiltration without encryption.

  • Cl0p is a Russian-speaking operation active since 2018. It began primarily as an encryption gang, experienced technical failures, and initially targeted smaller organizations with limited ability to pay. Its structure reportedly included about six technical members, two or three coordinators, two principal negotiators, and several members who moved in and out.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚