Chief Paranoia Officer (℠).
Trying to live a little longer but have metastasized atypical BRAF mutation melanoma killing me with pain.
InfoSec at SickKids
hi everyone, this is Agrivane’s wife, with some unfortunate news. He lost his battle this morning and will be missed more than I can say. Big thanks to the #ThanksCancer community for the support
@ThanksCancer except for the times you wish were more lucid, a nurse decided I needed more and dozed me with a bolos dose of morphine without asking, not cool.
@JamesAgombar Not great, admitted to Bridgepoint palliative care and not expecting to go home again.
I don’t know what that means as far as timelines but i’m concerned it’s weeks instead of months at this point. I’m collecting fluids because my lymphatic system and kidneys are both hurt.
I get to go home before I die and we are setting things up to do so. i hope it works for a few weeks at least, @ThanksCancer much better than the hospital, I’ll be with my lady at least.
Let's talk about ransomware for a second.
Ransomware Threat Actors are opportunity driven. They do not have specific targets in mind. If you've got a dollar, they want it.
The reality of the matter, in the ransomware ecosystem, is initial access brokering is cheap and affordable, it is a worthwhile investment for ransomware affiliates to establish a good relationship with an initial access broker.
There is an initial access broker who will sell you roughly 1,000,000 misconfigured VPN's for $1,500. These 'misconfigured' VPNs typically will be companies which have accidentally set a VPN user login to something like 'test' as the username AND password. Although this may sound absurd, or unlikely, these are extremely common as companies may simply overlook small errors. However, these misconfigured VPNs are not curated. Ransomware affiliates might have to spend weeks, or months, sorting through the list determing which companies discovered have:
1. Money
2. Do not violate the rules of the ransomware group
3. Have insufficient security posture
4. Are outside with CIS (ex-soviet countries).
This is often how ransomware groups collide with each other. Two different initial access brokers may have identified (or gotten access) to the exact same organization and then sold this identified vulnerable organization, or access, to two different ransomware groups. There have been stories where ransomware affiliates gain access, only to discover upon entry the organization has already been ransomed!
Companies that have correctly configured EDRs (a detected blue team), a SOC, and have good policy and/or asset control will defeat most ransomware affiliates. More often than not, if an affiliate encounters a company that has a good EDR, or hardened machines, they may simply abandon the target all together (or sell it to a different ransomware operator) because it may not be worth their time. Metaphorically speaking, time is money to the Ransomware Threat Actor.
Regarding targets, there is another aspect often overlooked. Ransomware operators residing outside NATO often do not understand the culture or targets they have identified. For example, we have witnessed ransomware groups target public school systems, failing to understand how the United States allocates money for schools. They mistakenly believe tax-funded schools are ripe with cash and simply do not believe negotiators when they say the victim doesn't have the money. They rely on publicly available information (often wrong information) from places like Wikipedia or ZoomInfo. They see big numbers and believe that this is the profit margins.
tl;dr if you very seriously want to defeat ransomware, security companies need to understand the financial limitations many organizations face. They do not have the money, or man power, larger companies have to combat an ever evolving threat landscape.
NOTE: There are some caveats to this rant. Every ransomware affiliate will seek different avenues of gaining access. Blah, blah, blah.
Thanks for reading. Have a goodnight (or morning).
If we had a cancer party:
🎈Melanomies are by the pool offering shade umbrellas and swim shirts
🎈 Breast cancer patients are admiring each others scars
🎈 Colon cancer peeps are having a detailed conversation about the food and also their poops
👇👇👇
@Anisha12@defcon Isn’t this exactly what they want you to do? Seems like they are constantly seeking negative attention with these trolling posts that are so blatantly off target it’s silly.
So yesterday I had my first radiotherapy appointment to get marked up etc ready for my treatment starting on the 12th. but I was on the table of the ct scanner for an hour and my back was on fire with the #Cancer in my spine and they were trying to get it accurate for the #breastcancer that's gone through my chest wall and into my back, but after an hour I've been marked and poked and written on I couldn't take it anymore. Because my gp and my pharmacists had failed to give me my morphine Between them though arguing over whose fault it is in the meantime I have no pain relief luckily the senior radiographer took over and she's already called me this morning to say she's speaking to my Dr. Why is nothing ever easy, why are we the ones having to call and sort out shit they e caused putting us in more pain. I literally cried myself to sleep with the pain. Feeling very exhausted, in pain and angry :(