Polymer

Download free DLP for AI whitepaper

Summary

  • Colonial Pipeline announced that hackers had infiltrated its computer systems with ransomware – malicious code used to seize computers and extract payments from victims.
  • The hackers responsible, known as DarkSide, continue to evolve by day.
  • You need to safeguard your business against this malware using tools like Polymer DLP.

Colonial Pipeline was hacked recently.

The cyberattack that forced the United States’ largest gasoline pipeline shutdown has triggered fresh questions about the vulnerability of the country’s vital infrastructure and businesses at large to cybercriminals.

The breach at Alpharetta, Ga.-based company, is the latest high-profile cyberattack reminder that many of the nation’s businesses aren’t prepared to deal with threats posed by malicious data breaches.

In fact, a study commissioned by Hiscox found that 7 out of 10 American companies are not ready for a cyberattack.

What follows is a rundown of how a criminal gang code-named DarkSide managed to penetrate Colonial’s infrastructure, and the strategy they used – ransomware – is such a persistent threat.

Colonial Pipeline ransomware attack: The possibilities

Infographic showing how ransomware works

Image Source

Colonial Pipeline announced that hackers had infiltrated its computer systems with ransomware – malicious code used to seize computers and extract payments from victims.

The breach pounced on Colonial’s business network, which is used for processes such as reporting data to regulators and managing payrolls.

While the initial attack vector remains unknown, there’s every possibility that an old, most likely unpatched vulnerability in Colonial’s system triggered the event. Other possibilities include:

  • A phishing email that successfully fooled an employee including:
    • Malicious Google Drive links containing an LNK downloader
    • Dropbox links with Zip archives that downloaded the backdoor.
  • Brute force password attack
  • Insider threat
  • An SQL injection vulnerability against Colonial’s Virtual Private Network (VPN) infrastructure

There are three unique sets of tactics, techniques, and procedures (TTP) that DarkSide could have used to take control of the company’s systems. Generally, cybercriminals create persistence in computers and networks through:

  • Command and control (CS) infrastructure
  • Using a backdoor that can execute.NET commands, takes screenshots, and supports keylogging.
  • Downloading and using TeamViewer

Installing ransomware into Colonial’s systems

Upon gaining access, the attackers check the operating system language and install the malware. At this point, they have administrative and privileged access.

They then proceed to use CertUtil.exe and PowerShell.exe files to download and execute the DarkSide code. The attackers will also save a copy of the malware to the hacked device.

Further, the criminals escalate privileges by installing the malware, thereby gaining complete autonomy over the Colonial’s infrastructure. They can achieve this using:

  • Mimikatz – An application used to harvest credentials
  • Vulnerability operating on a Netlogon Remote Protocol, in this case, the CVE-2020-1472. That way, they can run applications on devices in the network.
  • Local Security Authority Subsystem Service (LSASS) process memory dumps. These are memory files carrying domain, passwords, and usernames.

Encrypting files & exfiltrating data

With the malicious code already downloaded and access gained, it is time for cybercriminals to start collecting sensitive data and files. DarkSide made away with 100 gigabytes of data.

Having collected the information they want to hold for ransom, the criminals start to encrypt data using ransomware copy in the shared folder on the first device. That way, they can create a scheduled task to spread the fraudulent code throughout its systems.

The DarkSide code also stops and deletes processes that the organization may need to use.

It is important to mention that the DarkSide gang targeted Colonial’s business side. That means the attack was money-oriented and wasn’t intended to send the pipeline crashing down.

Colonial Pipeline paid a staggering $5 million to Eastern European hackers, according to Bloomberg.

Stats showing ransomware's impact on different industry

Image source

Sure, there are many theories of how the Colonial Pipeline data breach happened – and all could be true. However, we firmly believe that a phishing email was the most likely culprit.

The U.S. Cybersecurity and Infrastructure Agency (CISA) tied the DarkSide gang to other phishing-related attacks dating as far back as 2019. In all the incidents, the criminals used phishing emails to deliver ransomware to their targets.

Also, the cybercriminals were remote (based in Eastern Europe, according to multiple reports), which makes the use of document malware even more probable.

Besides, email is a universal communication tool that binds together the entire industry. And, with the ability to hijack a legitimate account, cybercriminals, and send an email originating from a legitimate domain known to the recipient.

In addition, phishing emails delivered through malicious macros in spreadsheets and documents were responsible for other recent high-profile attacks.

How can you protect your organization against ransomware?

The fact that a high-profile company such as Colonial Pipeline can fall victim to cybercriminals means every organization should work to protect itself against ransomware.

Cybercriminals such as DarkSide continue to evolve by day, which means the time to safeguard your business against document malware using Polymer is now.

Polymer is a data governance solution that monitors and secures sensitive information exchanged on tools such as Dropbox, Slack, GitHub, Zendesk, Teams, and more.

The solution allows you to tame the risk associated with files distributed across collaboration tools while ensuring that your systems run smoothly.  

Polymer is a human-centric data loss prevention (DLP) platform that holistically reduces the risk of data exposure in your SaaS apps and AI tools. In addition to automatically detecting and remediating violations, Polymer coaches your employees to become better data stewards. Try Polymer for free.

SHARE

Get Polymer blog posts delivered to your inbox.

RATU311

thor311 tajen bali

thor311 alternatif

situs toto4d

thor311 toto4d

thor311 akses

ceri188

KUPU178

daftar ceri188

cery188

ceri188

KUPU178

KUPU178

slot gacor

kupu 178

kupu178

ceri1888

ceri188

slot online

hoki311

togel online

ceri188

ding dong

ratu311

slot gacor

kupu178

live casino

kupu178

RATU311

mix parlay

ceri188

judi bola online

thor311 slot

RATU311

HOKI311

HOKI311

THOR311

RATU311

RATU311

KUPU178

THOR311

THOR311

ceri188

ratu311

slot online

hoki311

kupu178

togel online

kupu178

slot gacor

ceri188

judi bola online

ceri188

ratu311

kupu178

RATU311

RATU311

live casino roullete

ceri188

slot pg soft

kupu178

KUPU178

KUPU178

THOR311

THOR311

THOR311

THOR311

RATU311

KUPU178

KUPU178

THOR311

THOR311

THOR311

RATU311

thor311 domino qq

thor311 akses

thor dingdong

THOR311

ceri188

ceri188

KUPU178

RATU311

RATU311

kupu178

kupu178

HOKI311

togel

kupu178

mix parlay

ceri188

slot online

kupu178

THOR311

THOR311

KUPU178

KUPU178

kupu178

hoki311

togel online

kupu178

ceri188

ceri188

www.vrcorporate.in

phbalance.vn

togel hongkong

kupu178

slot gacor

kupu178

kupu178

ceri188

kupu178

RATU311

KUPU178

RATU311

RATU311

slot online

kupu178

THOR311

KUPU178

slot mahjong ways

hoki311

slot gacor

ceri188

kupu178

Casino Baccarat Online

kupu178

kupu178

ceri188

toto macau

KUPU178

Slot Gacor

KUPU178

RATU311

Mahjong ways

KUPU178

THOR311

RATU311

RATU311

RATU311

KUPU178

KUPU178

RATU311

RATU311

RATU311

Toto Togel

KUPU178

CERI188

Slot Sweet Bonanza 2500

KUPU178

RATU311

RATU311

KUPU178 X SLOT777

judi bola online

THOR311

KUPU178 SLOT TERPERCAYA

KUPU178 TOGEL

TOTO 4D MACAU

KUPU178

KUPU178

THOR311

HOKI311

KUPU178

RATU311

Slot Mahjong Ways

KUPU178

CERI188

Slot Online Resmi

KUPU178

RATU311 SLOT ONLINE

KUPU178

KUPU178: Link Akses Resmi

KUPU178: Strategi Menang Di Game Live Casino

KUPU178

KUPU178: Minimal 200 Rupiah

THOR311

THOR311

THOR311

THOR311

THOR311

KUPU178

Slot Thailand

CERI188

CERI188

THOR311 RTP

RATU311

RATU311

CERI188

KUPU178 TOTO SLOT

CERI188 TOTO Singapore

THOR311

CERI188

RATU311: Alternatif karnpuracollege

Thor311 Terbaru

THOR311 MAHJONG

RATU311: BONUS SABUNG AYAM

CERI188: Masuk Akun Slot Super Cepat

CERI188

CERI188

THOR311

HOKI311

HOKI311

RATU311

HOKI311

KUPU178

RATU311

RATU311

RATU311

THOR311

CERI188

CERI188

RATU311

RATU311

RATU311

Game Thor311

HOKI311

HOKI311

RATU311

HOKI311

HOKI311

THOR311

RATU311 NONTON BOLA

HOKI311 Link QRIS EWALLET

RATU311

HOKI311 Link Apk Resmi

CERI188

RATU311 judi bola

KUPU178

HOKI311

RATU311

THOR311

HOKI311

KUPU178

KUPU178

KUPU178

RATU311

RATU311

KUPU178

THOR311

KUPU178

RATU311

THOR311