This week the New York Times released a report warning that a group of Russian hackers going by the name “Evil Corp” has been attempting to exploit the rampant vulnerabilities presented by the US workforce shifting to working from home at remote offices, raising fears that major U.S. brands, news organizations, or even election systems could be disrupted with ransomware attacks. The research, conducted by Symantec, revealed that 31 large U.S. corporations, including Fortune 500 companies and news organizations, have fallen victim to Evil Corp, and those are just the ones we know about.
While the scale of the Evil Corp ransomware attacks is shocking, the threat presented by work from home networks has been well illustrated by Bitsight research. Back in March 2020, when the workforce was just a few weeks into its shift to working from home (which saw up to 85% of workers in some industries start working from home), Bitsight released a report on the dangers presented by remote offices and work from home networks. To briefly recap, what we found was alarming, to say the least. After we took a look at the home networks associated with 41,000 organizations we found:
Malware:
- 3.5x more likely than corporate networks to have at least one family of malware
- 7.5x more likely to have at least five distinct families of malware
- Common families of malware are extremely prevalent including Mirai, which is observed 20x more frequently, and Trickbot which is observed 3.75x more frequently
Services & Remote Management Exposure:
- More than 25% of all devices have one or more services exposed on the internet
- Almost 1 in 7 WFH-RO IP addresses have exposed cable modem control interfaces
Given our findings, the fact that a group of malicious actors is exploiting insecure home networks to attack corporations is not unexpected. What is unexpected however is the scope and sophistication of the attacks, which are somewhat ingenious and perfect for the work from home era. To precisely target their prey, the group is looking for users connecting to the internet through VPN. However, rather than going after the VPN itself, they are merely using it to figure out which organization the user is associated with. Malicious code is then placed on websites, including commerce and news sites, in hopes the user will visit, where it can then be installed when the user is vulnerable.
Once on the endpoint, the group can attempt to connect back to the organization's network and install the ransomware code.
While no active attacks or demands have yet been disclosed, there remains the very real possibility that the economic recovery, or even the upcoming elections, could be interrupted by the activation of the ransomware code -- which could lock users out of voter roll data, critical business systems, and more. “Right now this is all about making money, but the infrastructure they are deploying could be used to wipe out a lot of data — and not just at corporations,” said Eric Chien, Symantec’s technical director.