Conti Ransomware Was Released by the CSA
Joint statement with the FBI and the NSA warns of increased Conti Ransomware attacks
2024-01-17
The cyber threat actors responsible for more than 1000 registered conti ransomware attacks are still active. Tights and cobalt are the two main attack vectors. Although there are currently no specific cyber threats in the United States, the CISA, the FBI, the NSA and the United States Secret Service (USSS) urge all organizations to review all mitigation measures and their views and implement them accordingly.
The use of Conti ransomware programs has increased with more than 400 attacks on US and international organizations, as observed by CISA and the FBI. The attack vector of Conti ransomware consists of file theft, server encryption and ransom payment requests. Conti, malware, ransom attacks against CSA for protection, multi-factor authentication implementation, network segmentation, and a number of operating systems and software related to updating advised. The CSA also released a list of MITRE attack sites and vectors used to assist with ransomware attacks.
Technical Details
Conti is a variant of a ransomware program based on raas (Ransomware as a Service), which differs in different ways. It is believed that Conti developers are paying developers a reward for a successful attack. Their campaigns usually include:
- Sending emails with Trojan horse files over the Remote Desktop Protocol (RDP),
- Finding fake SEO software,
- Promoting on malware distribution networks,
- And exploiting common vulnerabilities.
Recent reports say that Conti’s malware groups are using unsolicited resources to increase privileges and move sideways. They also used an open-source Rclone command-line program to filter the data.
Mitre Attack Techniques
The CSA has a number of MITRE attack methods used by the Conti ransomware group. It also briefly describes how these methods are connected to Conti ransomware attacks and how hackers use them.Some of the assault methods include:
- Attachment Phishing: Spearphishing
- Remote Desktop attack on known legitimate accounts using
- Phishing Link: Spearphishing Link
- Windows Command Shell Native API External Remote Services Process Injection Command and Scripting Interpreter
- Many more, such as brute force.
Mitigations
The NSA, FBI, and CISA have provided various techniques to guard against the Conti Ransomware attack.
- Using Multi-Factor Authentication (MFA) to gain access to remote sources
- Using a DMZ network to eliminate uncontrolled network traffic
- Enforcing Emails with strong anti-spam filtering
- Remove any applications that you don’t want.
- Look into unlicensed software and a variety of other issues.
- The CSA has released a detailed report on the Conti ransomware assault scenario and attack pathways.
- To avoid Conti ransomware attacks, network administrators and cyber security workers are advised to follow the provided advisories.