H1 2023: Ransomware's Pivot to Linux and Vulnerable Drivers

H1 2023: Ransomware's Pivot to Linux and Vulnerable Drivers

insikt-group-logo-updated-3-300x48.png

In the first half of 2023, ransomware attacks surged, with attackers increasingly relying on exploiting vulnerabilities for rapid compromise. Prominent campaigns targeted organizations using vulnerability exploits, such as the VMware ESXi hypervisor breach. This trend was fueled by ransomware groups targeting Linux servers, which allow for faster attacks but present a less user-rich environment than Windows or MacOS, making vulnerability exploitation a priority for initial access.

Prominent malware variants in H1 2023 included LockBit, ALPHV, Royal, ESXiArgs, and Pegasus. Additionally, attackers exploited vulnerable drivers to bypass endpoint detection and response solutions, emphasizing the need to inventory and patch organization-used drivers.

Un événement à impact financier important a été l’exploitation d’une vulnérabilité zero-day affectant la passerelle de sécurité des emails (ESG) de Barracuda, entraînant le remplacement des appliances ESG et des pertes financières substantielles. La redondance dans l’architecture informatique et de sécurité est cruciale. Le reste de 2023 sera probablement marqué par une attaque continue par ransomware via vulnérabilité exploitées et ciblant des conducteurs vulnérables. Les défenseurs devraient optimiser les ressources et les budgets pour éviter la redondance afin de répartir les risques.

Ransomware actors will exploit third-party software vulnerabilities, as demonstrated by the CL0P group's breaches. Defenders should review security policies for third-party software, especially products targeted in H1 2023. Steps include inventorying MFT systems, maintaining robust patch management, and coordinating with vendors for effective vulnerability responses.

Vulnerable drivers are a growing attack vector requiring vigilant tracking, identification of malicious drivers, and regular audits to minimize exploitation. Organizations relying on single security solutions should prioritize redundancy for cyber risk distribution.

Overall, the landscape emphasizes the need for proactive measures to counter ransomware and vulnerability exploits, involving thorough inventorying, patch management, redundancy, and collaborative response strategies.

To read the entire analysis with endnotes, click here to download the report as a PDF.