How University of Pisa seized for $4.5 million

In November 2021, BlackCat, one of the first ransomware families developed in the Rust computer language, appeared on the scene. It has recently become one of the most active ransomware groups.For Saturday's attack, the crooks produced a ransom letter, giving the university administration until June 16 to pay $4.5 million. This could not have come at a worse moment for beleaguered Italy, which has already seen another ransomware assault disrupt municipal elections in Palermo.The victims were granted exclusive access to a chat thread on the secret browser Tor, which is used to reach the dark web, in order to reply to BlackCat's ransom demands."This sum is necessary to recover access to data that have been encrypted and hence made worthless," according to the message, which CyberSecurity360 saw. BlackCat, also known as ALPHV, has threatened to release the critical material if it is not paid, a practise known as double or triple extortion. CyberSecurity360 approached the University of Pisa for an official response on the incident, but it has not answered as of the time of writing.It has been said that the ransom must be paid in order for the victims to have access to their encrypted file utilising the encryption key given by these criminals. If the ransom was not paid, BlackCat, also known as ALPHV, used a tactic called as double extortion to divulge critical data.They also developed triple extortion to leverage the vulnerability by selling information on the dark web if their demands were not met promptly. CyberSecurity360 approached the University of Pisa for a formal meeting to remedy the data breach, but no response has yet been provided. Nonetheless, a succinct solution has been proposed. As a result, data breaches from this section may be widely accessible if adequate vulnerability management is not implemented. Continuous system and infrastructure scanning Patching software flaws, upgrading systems to the newest version, and employee training should be done on a regular basis at the University to lessen the likelihood of assaults by threat actors.

The Rust programming language aids the ransomware gang in evading detection by traditional security tools and is a hurdle to defenders attempting to reverse engineer the payloads or compare them to comparable patterns. These threat actors often gain access to systems using remote desktop programmes and exploited credentials. In one case, Microsoft detected attackers using an unpatched Exchange server to gain access to the target business. "It took the attackers two weeks from the first penetration to spread ransomware, illustrating the importance of triaging and scoping out alert activity to identify accounts and the breadth of access an attacker got through their activity," the researchers write.

The business also saw two of the most active affiliate groups, DEV-0237 and DEV-0504, using BlackCat. DEV-0237 has been seen spreading Hive, Conti, LockBit 2.0, Revil, and Ryuk, as well as experimenting with the following ransom families: BlackMatter, Conti, LockBit 2.0, Revil, and Ryuk. "Payload swapping is common for some RaaS affiliates to assure company continuity or to maximise profit." Unfortunately for enterprises, increasing adoption increases the difficulty of spotting connected risks," Microsoft stated.

 

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author
Sam
Sam