{"id":7591,"date":"2020-10-15T21:31:26","date_gmt":"2020-10-16T04:31:26","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?p=7591"},"modified":"2023-04-05T12:42:49","modified_gmt":"2023-04-05T19:42:49","slug":"cyber-hygiene-ransomware-is-causing-critical-care-disruption-in-hospitals","status":"publish","type":"post","link":"https:\/\/webdev.securin.xyz\/articles\/cyber-hygiene-ransomware-is-causing-critical-care-disruption-in-hospitals\/","title":{"rendered":"Cyber Hygiene: Ransomware is Causing Critical Care Disruption in Hospitals"},"content":{"rendered":"
We analyzed three ransomware incidents (Ryuk, Revil & AKO) and found 16 CVEs associated with them. Incidentally, CSW warned about four of these CVEs in our cyber risk series way back in March 2020!<\/span><\/strong><\/span><\/p><\/blockquote>\n
Hospitals all over the world, stringently follow infection management protocols such as hand washing, sterilization of gowns, face masks & shields, continuous sterilization of equipment and devices to ensure proper protection for patients and doctors alike.<\/span><\/span><\/p>\n
If only health care workers, doctors, nurses and hospital employees could extend the same principles to cyber hygiene, we wouldn\u2019t be seeing a spate of Ransomware attacks sweeping all over the world.<\/span><\/span><\/p>\n
Last week, Universal Health Services was attacked by Ryuk Ransomware, leading to a shutdown of the network in over 250 hospitals all over the US.<\/span><\/span><\/p>\n
Investigations revealed that Ryuk ransomware has infected their systems. Ryuk attackers trick users into opening malicious links and they use vulnerable Internet Explorer browsers to exploit and deliver malware.<\/span><\/span><\/p>\n
Ryuk exploits the following vulnerabilities –<\/span><\/span><\/p>\n
\n
- CVE-2013-2618<\/a> (Network Weathermap HTML Injection Vulnerability),<\/span><\/span><\/li>\n
- CVE-2017-6884<\/a> (Zyxel EMG2926 home router OS Command Injection Vulnerability)<\/span><\/span><\/li>\n
- CVE-2018-8389<\/a> (Internet Explorer Remote Code Execution Vulnerability)<\/span><\/span><\/li>\n
- CVE-2018-12808<\/a> (Adobe Acrobat and Reader Arbitrary Code Execution Vulnerability)<\/span><\/span><\/li>\n<\/ul>\n
It\u2019s high time that hospitals and health care centers take cyber hygiene seriously because a ransomware attack is not a pesky technical problem anymore. It can take lives. It already has.<\/span><\/span><\/strong><\/p><\/blockquote>\n
Last month, D\u00fcsseldorf University Hospital (Germany) was attacked by Revil through Citrix\u2019s VPN server vulnerability CVE-2019-19781<\/a>.\u00a0<\/span><\/span>This ransomware attack led to the death of a patient – making this incident first recorded fatality caused by a ransomware.<\/span><\/span><\/p>\n
Revil exploits vulnerabilities such as –<\/span><\/span><\/p>\n
\n
- CVE-2019-2725<\/a> (Oracle Weblogic Vulnerability)<\/span><\/span><\/li>\n
- CVE-2019-19781<\/a> (Citrix ADC and Citrix NetScaler Gateway Arbitrary Code Execution)<\/span><\/span><\/li>\n
- CVE-2018-8453<\/a> (Window 10 and Windows Server vulnerability)<\/span><\/span><\/li>\n<\/ul>\n
Earlier last month, the AKO ransomware attack on Children\u2019s Minnesota and Allina Health hospitals led to the exposure of over 160,000 patients\u2019 records through a cloud computing company called Blackbaud that manages the hospital’s database.\u00a0 AKO ransomware uses Citrix vulnerability CVE-2019-19781<\/a>\u00a0to deliver ransomware.<\/span><\/span><\/p>\n
Cyber hygiene and a lack of awareness about cyber security is being exploited by these malicious actors who don\u2019t think twice before attacking a hospital during pandemic times.<\/span><\/span><\/p>\n
Our research has revealed that there are many state-sponsored groups that are using Ryuk and Revil to take down health care centers and hospitals in Europe, UK, US etc. <\/span><\/span><\/strong><\/p><\/blockquote>\n
\n
\n <\/h3>\n<\/caption>\n\n
\n \nRansomware<\/th>\n CVEs<\/th>\n APT Groups<\/th>\n<\/tr>\n<\/thead>\n \n Ryuk<\/td>\n CVE-2017-0143<\/td>\n Calypso<\/td>\n<\/tr>\n \n CVE-2017-0144<\/td>\n Shadow Brokers<\/td>\n<\/tr>\n \n CVE-2017-0145<\/td>\n APT3 (Chinese Group)<\/td>\n<\/tr>\n \n Revil<\/td>\n CVE-2019-2725<\/td>\n GOLD SOUTHFIELD threat group<\/td>\n<\/tr>\n \n CVE-2019-19781<\/td>\n<\/tr>\n \n CVE-2018-8453<\/td>\n<\/tr>\n \n AKO<\/td>\n CVE-2019-19781<\/td>\n APT41 (Chinese Actor)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n \u00a0<\/span>We urge hospitals and health centers to patch these CVEs without further delay.<\/span><\/span><\/p>\n
<\/p>\n