Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Ransomware attack shutters Brazilian courts.
#1
https://www.theregister.com/2020/11/06/b...ansomware/       
Security
Ransomware attack shutters Brazilian courts. But did attackers breach the virtual machine divide?
Six-day outage predicted as rebuild commences from untouched backups
Simon Sharwood, APAC Editor Fri 6 Nov 2020 // 04:31 UTC

Brazil’s Superior Tribunal de Justiça has temporarily shut down after a suspected ransomware attack.

The Tribunal (STJ) is second-highest of Brazil’s courts and is the highest court that decides on federal matters other than constitutional law. At the time of writing, the court’s website consists of nothing but a series of updates on the attack. Those notifications state that a virus attack was detected on November 3, when court networks were shut down as a precaution.

The most recent update says data scrambled by the ransomware related to legal proceedings, email, and administrative contracts. The statement says the data has been backed up and that work to restore systems is under way, with court business to resume on Monday November 9. Which will be more than welcome because hundreds of cases have been suspended due to the incident.    Local media report Brazilian president Jair Bolsonaro saying the authorities have identified the culprits.

Brazilian tech news outlet CISO Advisor claims it has viewed an internal report on the incident that suggests it was a deliberate action by organised crime figures, possibly a collaboration between local and offshore players.

The outlet also says that virtual machines were encrypted and deleted, which is explosive as reaching guest VMs suggests a possible compromise of hypervisor security. And hypervisors' big selling point is that they completely isolate guests. An attack that encrypts guests would, theoretically, need to pick them off one by one.

The Register is aware of a similar-sounding case discussed in an October Reddit post alleging that ransomware reached shared storage that holds virtual machine files managed by VMware ESXi. We consulted VMware experts who cast doubt on that scenario as a viable ransomware vector.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack mrtrout 0 7,695 06-20-2023 , 09:05 PM
Last Post: mrtrout
  Maastricht University gets partial ransom back after ransomware attack in 2019 mrtrout 0 539 07-03-2022 , 09:56 PM
Last Post: mrtrout
  Nordic Choice Hotels Turns Ransomware Attack into Success Story mrtrout 0 665 01-18-2022 , 11:18 PM
Last Post: mrtrout
  Sinclair TV stations disrupted across the US after ransomware attack mrtrout 0 628 10-18-2021 , 10:01 PM
Last Post: mrtrout
  Ransomware Attack Creates Cheese Shortages in Netherlands Mohammad.Poorya 0 1,000 04-15-2021 , 07:39 PM
Last Post: Mohammad.Poorya

Forum Jump:


Users browsing this thread: 1 Guest(s)