Skip to main content

Explained: How MOVEit Breach Shows Hackers' Interest in File Transfer Tools

Ransom-seeking hackers have increasingly turned a greedy eye toward the world of managed file transfer (MFT) software, plundering the sensitive data being exchanged between organizations and their partners in a bid to win big payouts.

Governments and companies globally are scrambling to deal with the consequences of a mass compromise made public on Thursday that was tied to Progress Software's MOVEit Transfer product. In 2021 Accellion's File Transfer Appliance was exploited by hackers and earlier this year Fortra's GoAnywhere MFT was compromised to steal data from more than 100 companies.

So what is MFT software? And why are hackers so keen to subvert it?

Corporate dropboxes

FTA, GoAnywhere MFT, and MOVEit Transfer are corporate versions of file sharing programs consumers use all the time, like Dropbox or WeTransfer. MFT software often promises the ability to automate the movement of data, transfer documents at scale and provide fine-grained control over who can access what.

Consumer programs might be fine for exchanging files between people but MFT software is what you want to exchange data between systems, said James Lewis, the managing director of UK-based Pro2col, which consults on such systems.

"Dropbox and WeTransfer don't provide the workflow automation that MFT software can," he said.

MFT programs can be tempting targets

Running an extortion operation against a well-defended corporation is reasonably difficult, said Recorded Future analyst Allan Liska. Hackers need to establish a foothold, navigate through their victim's network and exfiltrate data — all while remaining undetected.

By contrast, subverting an MFT program — which typically faces the open internet — was something more akin to knocking over a convenience store, he said.

"If you can get to one of these file transfer points, all the data is right there. Wham. Bam. You go in. You get out."

Hacker tactics are shifting

Scooping up data that way is becoming an increasingly important part of the way hackers operate.

Typical digital extortionists still encrypt a company's network and demands payment to unscramble it. They might also threaten to leak the data in an effort to increase the pressure. But some are now dropping the finicky business of encrypting the data in the first place.

Increasingly, "a lot of ransomware groups want to move away from encrypt-and-extort to just extort," Liska said.

Joe Slowik, a manager with the cybersecurity company Huntress, said the switch to pure extortion was "a potentially smart move."

"It avoids the disruptive element of these incidents that attract law enforcement attention," he said.

© Thomson Reuters 2023
 


Apple unveiled its first mixed reality headset, the Apple Vision Pro, at its annual developer conference, along with new Mac models and upcoming software updates. We discuss all the most important announcements made by the company at WWDC 2023 on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.


from Gadgets 360 https://ift.tt/J8aSNUh

Comments

Popular posts from this blog

Xiaomi Offers Free Xiaomi 12 Pro Upgrade to Mi 11 Ultra Users Facing Wi-Fi Issues

Xiaomi is offering a free upgrade to a Xiaomi 12 Pro for Mi 11 Ultra users who are facing Wi-Fi issues. These users also have the option to further upgrade to the company's latest Xiaomi 13 Pro by paying an extra fee of Rs. 30,000. Just recently, the company extended the warranty of the Mi 11 Ultra alongside other smartphones by two years, after users complained of camera and motherboard issues. The current offer — including the free upgrade and the paid one, is extended to the Mi 11 Ultra users who are having trouble with Wi-Fi on their handsets. The Xiaomi India President Muralikrishnan B announced the offers in a video message via Twitter. He added that the  Mi 11 Ultra users who had previously paid and upgraded their handsets to the Xiaomi 12 Pro will be offered a full refund. They will need to contact the company online or through the nearest Xiaomi service centre. Notably, this refund is only applicable to users who upgraded their handsets due to Wi-Fi issues....

Croma Republic Sale 2024: Discover Exclusive Deals on 7 Popular Items

Get ready for an unbeatable shopping experience at the Croma Republic Sale 2024! As technology enthusiasts and bargain hunters unite, we present to you a curated selection of seven must-have products that will enhance convenience, entertainment, and lifestyle. From cutting-edge smartphones and immersive audio systems to impressive appliances, each product promises value at exclusive sale prices. Dive into this article to discover the top deals, discounted prices, and exciting features of these products, giving you a sneak peek into what awaits you during this sale event. OnePlus Nord CE 3 Lite 5G OnePlus Nord CE 3 Lite 5G is a smartphone with a 6.72-inch LCD display featuring a 120Hz refresh rate, 8GB of RAM, and 256GB of internal storage. Powered by a Qualcomm Snapdragon 695 5G processor, it boasts a 108-megapixel triple rear camera setup and a 16-megapixel front camera. It comes with a 5000mAh battery and 67W fast charging. During the Croma Republic Sale 2024, grab this smartphone ...