This week on the podcast, we cover the key takeaways from the 2024 Verizon Data Breach Investigations Report. Before that, we discuss what we learned from United Healthcare CEO Andrew Witty's congressional testimony on their ransomware attack in February. We also discuss a research article from JFrog on malicious Docker Hub repositories.

Hey everyone, welcome back to the 443 security simplify. I'm your host Mark liberty and joining me today is

Just good old Corey old guy Nachreiner. I'm old and tired and cynical.

Someone sent Corey a cup of coffee and like a Snickers bar.

Let's talk about the same old security crap that happens over and over again because people don't listen to basic advice and then keeps on happening again and again. And we're all in Groundhog's Day and my alarm is gonna go off and there's another breach and credential leak and no MFA.

I thought I was the cynical one. On today's episode, we will discuss a recent ransomware attack that Korea is heavily hinting at having a very simple cause and very preventable cause. After that, we'll go over some research into a Docker Hub analysis on a massive amount of malicious Docker Hub repositories.

Connect to the International Space Station Docker hubs,

yes, this episode from space. But after all, that, we will dive headfirst into the Verizon data breach investigations report for 2024. And including some of the key takeaways for this year from data breach and just breach trends that Verizon analyzed from massive amounts of data, including data from WatchGuard. With that, let's go ahead and

Dr. Roll on in scroll through 100 pages trying to find the rent one random stat mark is talking about?

Yes, let's do that. So let's start this week with an update on a story we chatted about. Man, this would have been in February, I believe. And again in March, where if you remember back in February change healthcare, which is owned by UnitedHealth, massive healthcare conglomerate in the US disclosed that they had been the victim of a ransomware attack at the time. And the reason we talked about this twice is I think we talked about the initial incident. And then a few weeks later with the threat actors that did this, or at least the ransomware as a service operator, ALPHV or blackcat kind of dropped off the face of the earth, and we discussed their little exit scam they ran against their customers. But so UnitedHealth CEO Andrew witty, testified in front of Congress last week for about two hours. I imagine he was sweating through everything he was wearing during that because he was getting a firm grilling. About so testified about the change healthcare ransomware attack earlier this year. And the testimony actually gave us a few more interesting details about this incident, and the impact it had. So I'll go through a few of the takeaways, Corey, and I'm curious what your thoughts are on some of these two. So the first one, just starting with a timeline, the attack started actually on February 12, when the attacker used stolen credentials for their initial access to gain access to the organization through a Citrix Remote Access Gateway server. So if you're not familiar with Citrix Remote Access Gateway, it is a server software designed to be exposed to the internet earliest advertise that way to enable remote desktop access into the organization. And, you know, on the face of it, this sounds like a pretty important application to secure and prevent unauthorized access to but then in the case of change healthcare, they were not using multi factor authentication for accounts on the service which allowed the attacker to steal a credential and log straight in pause there for a second Corey, I

think everyone knows our feeling on this. I like you. How could you not if you listen to the podcast, remote management interface, put it on the intranet good idea. Probably not use a VPN instead. But Citrix portal Citrix says do VPN if you're going to put a VPN publicly on the internet. What do you do you add MFA. It's like another story does say it is pretty much cybersecurity one on one at this point. We know that bad guys are targeted. I mean, everything's remote. Now. You know, even companies that have gone back to work have a lot of remote access. You have to secure that crap threat actors know we have remote access. They know it's easy to target and they know how to steal credentials and people are still bad with their credentials. So, MFA is absolutely required. And frankly, other than other than tools specifically designed to secure remote access read VPN or zero trust network access or SSL portals. I don't think you should have any other remote management on the internet at all without a VPN ctma or some sort of SSL portal. So Oh, really the only thing you should be exposing is something made to secure remote access. And that thing Dang, well better be using MFA. So I agree, I think there's still a lot of companies that, you know, it's as much as the surveys even down to the SMB say, oh, yeah, we use MFA da. I still think a lot of companies do not have a whole lot of MFA widely deployed for all their employees yet. And it's clear that even the biggest companies seem to forget, seem to not do this. Is it just the friction still, Mark? What do you think?

I mean, so I understand not having MFA totally, like 100% deployed across an organization that is actually a pretty difficult challenge, especially when you take into account like shadow IT SaaS applications that other like teams or organizations within your company may have gone out and acquired on their own, like, so I understand not getting 100%. But there is a priority when it comes to deploying multifactor authentication. And I feel like the internet exposed gateway that allows direct remote access to computers on your network is probably right up there as number one, for enabling enabling multi factor authentication on. So, you know, I also understand and healthcare specifically, you know, there's plenty of reports about how strapped for IT resources these organizations are, and how sometimes they do have to prioritize just any work at all. But again, if you're gonna have internet connected remote access into your systems, like putting MFA on that seems like step zero for it. Now, their CEO, Mr. Woody didn't disclose exactly how the credential was stolen, but actually another organization. So Hudson rock, their CTO actually claimed that they have threatened diligence sources that indicate that that credential was stolen from a info steal or malware on February 8, so about four days before the attack started. In this case, they posted a screenshot and like a bleeping computer article I saw of their platform identifying that credential associated with change Health's Citrix web portal now, they only indicate a credential of a employee was stolen, not that this was the specific credential that enabled the breach. But the timelines do at least match up. And that is a plausible explanation for how that credential ended up in the attackers hand because that's a pretty common method. For sure. So the attack started February 12. The ransomware wasn't deployed until nine days later after the initial intrusion. So the attacker had time to go scope out the network, look for sensitive data locations exfiltrate that data, because as we discussed originally, and we'll head again later, they attempted to extort change healthcare with the stolen data to and then after they gathered all they went in and deploy the ransomware attack. The attack impacted around 150 million customers, which, if you do the math is about half the population of the United States, which is a pretty dang big impact, because during this time, so change healthcare, they also own what is like optimum RX, or some very popular Prescription Service. And that entire service was down and pharmacies were unable to operate during the course of this ransomware attack. So it did have a pretty big impact to just random people in the United States. The company estimates the cost was $872 million in damages because of the breach. That was a ton of money. And that isn't just you know, the extortion which itself was only 22 million. But you know, the cost of downtime, loss of revenue, the cost of bringing in companies like Mandiant or whoever that was they brought in for incident response to help investigate all that adds up. I imagine some pretty hefty HIPAA violations are probably slapped in there as well to speaking of the ransom extortion though, they did end up paying $22 million to Alfie and I one thing that stood out to me in the deposition or whatever you want to call it the testimony to Congress was so the CEO goes this was entirely my decision to make and I guess that is him just like falling on his sword for a difficult decision. But it does kind of highlight that paying a ransom is a business decision for an organization and I don't know your thoughts Corey, but it's I still firmly believe should not pay ransom. All it does is fund additional cybercrime and incentivize additional cybercrime. But it's easy for me to say right now in a situation where my company is not impacted by a ransomware attack. So I can sympathize.

I can definitely sympathize. To be honest, I don't think this changes my thoughts at all only because it falls within the caveat I I think we've always had, or at least if you remember, ransomware has been targeting healthcare, specifically hospitals forever, including one wanna cry. So I've always been very, very strongly against not paying the ransom. I think people who pay the ransom are just going to increase the business case. But my caveat was always specifically with hospitals, but I could see it with the United Healthcare to that. That is a easier decision for a business that has nothing to do with saving lives to make, right if you're a hospital, you can't get your patient record, surgeons are waiting to do surgery. And you don't have a convenient paper backup. People can die. And so there's always a exception to rule. So caveat. And you know, so with health care, it was the kind of thing I still don't like the fact that, you know, people pay in some cases, but I understand how it can become a very personal decision. Like if this were a let's not, don't don't get me wrong, United Healthcare is a for profit business. And I won't even go down the rabbit hole of how for profit us medical care is, but if this were like some business where Yeah, they were being hurt by the ransomware. But it wasn't really hurting anyone, it'd be, it'd be easier for me on my little ivory tower to judge them. But for health, like for health care, I get it as as someone that is an insurance provider, it's like the first freakin thing anyone asks you even going into a clinic. So it can disrupt a lot of things that has to do with human life. So I understand why they might have to make a hard decision that said, I still don't want to normalize it. I still want this to be something people think thrice about every time, thrice or more, quadruple thrice. I don't know why I picked him three instead of two, two years, it's

not enough to think about it. You were both

saying like, I won't overly judge this CEO, you know, is a health care company. And the metrics are not like when the metrics are just money, then it's hard to know whether it's greed or whatever, or even, you know, I guess you could say it's still a business decision, insurers would argue the loss is less by pain than it is by not, but I think long term that's a crappy business decision, because it encourages the market to continue and your losses will continue to rack up over time. But when the loss is measured in human life or suffering, it's a much different metric. Yeah,

I agree. So if you remember, it was early March, we discussed how ALPHV someone had paid $22 million into a Bitcoin wallet owned by them. And we suspected this was change healthcare paying the ransom extortion demands. And two days after that their public Dark Web website went down with a message saying they'd been seized by the FBI. And as a part of an international effort, and some of those international agencies said, Wait a minute, we did no such thing. So our takeaway at the time was that they had basically pulled the rug and stolen $22 million from their affiliate. Well, so it turns out the the affiliate in this case, actually retained the hospital's data. So after Alfie's exit scam, they kept the data and then partnered with a another ransomware operator called ransom hub, to then go and try and extort the company. And from one of our resident ransomware, experts Ryan on our threat lab team. Yeah, he gave us a bit of a note here saying that ransom hub is a newer group that seems experienced. And his guess is that it's possible they could have some or many the members from Alfie is actual members of this new group, or other forgotten or retired ransom are groups which I thought was an interesting take how this place this organization, Ransom hub just kind of materialized that are nowhere. It and as we've talked about in the past, I have a sneaking suspicion that most of these brands of our operators as they go away, don't permanently go away, and that they most likely come in materializes another one. So, either way, the testimony, it was two hours, it was pretty heated, as I won't say poor CEO, but unfortunate CEO is totally grilled by Congress. And it was interested in getting some of our suspicions confirmed, like the ransom or extortion was paid. And some updates on the timeline and details about the incident. I think if there is one takeaway, it's the one we highlighted at the very beginning of this. Just set up MFA on your important system. So it is that would have protected or at least made it significantly more difficult for this attack to have succeeded.

It's not to say breaches can still happen with other ways. But I mean, this seems to be just the common it's the lowest hanging In fruit we've seen over and over open management, open VPN, no MFA, bam, bam, bam, they've knocked down in 10s of big companies this way. Don't Don't be like them.

Don't be like them do better. So well said. Moving on to the next story. So researchers at J frog published a blog post last week, they had a pretty interesting headline. you giggled, because their name is a bit silly

for a good group if we followed their research before, but I still can't help and giggle every time I heard a frog. Yep.

Anyways, so pretty interesting headline that caught my attention. So they did an analysis of Docker Hub, which if you're not familiar with Docker Hub, it's a repository for Docker images, kind of similar to like other package indexes, like NPM for node packages, or pi pi for Python packages. It's basically a registry, where organizations and developers can post a Docker container image, which is like a fully bundled up micro application. And then maintainers can also post like a short description

I am I define it by saying a Docker image is almost like a cloud VM image, like it's not literally a virtual OS image, but it's like, it is an image of a bunch of components tied to something that you can spin up in the cloud. And it can have multiple applications and connections between them that you've set up for whatever thing you're trying to build. Yes, that is a little stripped down

mini VM, I think is a fair description of it. So on Docker Hub, you can like post your images for other people to go download. For example, you can go download, like the Ubuntu Docker image to get a little mini containerized version of Ubuntu, and so on, so forth. So while analyzing all the public repositories on Docker Hub, J frog found three large scale malware campaigns that planted millions of what they call image list repositories with malicious metadata all over Docker Hub. And when they did the math, this is roughly 20% of all public repositories on Docker Hub hosted some sort of malicious content. And the vast majority of just all image lists, repositories, so ones where they have not actually uploaded a container image yet, were entirely malicious. This is what stood out to me like that is a pretty sizable percentage of a legitimate service to be hosting illegitimate or straight up malicious content. So they went through their analysis steps. They said while analyzing newly added repositories, they noticed a pretty common trend over time, where you would see more repositories created on a daily basis during the week, Monday through Friday, a bit of a dip on the weekends, and then a bit more than next week. It was a pretty flat wave month over month, year over year. But there were these two really big spikes they found in 2021 and 2023, where the number of newly created repositories went up tenfold in Docker Hub. And some of them when they looked at their repositories, they noticed none of them had images actually associated with them. So it was just the kind of entry in the directory itself with some HTML information in there. And when they analyze them further, they found interesting malware and phishing campaigns leveraging these. So for example, some of them are just hosting like a simple phishing site or a phishing link. They give one example, that's advertising oxycontin tablets for sale with a link to a phishing toolkit. But in some of the other ones, they were actually hosting links and automated like dynamic redirect errs to malware downloaders like actual malicious payloads. The malware downloader campaigns came online in two distinct rounds, one in 2021, one and 2023, both of them using the exact same payload called free HTML validator dot exe. This malware, it's a pretty basic downloader image, it beacons back to a command control server to get a configuration that actually checks to see which country it's running in. And it's got a list of four countries which I'll bet you'll never guess what any of those countries are Korea on the face of it, that it makes sure it's not right.

It won't be Russia def definitely Russia is definitely not on that list, right. Because Russia and Azerbaijan

Armenia and Belarus the four amigos, although I guess Azerbaijan and Armenia are not exactly best friends with each other but

we only recently Russia makes sense.

So it checks to make sure that it's not running in one of those countries if it is it stops execution. It also looks for a few specific antivirus engines to things like Avast, or AVG, or even McAfee and it stops running if it sees one of those on the machine too. But assuming all those checks pass that beacons back home, and it goes to download additional malware payloads onto the endpoint. The other campaign, they found is what they were calling an ebook phishing campaign. Were roughly in the middle of 2021. Someone was turning Docker Hub into a pirate ebook library, where they post like big excerpts of a public ebook, and then a link saying you didn't go here to go download the full copy of this ebook. Now that link would send you to a page that ultimately would ask for a credit card information to try and maybe get you to pay $2 for this free ebook, in reality behind the scenes, it was just stealing your credit card info. So J frog worked with Docker, they've been taking down these repositories and putting in additional protections too. But you know, we've talked about especially on like our podcasts, where recovered like internet security reports, how it's increasingly common for threat actors to leverage these legitimate services to host malicious content, like sharehub as a domain where you can go register subdomains and host whatever you want, is a pretty popular target. We've talked about various legitimate Services websites, like especially file hosts that don't have the right, checking for file type for uploads, where attackers will start uploading malware and using them as a command and control or a malware delivery vehicle. It's what stood out to me was seeing Docker hub, a pretty big website being used for a sizable amount of malware to deliver 20% of all repositories versus ciated with these campaigns, because I think in comparison, things like GitHub, there's obviously malicious content on GitHub. There's obviously threat actors using it to deliver content. We just talked last week, the week before, about using GitHub comments as a way to get a legit looking link for malware files. But I'm willing to bet it's not 20% of all GitHub repositories are straight up malicious. So that was interesting. This isn't because they are addressing the issue now they've seen it. But man, yet another way of abusing a legitimate service for hosting stuff. Oriente. What do you think we're gonna see pop up? Next is the avenue for threat actors.

What else do we share a bunch of stuff. I am interesting. My only hot take was, it's clear that this was a Docker Hub being used, but it wasn't actually images containing malicious malware. I even though that's not the case, I wonder if that I mean, what a great way to image essentially spin something up, that's running code to have a service. But if you trojanized it, you could also have a lot of bad stuff going on. So if you could actually compromise legitimate images, I remember a very old WatchGuard prediction, I can't remember if it was right when you joined my team or a bit before where, you know, when, when it was just using virtual images. And even in new laptops, whether you're virtualizing the server or you have a new laptop, you might have a golden image that you either spin up as a new virtual server, or that you use to build your your default laptop image. And I used to have a prediction that threat actors would purposely go after that, quote, unquote, golden image infected with some Trojan, it would still do whatever its job that it expected. But what a great way to affect every server, they spun up from that point. So this is scary enough just using the repository without actually having images in these different repositories. But if they ever get access to common Docker images that people use to just because it's shared open source, you want to provide this, this service, just spin up this Docker image, that would be even more scary, too. So maybe the next step is to go from these empty or not empty, but you know what I mean, non image repositories to actually hijacking a real repository and start trojanized seeing some common images people use who

especially because like, so the way Docker containers and images are built, it's entirely visible, like you can see the whole manifest of what's going on inside of it. If you go to look for it. If you just go blindly download a Docker image, like it just using the Docker command line and like, you know, Docker poll and image name. All you get is the little download bar and it's done and it's running. You don't see what's going on inside of it. And so it would be a really easy way to like you said deliver something malicious to an endpoint if folks aren't reviewing it. Now, my hope is that in a enterprise organization or an enterprise deployment, you aren't just blindly downloading and running Docker images you are inspecting the manifest to see or building your

own. Of course, you are mark, it's the same way when there's open source packages, you're not blindly downloading open source, you're checking it out before you use it in your critical applications, right, Mark, everyone does that all the time, they don't blindly download things.

Corey Nachreiner  25:31  
Marc Laliberte  25:57  
Corey Nachreiner  26:30  
Marc Laliberte  26:43  
Corey Nachreiner  26:51  
Marc Laliberte  26:57  
Corey Nachreiner  28:23  
Marc Laliberte  29:29  
Corey Nachreiner  30:13  
Marc Laliberte  31:25  
Corey Nachreiner  31:49  
Marc Laliberte  31:53  
Corey Nachreiner  31:56  
Marc Laliberte  33:25  
Corey Nachreiner  34:27  
Marc Laliberte  35:32  
Corey Nachreiner  36:43  
Marc Laliberte  38:27  
Corey Nachreiner  39:45  
Marc Laliberte  40:55  
Corey Nachreiner  41:25  
Marc Laliberte  41:37  
Corey Nachreiner  42:12  
Marc Laliberte  42:43  
Corey Nachreiner  42:45  
Marc Laliberte  43:35  
Corey Nachreiner  43:40  
Marc Laliberte  43:53  
Corey Nachreiner  44:53  
Marc Laliberte  45:36  
Corey Nachreiner  45:42  
Marc Laliberte  46:40  
Corey Nachreiner  46:45  
Marc Laliberte  46:50  
Corey Nachreiner  47:17  
Marc Laliberte  48:06  
Corey Nachreiner  48:38  
Marc Laliberte  49:01  
Thanks again for listening.

Thanks again Verizon for another cool report.

If you have any questions on today's content or suggestions for future episode content, you can reach out to us on Instagram. We're at watchguard_technologies. Thanks again for listening.

They should have my puppies Instagram account. It can give me 443 updates there.