HT TECH wants to start sending you push notifications. Click allow to subscribe

When a ransomware attacker isn’t up to snuff- a rookie mistake shows hackers aren't all geniuses

For more than two decades, ransomware attacks have been the bane of corporate IT managers and their CEOs, and a source of much research for cybersecurity professionals.

By: BLOOMBERG
Updated on: Jun 20 2022, 22:27 IST
A ransomware attacker isn’t up to snuff! (MINT_PRINT)

For more than two decades, ransomware attacks have been the bane of corporate IT managers and their CEOs, and a source of much research for cybersecurity professionals. An underground market for hacking and encryption tools has helped such incursions proliferate, but thankfully a recent case shows what we can learn when attackers don’t know what they’re doing. 

Unlike other cyber nuisances, such as viruses, which replicate and cause mayhem, or denial of service attacks, which bring networks to a grinding halt, ransomware is almost impossible to unwind once it’s been deployed successfully. That’s because they use encryption to lock up the files, with a secret decryption key being the only route out. 

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
21% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,749₹24,990
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Rather than try to undo this encryption, most victims just write off the files and restore their systems using backups. This can take days or weeks, assuming the target has good data practices, while still costing millions of dollars. It may be impossible if secure backups don’t exist. And that’s what ransomware attackers are betting on: the losses from restoring systems are so high that a target is willing to pay to get a copy of the digital key, which can decrypt the files and restore everything to normal. 

But what hackers don’t bet on is savvy cybersecurity professionals coming across rookie mistakes in the malware code that lets them reverse the encryption without paying a dime to the assailant.

A group at International Business Machines Corp.’s X-Force team did just that. Taipei-based CyCraft Corp. also managed to find the flaws and offered decryption tools for free.

In an article on IBM’s Security Intelligence website, and a recent presentation at the RSA Security Conference, the researchers outlined how they spotted an error within the code of the Thanos family of ransomware. Prometheus, a variant of Thanos, is believed to have struck at least 30 victims in industries including manufacturing, logistics and finance.

It all centers around randomness. This quality is one of the most important aspects of good encryption because encryption-decryption keys — they usually come as a mathematically linked pair — rely on being almost impossible to guess. And because these digital passwords are so long, a brute-force attack — scrolling through each possible combination to find the one that works — is infeasible.

Unfortunately, machines are terrible at randomness, it’s against their nature. (Computers are incredibly predictable: The same inputs put through the same system will always return the same result.) So to create randomly generated keys, computer scientists have developed pseudorandom number generators that mimic true randomness.(5) When used correctly, these software tools can do a very good job of creating passwords and encryption keys that are hard to crack.

But the writers of Thanos didn’t use those tools properly. Instead, they hard-coded one part of the process, and used the very predictable clock time of the victim computer for another.

Researchers uncovered that first part (it was a sequence of numbers counting from one to eight), and merely had to find how long the computer had been running before the malware was deployed.(4) It took a bit more sleuthing and some hit and miss, but eventually they could make educated guesses. From there, it was just a matter of plugging the numbers together to see if they could create a cryptographic key which would match. And they did. As a result, the malware’s super secret key wasn’t as hard to guess as its developers thought.

Beyond just outlining some clever investigative work by the cyber-intelligence community, the case of Thanos’s faulty encryption reveals a lot about modern hacking. First, as researchers well know, a lot of this malicious software is recycled among a vast community of would-be attackers, many of whom don’t really understand the tools they’re using.  In addition, the people who hack into computer systems and those who write the malware tools — often distinct groups — aren’t always experts in their fields. Using a hard-coded initialization vector is a pretty basic mistake. This means that flaws are often repeated, and offer researchers the kind of digital fingerprints they need to track and defend against growing threats.

As ransomware attacks grow in size and scale, it may be at least some consolation to know that not all hackers are geniuses.

Tim Culpan is a Bloomberg Opinion columnist covering technology in Asia. Previously, he was a technology reporter for Bloomberg News.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 20 Jun, 22:27 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
38% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹24,999₹39,999
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
24% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,699₹12,700
Buy now
11% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹96,999₹108,699
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
23% OFF
HP Envy 13 X360 13 ag0035au 5FP71PA Laptop
  • Dark Ash Silver
  • 8 GB RAM
  • 256 GB SSD
₹69,990₹90,486
Buy now
44% OFF
Asus ROG Flow X13 GV301RE LI201WS Laptop
  • Off Black
  • 32 GB RAM
  • 1 TB SSD
₹84,990₹152,990
Buy now
32% OFF
Asus VivoBook Pro 15 M6500RC HN741WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹65,921₹96,990
Buy now
NEXT ARTICLE BEGINS