• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Flyy Tech
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
Flyy Tech
No Result
View All Result

Hackers behind MGM cyberattack thrash the casino’s incident response

flyytech by flyytech
September 16, 2023
Home Security
Share on FacebookShare on Twitter



In an interesting turn of events, ransomware group ALPHV (aka BlackCat) released a statement on their leak site, thrashing both MGM Resorts International and the cybersecurity firm VX undergrounds for mishandling the ongoing cyberattack on MGM.

In a long message intended “to set the record straight,” ALPHV detailed what has happened in the ransomware seizure of MGM’s critical assets so far, noting MGM hastily locked out key services indicating a poor response team.

“MGM made the hasty decision to shut down each and every one of their Okta Sync servers after learning that we had been lurking in their Okta Agent servers sniffing passwords of people whose passwords couldn’t be cracked from their domain controller hash dumps,” ALPHV said in the message. “This resulted in their Okta being completely out.”

The message also criticized VX Underground for “falsely reporting events that never happened” with regard to the tactics, techniques, and procedures (TTP) used.

ALPHV calls MGM response hasty

ALPHV claimed to have initially infiltrated MGM’s network by exploiting vulnerabilities in the global casino owner’s Okta Agent without deploying any ransomware. They gained super administrator privileges to MGM’s Okta and Global Administrator privileges to their Azure tenant.

In response to network infiltration on Friday, September 8, MGM implemented conditional restrictions on September 10 that barred all access to their Okta environment owing to what ALPHV called “inadequate administrative capabilities and weak incident response playbooks.”

“Due to their network engineers’ lack of understanding of how the network functions, network access was problematic on Saturday,” ALPHV said. “They then made the decision to “take offline” seemingly important components of their infrastructure on Sunday.

Despite infection since Friday, ALPHV only launched ransomware attacks a day after MGM’s shutdown on Sunday (September 11), wherein it seized access to more than 100 ESXI hypervisors in their environment, according to the message. They did so “after trying to get in touch with MGM but failing.”

However, experts like Bobby Cornwell, vice president of strategic partner enablement & integration at SonicWall, believe MGM’s move to shut down was indeed justified. “Out of an abundance of caution, MGM made the right call to lock down all the systems it did, even if it meant inconveniencing its guests as a result of their actions,” Cornwell said.

VX Underground schooled for misinformation

ALPHV called out VX Undergrounds, the cybersecurity research firm that first linked the attack to ALPHV, for misinforming and oversimplifying the TTP(s) deployed in the attack.

“At this point, we have no choice but to criticize VX Underground for falsely reporting events that never happened,” ALPHV said. “They chose to make false attribution claims then leak them to the press when they are still unable to confirm attribution with high degrees of certainty after doing this. The TTPs used by the people they blame for the attacks are known to the public and are relatively easy for anyone to imitate.”

In an X (formerly Twitter) post, VX Underground had said, “All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk. A company valued at $33,900,000,000 was defeated by a 10-minute conversation.”

Uncertainly loom amid insider trading rumors

ALPHV said that an unknown user surfaced in MGM victim chat a few hours after the ransomware was deployed and that they couldn’t link him to MGM as their email inquiries went unanswered. ALPHV posted a link to download exfiltrated materials up until September 12 in the discussion with the user, yet neither the user nor MGM has reacted to deadlines threatening a leak.

ALPHV also alleged dubious activities within MGM, questioning the company’s interest in customer safety. “We believe MGM will not agree to a deal with us,” ALPHV said. “Simply observe their insider trading behavior. No insider has purchased any stock in the past 12 months, while insiders have sold shares for a combined 33 million dollars.”

Uncertainly looms as several of MGM key systems remain shut even days after the attack that came to light on September 10 when the company announced it was forced to shut down many systems due to a cybersecurity issue.

“The fact that the website is still down suggests this was the real prize for the attackers,” Cornwell said. “While gaming systems do have an abundance of elements that a hacker would look for in a ransomware attack, the resort’s website, which allows for bookings of rooms and entertainment does have a far-reaching and very public effect that could lead to a large payday for ransomware actors.”

Incident Response, Ransomware



Source_link

flyytech

flyytech

Next Post
Microsoft Flushes Out ‘Ncurses’ Gremlins

Microsoft Flushes Out 'Ncurses' Gremlins

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

A demon rat and a duck star in this buddy cop RPG

A demon rat and a duck star in this buddy cop RPG

February 20, 2023
Audio for VR & AR: Not What You Think

Audio for VR & AR: Not What You Think

October 2, 2022

Trending.

Three gaming-focused Linux operating systems beat Windows 11 in gaming benchmarks

Three gaming-focused Linux operating systems beat Windows 11 in gaming benchmarks

December 2, 2023
Thermalright Peerless Assassin 120 SE Review: Incredible, Affordable Air Cooling Performance

Thermalright Peerless Assassin 120 SE Review: Incredible, Affordable Air Cooling Performance

September 27, 2022
Baldur’s Gate 3 Slyly Adds Jiggle Physics For D**ks, Balls

Baldur’s Gate 3 Slyly Adds Jiggle Physics For D**ks, Balls

December 2, 2023
Critical ‘LogoFAIL’ Bugs Offer Secure Boot Bypass for Millions of PCs

Critical ‘LogoFAIL’ Bugs Offer Secure Boot Bypass for Millions of PCs

December 3, 2023
Stable Diffusion Benchmarks: 45 Nvidia, AMD, and Intel GPUs Compared

Stable Diffusion Benchmarks: 45 Nvidia, AMD, and Intel GPUs Compared

November 10, 2023

Flyy Tech

Welcome to Flyy Tech The goal of Flyy Tech is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Follow Us

Categories

  • Apple
  • Applications
  • Audio
  • Camera
  • Computers
  • Cooking
  • Entertainment
  • Fitness
  • Gaming
  • Laptop
  • lifestyle
  • Literature
  • Microsoft
  • Music
  • Podcasts
  • Review
  • Security
  • Smartphone
  • Travel
  • Uncategorized
  • Vlogs

Site Links

  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Recent News

Spotify shoots down big rumor; it still will not allow in-app purchases via the App Store

Spotify shoots down big rumor; it still will not allow in-app purchases via the App Store

December 9, 2023
Xbox Insider Release Notes – Alpha (2402.231117-1810)

Xbox Insider Release Notes – Alpha (2402.231206-2000)

December 9, 2023

Copyright © 2022 Flyytech.com | All Rights Reserved.

No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs

Copyright © 2022 Flyytech.com | All Rights Reserved.

What Are Cookies
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT