Security News > 2021 > April > Cring Ransomware Targets Industrial Organizations

Cring Ransomware Targets Industrial Organizations
2021-04-08 13:47

At the beginning of 2021, the threat actors behind the Cring ransomware were observed launching numerous attacks on European industrial enterprises, forcing at least one organization to shut down a production site.

The initial vector of attack was later identified as CVE-2018-13379, a vulnerability in the FortiOS SSL VPN web portal that could allow unauthenticated attackers to download FortiOS system files.

The directory traversal vulnerability can be exploited to extract the session file of the VPN Gateway, thus allowing unauthenticated attackers to gain access to usernames and plaintext passwords.

The attacks observed by Kaspersky started with test connections to the VPN Gateway, to check the software version on the target devices, followed by the main attack phase several days later.

"Various details of the attack indicate that the attackers had carefully analyzed the infrastructure of the attacked organization and prepared their own infrastructure and toolset based on the information collected at the reconnaissance stage," Kaspersky says.

The FBI and CISA issued an alert last week to warn governmental, commercial, and technology services organizations about attacks targeting multiple vulnerabilities in FortiOS. Fortinet too once again urged customers to apply the available patches, to remain protected from attacks.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/fTyTmtN4PPc/cring-ransomware-targets-industrial-organizations

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2019-06-04 CVE-2018-13379 Path Traversal vulnerability in Fortinet Fortios and Fortiproxy
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
network
low complexity
fortinet CWE-22
critical
9.8