←All insights

incident response

The boring list

Storm ransomware reached six Australian dealerships through one vendor's support tool. That is not a sophisticated attack, and the things that stop it are not sophisticated either. Our opinion on the Auto-IT incident, and the short, unglamorous list every organisation can work through.

Ryan BallootBy Ryan Balloot, Managing Director30 September 20266 min read
ByRyan Balloot30 September 20266 min read

Between 17 August and 1 September a group called Storm listed six Australian businesses on its leak site. Car dealers in Cairns, Victoria and Tweed Heads. Machinery suppliers in South Australia and western Victoria. On 15 September the company behind all of them, dealer management software maker Auto-IT, confirmed that a small number of its customer environments had been reached through "the unauthorised use of a third-party remote monitoring and management tool".

We wrote about what that means when a vendor holds the keys to your systems. This piece is about the other thing the incident shows, which gets lost every time a breach makes the news.

Ransomware is not clever.

Our opinion

Storm posted its first victim on 7 August. Within three weeks it had claimed 26 organisations worldwide. By 1 September six of them were Australian. That is not the output of a team of specialists picking targets. It is a business, run for profit, that scans for something left open and walks through it. The samples it published to prove its claims were staff passport scans, driver's licences, invoices, payroll and, in one case, a list of user names and passwords. Not the crown jewels. The HR folder and the finance share, because those are the first things a shared drive gives you.

The way in was a support tool. Remote monitoring and management software is how every vendor and every managed service provider looks after hundreds of customers from one console, and we run one ourselves. It is also, by design, a trusted door into every environment it manages. Someone used Auto-IT's without permission. Nothing in the public account suggests a , a novel technique or a nation state. It suggests a credential, or an exposed console, or an account that should have been closed. The ordinary stuff.

This matters because the industry, us included, has a habit of making ransomware sound like weather. Something that arrives. It does not arrive. It is let in, usually through one of a short list of doors that have been the same doors for a decade. The received more than 84,700 cybercrime reports last financial year, one every six minutes, and the pattern behind the ransomware cases in that pile is monotonous. A remote access tool with no second factor. An internet-facing system nobody patched. A backup the attacker could reach. Everyone a local admin.

So here is the list we give people who ask what to do first. It is short and it is boring, and that is the point. Sophisticated attacks exist. They are not what puts a Cairns car yard on a leak site.

The boring list

Work through it in this order. Each item says what it would have changed in the Auto-IT case.

Put a second factor on every door that faces the internet

Email, VPN, remote desktop, the vendor's support tool, the accounting platform, the cloud console. All of them. Where you can, make it phishing-resistant, meaning a or a hardware key rather than a code that can be relayed. A stolen password should be worth nothing on its own. In this case: unauthorised use of a support tool is much harder when the tool asks for something the attacker does not have.

Know every remote access path, and be able to close each one in an hour

Write down which vendors can reach your systems, through which tool, and whether that access is on all the time or opened per session. A remote support tool was the door in the Auto-IT case. Ask for per-session access, with a second factor and a log. A vendor that cannot tell you within a day how its access works is telling you something.

Patch what faces the internet within days, not months

Firewalls, VPN appliances, remote management consoles, web applications. These are the things scanners find first, and once a flaw is public the window is short. Mathspace lost 23 days to a patch that was already available. Internal systems can wait a fortnight. The perimeter cannot.

Keep a backup the attacker cannot reach, and prove you can restore from it

A backup on the same network, with the same credentials, is a copy the ransomware encrypts second. You want one that is offline or immutable, and you want to have restored a real system from it recently enough to know how long it takes. One of the Victorian dealerships has already restored its systems. That is the difference between a bad month and a closed business, and it is decided long before the attack.

Stop making everyone an administrator

Local admin on every laptop turns a click into a foothold. A shared drive every account can read turns one compromised login into the whole HR folder. Least privilege sounds like a project. It usually starts as a Tuesday afternoon removing rights nobody uses.

Delete what you no longer need

The data you do not hold cannot be leaked. Identity documents collected for onboarding, old customer records, scans that only ever needed to be sighted. Most of the samples we have seen on leak sites this year were things the victim could have thrown away.

Watch the trusted paths, not just the obvious ones

Most environments log the firewall and nothing else. A vendor's support tool doing something unusual at 2am does not show up anywhere anyone looks, because it is trusted by design. Monitoring has to cover the doors you opened on purpose. That is the gap an attacker holding a vendor's credentials walks through.

Write down who you call

One page is enough. Who decides, who calls the insurer, who calls the lawyer, who calls the responders, and what you do if the intrusion started at a supplier rather than on your network. The dealerships that handled August well were the ones that had this before they needed it.

What this does not cover

This list will not stop a determined, well-funded attacker who wants you specifically. Almost nobody reading this is that target. It will stop the affiliate running a scanner, and the affiliate running a scanner is who fills the breach tracker week after week.

It also will not do itself. Every item above is affordable and none of them is hard, which is exactly why they do not get done. They compete with real work and they have no deadline. If you want a deadline, SMB1001 gives you one, and its lower tiers are close to this list with a certificate at the end. The Essential Eight covers the same ground for organisations that need to show a government customer.

Either way, start with the second factor on the support tool. That one would have changed August.

Is this enough for a small business?

For most, yes. These controls cover the way in for the large majority of ransomware cases we see. A business with regulated data, a large customer base or a government contract will need more, but not before this.

Our IT provider says we already do all this. How do we check?

Ask for evidence, not assurance. A list of every remote access path. The date of the last restore test and how long it took. A count of accounts with admin rights. A provider doing the work will have these to hand.

Keep reading

More from the IronSights team.