Ransomware gang hacks MSPs to deploy ransomware on customer systems

From zdnet.com

Image result for ransomware
image from ciao.com

A ransomware gang has breached the infrastructure of at least three managed service providers (MSPs) and has used the remote management tools at their dispossal, namely the Webroot SecureAnywhere console, to deploy ransomware on the MSPs’ customers systems.

The ransomware infections were first reported today in a Reddit section dedicated to MSPs — companies that provide remote IT services and support to companies across the world.


Hanslovan said hackers breached MSPs via exposed RDP (Remote Desktop Endpoints), elevated privileges inside compromised systems, and manually uninstalled AV products, such as ESET and Webroot.

In the next stage of the attack, the hackers searched for accounts for Webroot SecureAnywhere, remote management software (console) used by MSPs to manage remotely-located workstations (in the network of their customers).

Read more…