{"id":6436,"date":"2022-02-14T19:01:07","date_gmt":"2022-02-14T10:01:07","guid":{"rendered":"https:\/\/cyberenso.jp\/?p=6436"},"modified":"2022-03-30T19:04:33","modified_gmt":"2022-03-30T10:04:33","slug":"fbi-releases-joint-advisory-with-u-s-secret-service-against-blackbyte-ransomware","status":"publish","type":"post","link":"https:\/\/cyberenso.jp\/en\/fbi-releases-joint-advisory-with-u-s-secret-service-against-blackbyte-ransomware\/","title":{"rendered":"FBI releases joint Advisory with U.S. Secret Service against BlackByte ransomware"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"6436\" class=\"elementor elementor-6436\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-dabf50e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"dabf50e\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ba3c3ee\" data-id=\"ba3c3ee\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-97f6b7e elementor-widget elementor-widget-text-editor\" data-id=\"97f6b7e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>On Friday 11<sup>th<\/sup> of February 2022, the US Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory with the U.S. Secret Service (USSS) about indicators of compromise associated with BlackByte ransomware. The joint advisory alert details indicators of compromise (IOCs) from previous BlackByte ransomware attack which organisations can use to detect and defend against future BlackByte&#8217;s attacks. The joint advisory also reveals \u201cas of November 2021, BlackByte ransomware had compromised multiple US and foreign businesses, including entities in at least three US critical infrastructure sectors (government facilities, financial, and food &amp; agriculture).\u201d<\/p><p>Some of the key IOCs associated with BlackByte activity that have been shared include MD5 hashes of suspicious ASPX files discovered on compromised Microsoft Internet Information Services (IIS) servers and a list of commands the ransomware operators used during their attacks.<\/p><p>The joint Advisory also listed recommended measures which organisations should take to mitigate possible future BlackByte ransomware attacks:<\/p><ul><li>Implement regular backups of all data to be stored as air gapped, password protected copies offline. Ensure these copies are not accessible for modification or deletion from any system where the original data resides.<\/li><li>Implement network segmentation, such that all machines on your network are not accessible from every other machine.<\/li><li>Install and regularly update antivirus software on all hosts and enable real time detection.<\/li><li>Install updates\/patch operating systems, software, and firmware as soon as updates\/patches are released.<\/li><li>Review domain controllers, servers, workstations, and active directories for new or unrecognized user accounts.<\/li><li>Audit user accounts with administrative privileges and configure access controls with least privilege in mind. Do not give all users administrative privileges.<\/li><li>Disable unused remote access\/Remote Desktop Protocol (RDP) ports and monitor remote access\/RDP logs for any unusual activity.<\/li><li>Consider adding an email banner to emails received from outside your organization.<\/li><li>Disable hyperlinks in received emails.<\/li><li>Use double authentication when logging into accounts or services.<\/li><li>Ensure routine auditing is conducted for all accounts.<\/li><li>Ensure all the identified IOCs are input into the network SIEM for continuous monitoring and alerts.<\/li><\/ul>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>On Friday 11th of February 2022, the US Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory with the U.S. Secret Service (USSS) about indicators of compromise associated with BlackByte ransomware. The joint advisory alert details indicators of compromise (IOCs) from previous BlackByte ransomware attack which organisations can use to detect and defend against future BlackByte&#8217;s attacks. The joint<span class=\"excerpt-hellip\"> [\u2026]<\/span><\/p>\n","protected":false},"author":1,"featured_media":6441,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,12,2,14,1],"tags":[],"class_list":["post-6436","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-latest_news","category-read_article","category-ce_news","category-read_special_reports","category-uncategorized"],"acf":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/cyberenso.jp\/wp-content\/uploads\/2022\/03\/Picture1-12.jpg?fit=1377%2C919&ssl=1","_links":{"self":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/6436"}],"collection":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/comments?post=6436"}],"version-history":[{"count":6,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/6436\/revisions"}],"predecessor-version":[{"id":6444,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/6436\/revisions\/6444"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/media\/6441"}],"wp:attachment":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/media?parent=6436"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/categories?post=6436"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/tags?post=6436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}