Quick Summary
The Securityish Brief
Ransomware gangs are increasingly using virtual machines (VMs) provided by ISPsystem to host and deliver malicious payloads. Researchers from Sophos discovered this tactic while investigating recent incidents involving the WantToCry ransomware. They noted that attackers utilized Windows VMs with identical hostnames, which suggests the use of default templates generated by ISPsystem’s VMmanager.
These identical hostnames were found across the infrastructure of multiple ransomware operators, including well-known groups like LockBit, Qilin, Conti, BlackCat/ALPHV, and Ursnif. Additionally, various malware campaigns, such as those involving RedLine and Lummar info-stealers, also utilized these VMs.
ISPsystem is a legitimate software company that develops control panels for hosting providers, including VMmanager, which is designed for managing virtual servers. However, Sophos identified that VMmanager’s default Windows templates reuse the same hostname and system identifiers, making it easier for cybercriminals to exploit this design flaw.
Bulletproof hosting providers that support cybercrime operations take advantage of this vulnerability, allowing malicious actors to create VMs for command-and-control (C2) and payload delivery. This method effectively conceals malicious systems among a multitude of legitimate ones, complicating efforts to track and shut down these operations.
Most of the malicious VMs identified were hosted by a small cluster of providers known for their poor reputations, including Stark Industries Solutions Ltd., Zomro B.V., First Server Limited, Partner Hosting LTD, and JSC IOT. Additionally, a provider named MasterRDP, which has direct control of physical infrastructure, was also noted for using VMmanager to evade legal requests.
According to Sophos, four specific ISPsystem hostnames account for over 95% of the internet-facing ISPsystem virtual machines: WIN-LIVFRVQFMKO, WIN-LIVFRVQFMKO, WIN-344VU98D3RU, and WIN-J9D866ESIJ2. All of these hostnames were linked to cybercriminal activities in customer detection or telemetry data.
While ISPsystem’s VMmanager serves legitimate purposes, its low cost and ease of deployment make it appealing to cybercriminals. The situation raises significant concerns about the effectiveness of current cybersecurity measures and the need for improved oversight of hosting providers.
Key Takeaways
- Monitor your network for unusual activity that may indicate the presence of malicious VMs.
- Consider implementing stricter controls and oversight for third-party hosting providers.
- Regularly review and update security protocols to address potential vulnerabilities in virtual infrastructure.
- Educate staff about the risks associated with using default configurations in virtual machines.
- Stay informed about the latest ransomware tactics and adjust your defenses accordingly.
Key Terms & Concepts
- ISPsystem: ISPsystem is a software company that develops control panels for managing virtual servers and infrastructure.
- VMmanager: VMmanager is ISPsystem’s virtualization management platform used to deploy Windows or Linux virtual machines.
- ransomware: Ransomware is a type of malicious software that encrypts a victim’s files and demands payment for their release.
- command-and-control (C2): C2 refers to the infrastructure used by cybercriminals to control compromised systems and deliver malicious payloads.
- malware: Malware is any software intentionally designed to cause damage to a computer, server, or network.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.