IOTW: DC Police Department Hit with Ransomware; Hackers "Quit"

Add bookmark

A relatively new and apparently now defunct Babuk hacking group successfully launched a ransomware attack against the Metropolitan Police Department of the District of Columbia (MPD), absconding with 250 GB of data that includes the PII of confidential informants, persons of interests, and employees. 

Babuk's activity was first spotted in January 2021. Since then, it has carried out attacks against five enterprises, the Houston Rockets basketball team and MPD. Babuk stated on its website that the MPD job was its last and that the group intends to open source its Babuk Locker ransomware so other bad actors can use it at will.

Cybersecurity experts state that Babuk's tactics mirror an evolution of ransomware attacks, from encrypting files and demanding ransom money for a decryption key to encrypting the file and threatening to publish the information if the ransom isn't paid. Worse, Babuk's decryption software has a bug it in that causes data loss.

Babuk had been fortifying its own capabilities, advertising for developer affiliates while operational.

The group stated that it would not attack hospitals, non-profits, schools or small businesses.

The Facts

On Monday, April 26, Babuk announced it had attacked the MPD. MPD was given three days to comply with the group's demand for $50 mn. Otherwise, informants' data would be shared with gangs. Meanwhile, the group has posted some examples of the stolen data on its .onion website which include the chief's reports,  lists of arrests, a folder named "Gang Database" and a Windows directory entitled "Disciplinary Files."

The MPD promptly contacted the U.S. Federal Bureau of Investigation (FBI) for assistance, after which the threat was identified and blocked. Neither the MPD nor the FBI will comment on the investigation at this time.

Security researcher Choung Dong, who first discovered the ransomware, said the software uses the Windows Restart Manager, SHA256 hashing, ChaCha8 encryption and Elliptic-curve Diffie–Hellman (ECDH) key generation.

Lessons Learned

According to McAfee, Babuk has been targeting transportation, healthcare, plastic, electronics and agriculture companies internationally. The most common entry vectors for the ransomware are:

  • Email spear-phishing.
  • Public-facing application exploits.
  • Using valid accounts.
  • Obtaining valid account using infostealers.

The ransomware embeds three different built-in commands to spread itself and encrypt network resources.

Anti-malware and anti-virus solution provider Emsisoft said the Babuk ransomware specifically targets ESXi servers and that data loss is caused by one of the bugs which attempts to decrypt unencrypted files, "trashing them in the process."

Quick Tips

  • Create backups or snapshots of encrypted data (Emsisoft).
  • Patch systems and software ASAP.
  • Have a ransomware incident response plan in place that is cooperatively developed with other risk functions that could be affected such as Operations, Risk Management, Legal, Compliance, IT, and Communications.
  • Provide basic cyber hygiene training for all employees, including updates as threats evolve.

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":0,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[],"featured_content_portal_embedded":null}" >