VMware ESXiArgs Ransomware – Tony Lauro, Akamai
Tony Lauro, director of security technology & strategy at Akamai, discusses VMware ESXiArgs ransomware, and how hackers are taking advantage of unpaged ESX images in medium and large businesses. Tony references zero trust initiatives and Akamai’s Ransomware Threat Report 2022.
Transcript
This is texturing TV. Well, I have the great pleasure being joined by Tony LaRue who is with us again. Who is with the Akamai?
Welcome, Tony. Hey, thanks for having me Mitch pleasure to be here good to have you again. We always talked about great topics on any excited that you're back first for folks who may not know you just tell them a little bit about yourself and what you do at I Sure, so I'm director of security strategy and Technology.
I work with our csos and others see level folks within our customer base and the goal really is to have conversations about how are they approaching Security in their security program from a strategic perspective. So what are their initiatives? How are they going to get there any specific things that they're looking at trying to Target?
And then we also kind of look towards the future. So as we're developing new technology, I take feedback back into our product development or to make sure that the needs that might be rising in the future kind of where the puck is being shot to that's the direction we're going instead of where the park was shot from. So that's that's a little bit about what I do.
Yeah, we don't just want to deal with thought what's already happened. Hopefully we can prepare I should have thrown in a football reference. But well it works.
Hey, I'm from Colorado. So, you know with the Avalanche. I'm happy to hear a hockey reference.
So yeah, no problem here. Well speaking of kind of where the pucks I guess is right now a lot of conversation around VMware esxi arguments, you know configurations and those types of things being encrypted for ransomware kind of going to the heart of it. Right?
It's one thing to you can yeah the database you can file servers and storage. Well, you can't even run your systems, right? That's that's a bit of a problem.
Yeah, it is and you know, it's it's funny when we kind of see this latest wave of of alerts so sisa and the FBI just released a joint advisory talking about this ransomware this targeting esxi servers. And the first thing that pops out to me is when you look at the recommendations especially is you know, many of these vulnerabilities that are being exploited are because the systems are unpatched. So you kind of go back to the adult age old adage of make sure you're dealing with you know, the the fundamentals and I think that's one of the big pieces here, especially looking at the fact that a lot of the systems that are being exploited are directly internet facing which is also a bit of a No-No.
So this brings up a lot of different topics, right? How do you deal with this from a technical perspective, but I think a lot more of it is kind of from a strategic perspective on how you access these systems when you're managing them. Shelves Etc.
So that's an interesting, you know point of conversation. Yeah, how long have been talking about patching? You know, one of the things that just sort of rolling around in my back of my mind is with the Telemetry and data that we have now that you know, we're hosting system.
We're automatically downloading updates for folks for us product providers be great. If there was some way to understand when we change certain things in software that has a bigger impact on customers have to do more testing versus other changes. Don't right so you could almost categorize updates to software to say low risk of compatibility issues, you know medium or higher risk just to make patching more quickly because unfortunately a lot of this compatibility testing you're sort of one size fits all and it can be pretty onerous.
Yeah, you know from that perspective. That's an interesting point to make right because a lot of times, you know, people are thinking hey, I've moved to the cloud so I'm kind of like offloading this risk to my provider but system patching and vulnerability updates and all that good stuff. That's not really the job of the cloud provider.
So you're kind of getting back to the the funny bumper sticker that the cloud is just somebody else's computer. But in this case it is it's still your computer. You have to patch it.
You have to maintain all these systems so over time, you know, what happens is you kind of get so far down the road where you're maybe kicking the can on having a plan system outage and you know what that looks like for you for your business from an operational perspective and then you get so far out that all the sudden you have all this technical debt in terms of you know, vulnerability and Patch management that haven't been dealt with and I think that's where a lot of Organizations that are getting a compromised are you know are coming up, you know to find themselves within this scenario and I think that's kind of the the real Crux of this problem at this point. Yeah very much is we just went through on some borone infrastructure needing to update? I think it was PHP actually in one of the service providers send a notice how to folks that were not a certain version that needs to be here by then.
And of course, you know, usually more internal things like that has to have bigger bigger impacts when you're forcing an upgrade on things. So well talk a little bit more about I mean, obviously the prevalence of VMware and Vmx systems, you know, it was very widespread. You know, not everybody uses VMware.
I'm sure everyone wish everybody did but you know your small business, you know donut shop probably not running VMware but a lot of midsize and of course large Enterprise definitely are Yeah, this you know, we released a ransomware report at the end of last year that basically found that while looking at the Conte ransomware wave that they had we found that there was kind of a goldilock range between you know, zero and 250 million in revenue is where this rent to where group specifically was targeting in this case with a you know VMware systems. It may be a little bit more opportunistic. But the idea that there's actually this thought process this, you know, kind of this mind share being shared between different ransomware groups and then you know, the people when we look at the Conte ransomware Playbook, there's a differentiation between the people who write the code to help compromise the systems and and deploy the malware.
And then the actual malware writers which are looking at the real intricacies of how it works how it propagates on the network Etc. And you know, when we look at all that and do that kind of analysis, you know from a kind of a big picture perspective. It's a great time for us to step back and say, Let's talk about the overarching ways in which the security environment failed itself.
Right? So for secure remote access, how are you actually communicating with the environment that you manage when it's not, you know, right around the corner of your office in the data center that you own. So when it's in the cloud, how are you getting in there?
Do you have some kind of more secure remote access and VPN because we know this is been a big issue over the past few years and then when it comes to well, maybe the people who do have access maybe they're doing it correctly. But the access to their accounts to be able to access those environments are being compromised through fishing or kind of social engineering you start looking at managing the the credentials and managing the the account ownership and this comes back to you like a multi-factor authentication technology, right? Can I trick a user?
giving me access as a bad guy into the environment when I already know their credentials because I fished them the week before right and this is where we kind of we're looking at how the principles of zero trust and I'll put air quotes around this because there's so many different things to look at here, but the concepts are don't Trust as a matter of fact the people who have access how they're accessing the environment and then what they do after they're in there. So what they do after they're in the environment comes down to what kind of visibility do you have in the environment that you are already? Assuming is a trusted environment.
So do you have you know micro segmentation or do you have hunt services? So you're actually looking at threat identification when you watch how the machines are communicating with each other? One if you can't identify it, you can't do anything about it.
But two you have to have a policy set in place that says if something were to happen on one of these systems malware likes to move laterally once it's inside your network. So how do you identify by policy that the machine now is communicating across the network in a way that it's never done before and in a way that's indicative of you know, malware jumping laterally across the environment. So all of those things are all part of a zero trust big picture, but I think a lot of organizations at this point are kind of having they're having trouble moving the needle there and in our advice at that point is really start with a quick win, maybe take just say you're you're working on remote access solution take a quick win, which is maybe this developer set.
That's remote. Let's take their whole group and put them into this new zero trust network access model and let's test with them and see how this works because you're really trying to take all the different pieces where the attackers are assuming what it's going to be like when they get into your network and take all those assumptions off the table by by flipping the script changing the game and that's what's happening right now. I think with the the wave of of new initiatives we're seeing from a zero trust perspective.
Curious to you know, thinking zero trust and also of course supply chain security. One of the kind of big topics again think about a month or two ago was containers containing ransomware malware. I'm from sources that you download containers from of course.
We've been downloading, you know, VMware images and other kinds of virtual images from VMware and lots of sources too. I would think that that's less of an issue with VMware. Where do you think that's still a risk?
We need to also be cognizant of that. It could be introduced to the source and the image itself. I think that's a you know, so so one whenever you get images this this happened, I'll say 20 years ago.
This was a problem in the illegal software downloading realm where people like oh I can get a free copy of this of this program come to find out after you download it and install it it's backdoored. It's you know, making your your system into remotely accessible to the to the bad, you know threat actor system. So now you're part of this bigger problem on the internet, so it goes back to this old adage if you if you're not getting your software from reputable sources because those reputable sources they have a process in place for what it looks like to validate and create checks on the sport for images before they're you know, when they're uploaded to this server and then when you download them from the server and you can do checks and make sure that that check some matches but you know Flash Forward to 20 Three talk to any security engineer and you're bringing up a virtual machine, you know probably on your systems.
Some people have totally separate systems. But when you're looking at different software packages and different malware when you're studying that you're doing it in a virtual environment. So there is a little bit of an assumption that hey if something happens that machine I'll just wipe it or restore from an image Etc.
But it brings up, you know the virtual machine probably if you wanted to be usable it probably has access to the internet and it probably has access via some paths on your internal Network for DNS call outs and some lateral communication. So there is a risk that things could still happen, even when you're working inside of a virtual environment and I think that's what the attackers are finding out here where they're saying. Hey, maybe I don't jump, you know from machine to machine Maybe.
I just compromised the virtual machine that they think is so safe. And and again when you look at the lowest hanging fruit, if XYZ is more complicated and ABC is Least Complicated. They're going to go with the ABCD solution, you know.
Absolutely. I refer to it as the water model whatever the least passive path of resistance is right. I've had a roof leak several times and that's that's actually factual.
It'll find it away in full topic. I'm sorry. I brought that up.
Yeah, they're roof leaks and hacks are no fun this last similarities there. I guess interesting. So we any kind of thoughts going forward.
Where do you see this evolving to or maybe some other recommendations we can let's talk about where the pucks going to be and how we might think about getting their head. Yeah, it's uh, it is a challenging conversation because the Assumption around moving the needle and zero trust is, you know, this is a multi-year project. There's a lot of moving parts and it's partially true you want to take careful consideration not only in what you choose to do.
But in what order you choose to do it, I mentioned the use case to maybe saying hey this remote development team. Let's move them to zero trust network access model. You know from a from a Safety and Security standpoint, you might do the same with micro segmentation.
You might say hey, we're gonna deploy software defined micro segmentation technology to these this set of critical systems and what we're gonna get from that is not only the ability to kind of ring fence the blast radius of anything that happens on a compromised system, but you're gonna get observability of what's Happening across the network in between those machines and by policy and by how you tag it and kind of I don't want to miss you use the word containerized but maybe categorize the communication paths that are that are in place and the systems that are doing that communication. You could take a smaller part of your your system environment and start that process of my segmentation within those boundaries. But yeah moving the needle here is really one identifying the fact that there are Technologies in place that can help you get here.
It does seem like kind of a It seems like a really large, you know project to Bear when you come to the idea of like hey, our whole network is still built the way it was built in 1999 and 1989 something matter. Right? So, you know looking at that you kind of have to come to realization.
Hey, we can make steps forward we have to do it incrementally and we have to pick you know, what areas of risk are we willing to to kind of hold on to while we're working on these other projects and I think that's the biggest thing is kind of looking at the timing and the the relevance of which projects you tackle first, but I would say work with people who do it all the time. You know, there's a lot of vendors out there that have technology that can help in this area. Um and work with those advisors to help figure out what the next step should be because doing it on your own is never never a good option.
You know, they say if you're gonna fail don't do it alone sounds horrible sounds like you're bringing someone down with you, but the idea is you want to put a lot of Minds into action on these projects and and not try to do it yourself unless You have a long track record of you know, being able to do it yourself and executing properly in that case go for it. You know, you know, there's there's kind of other things that are happening in parallel, like platform engineering is the topic, you know, a very top popular within the software World kind of crossing over into operations and cloud and platform engineering and there's very much of an automation Focus there too. Whereas you were talking about how we've operating on infrastructure using the same techniques.
We used five 10 20 years ago, right which may not have been as automated so there's processes that are happening in that kind of development World about Checking these things but being automated maybe we can apply some of those ideas here too doesn't help if it's been stick-built 20 years ago, but but we may be able to make a dent in some other areas, too. Yeah, that's that's definitely true. There's a lot of areas in which process Automation and kind of simplifying simplifying these processes can be very very helpful, but it's important to remember that this is an old adage.
I think this was from Bill Gates like around the year 2000. He said something at you know, their developer conference something to the effect of you cannot automate a process that's broken or else you're gonna be automated automating the Brokenness of that process and when I when I think about that, I think hey there's some simple fundamentals that still aren't being executed on properly. And my advice to organizations would be get the fundamentals right?
Make sure you have Network visibility. Make sure you have you know, patches and and security updates happening on a regular basis. Make sure you have some kind of segmentation.
Even if it's not the latest greatest technology because Trying to cut all of those different Avenues of communication and paths that we're an attacker might find Value. That's the first step in getting ahead of this process. Right?
But if you're not getting simple patch management down, you're probably going to be struggling for quite some time to to do the rest of the of the new hotness that you probably want to get done. Yeah. It's always gonna be a problem.
I hear someone say once, you know automating a bad process just make the bad process happen faster. And yeah, exactly. That's almost exactly what bill was saying.
I guess. Yeah, same idea. Well Tony, it's been great having you with us.
Again today, and thanks for coming on to talk about esxi. Our arguments args and cons interesting things happening in the security World. Hopefully we can work together to make that more secure for all of us.
So appreciate your expertise here. All right. Thanks a lot Mitch.
Good Channel Tony from Akamai welcome again. Thanks.