|
Welcome back to the TCE Strategy monthly newsletter! April has brought some of the most unusual and interesting hacks (and hacker takedowns) that we have seen in some time. From the strike on Stryker to the hacker-turned-cyberhero, let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.
7000 Robot Vacuums Accidentally Hacked, Video Cameras and All
More and more devices are being sold as “Internet Connected”, which generally speaking I’m not a fan of. The Internet is a war zone, and things connected to the Internet need a certain level of cybersecurity. Turns out that DJI (the company known for making consumer drones) has started making a Roomba-style robot vacuum. A cybersecurity researcher and hobbyist named Sammy Azdoufal bought one, and thought it would be cool if he could drive the vacuum using a Playstation 5 controller, so he started tinkering. Not only could he interact with his vacuum, but he found 7,000 of them were all suddenly accessible to him. He could watch their video feeds and listen in on their microphones. He could get 2D floorplans of the houses they were in, and could get their approximate geolocation via their IP address.
I’m guessing that DJI had no intention of selling vacuums-turned-spy devices, but that is exactly what they did. When these IoT (Internet of Things) devices enter a home network and reach out to a server on the Internet, it’s a two-way connection: The server can talk directly to the device in the home network, and if the device has cameras or microphones, they can be used by anyone that has control of the server. For privacy minded consumers, this is bad. Furthermore, why does a vacuum need a microphone? I can understand where a video camera would be useful for it to “see” what it’s doing when it vacuums, but how is a microphone needed?
DJI recently announced that they will pay an “unnamed researcher” $30,000 for alerting them to the vulnerability, which is very likely Sammy. I’m glad that he is receiving a reward, but I’m genuinely amazed that DJI sold a system with essentially zero cybersecurity testing prior to releasing it.
I’ve long been against devices that can listen in to conversations occurring in our homes. In fact, I have a first-generation Amazon Alexa in my office, specifically so that when people ask about it, I can show them that the power cord isn’t plugged into an outlet. These devices can and have been used as part of law enforcement warrants. Hackers have broken into them to spy on children. These devices are sold as appliances or toys. Make no mistake: these are surveillance devices, and they can be used to surveil you and your family.
Takeaway: Be careful what Internet-connected devices you buy. What added value does a vacuum, water softener, washing machine or crock pot have when it is connected to the Internet? For devices that you do want to connect to the Internet, I recommend a “guest” Wi-Fi network for them, and don’t buy anything you don’t need that has a camera or microphone.
Iranian strike on Stryker
Stryker is a very large medical device company ($25 billion in annual revenue), and companies this size have a lot of computers. On March 11th, Stryker found that all of their Windows computers had been remotely wiped of all data, including their Operating System (Microsoft Windows). An Iranian hacker group named Handala claimed responsibility, stating that the attack was “in response to the strike on the Minab school in southern Iran”.
Stryker did an admirable job keeping the world up to date on the details of the cyberattack. They claimed to be fully operational on April 1st, which is a stunningly fast recovery from having 80,000 bricked computers. Apparently the Handala group was able to get a hold of an “Admin” level account to Microsoft InTune, which is what Stryker used to monitor, patch, and otherwise manage their Windows computers. InTune also has the ability to perform remote data wipes, which is useful if a device is lost or stolen. In this case, that remote wipe functionality was weaponized to erase all Windows computers in the environment. Wow.
Stryker appears to have absolutely nothing to do with the USA/Israel - Iran war. My guess is that Hadala simply used them as cannon fodder to prove that they can do noticeable economic damage within the USA.
Takeaway: This attack is a smoking gun that demonstrates how companies that make a cybersecurity mistake can get caught up in serious geopolitical issues that they have no involvement in. Stryker was likely chosen simply because they were not Secure Enough. It is imperative that IT teams protect admin-level credentials with very strong passwords, multi-factor authentication, and dual-controls wherever possible. CISA put together a good list of best practices to help other companies from falling victim to a similar attack. Cybercrime is almost always a preventable crime.
When a Hacker uses their Power for the Bright side of the Force
In a follow-up to the “residential proxy story” that I covered in the February newsletter, much, much more has come out about this, and the write-ups on it are so good that I would really encourage you to follow the links below in this story. Here is the Cliff-notes version:
Botnets are large groups of computer devices that are being remotely controlled by a cybercriminal. These have been around for years. A large botnet called Kimwolf was used to overwhelm websites with so much traffic that they went offline, and Kimwolf was used to do this 26,000 times to 8,000 different victims.
Part of what made this botnet unique is that it used Android devices rather than more traditional botnets (they are often made up of large numbers of security cameras or Windows PCs). What’s even more interesting is that many of the Android devices were deliberately sold to consumers as TV Streaming devices that serve up pirated TV shows, when in reality they were specifically designed as hacking tools against the very home networks their purchasers used.
Benjamin Brundage steps in, a college student who does some fantastic detective work to befriend one of the hackers responsible for Kimwolf. He then partnered with law enforcement to disrupt the entire operation. Absolutely awesome.
Takeaway: First, do NOT buy TV streaming devices that claim to allow for pirated content. Get a Roku, an Apple TV or an Amazon Fire if you want a streaming box. Second, if you have friends that might use one of these, do NOT hook up anything of yours to their network. Finally, if electronics and hacking is of any interest to you, there are a lot of real-world ways that you can make the world a better place using those skills. This story is one of the best examples I have seen in a long time.
Until next month, please stay safe!
|