Qilin Ransomware: Analyzing the threat that hit London Hospitals

  Рет қаралды 41,084

PC Security Channel

PC Security Channel

Күн бұрын

Пікірлер: 175
@zetectic7968
@zetectic7968 6 ай бұрын
The hospitals affected were unable to access the records for blood stocks, so had to make an emergency appeal for O -ive donors to donated asap. This was serious.
@totallyoriginal6934
@totallyoriginal6934 6 ай бұрын
it's concerning that people find it in any volume interesting, fun, or important to hijack hospitals with ransomware.
@ZzzZzz-yd2je
@ZzzZzz-yd2je 6 ай бұрын
They want money ?
@wfwfwffw
@wfwfwffw 6 ай бұрын
@@ZzzZzz-yd2je yes but that is a very concerning way to do it, i mean imagine probably killing a few people just for some money, what a scummy and sad way to do it.
@Slavolko
@Slavolko 6 ай бұрын
​@@ZzzZzz-yd2je Exactly. Same reason governments send their people to die in wars: more resources.
@carloscueto7561
@carloscueto7561 6 ай бұрын
@@wfwfwffw I mean, whoever does this in the first place isn't exactly ethical to begin with. It's not that surprising.
@instinctmlbb757
@instinctmlbb757 6 ай бұрын
Yeah these new gens are wild, I don’t think they will get respect in their own community for doing this shit.
@rjjeffreys
@rjjeffreys 6 ай бұрын
Congrats on the 500K subscribers. It is well deserved and earned.
@Wahinies
@Wahinies 6 ай бұрын
Hear hear
@Aloha_XERO
@Aloha_XERO 6 ай бұрын
Yeah I can confirm that this attack wasn’t just in the UK, but this attack happened also to hospitals in Sweden
@fernandohg225
@fernandohg225 6 ай бұрын
Hospitals need to have physical information along side the digital, they cant rely on systems/networks. Theres need to have a backup for these types of cases.
@NetrunnerAT
@NetrunnerAT 6 ай бұрын
This isnt possible now a days. I Work in the Radiotherapie. It is Impossible to Store a hole patien Data on paper. The importend parts are stored in paper, But its a small part of the Medical importend History.
@davidc5027
@davidc5027 6 ай бұрын
Looking forward to seeing your testing with all major AV/EDR vendors. Crowdstrike is the leader these days, so looking forward to seeing the results from that solution.
@IPendragonI
@IPendragonI 6 ай бұрын
I'd argue SentinelOne is close. However, I think he mostly focuses on private AVs specifically Kaspersky cause he's paid by them
@davidc5027
@davidc5027 6 ай бұрын
@@IPendragonI in 2023/2024, the top 3 are Crowdstrike, MS, and SentinelOne. I would venture to say any of the leaders are going to close, so definitely agree.
@marcusaurelius3487
@marcusaurelius3487 6 ай бұрын
*cough* *cough* SElinux *cough* *cough*
@Rogue0DK
@Rogue0DK 6 ай бұрын
Great video as always. I have to say though that after the latest MalwareBytes update I have been bombarded with popups from it. A video to disable those would be nice, as I had to dig around quite a bit to kill them. I dont like needless pop up messages .
@gir489returns2
@gir489returns2 6 ай бұрын
I haven't done pen testing in almost 20 years, because I pivoted to becoming a programmer instead. But why don't you just hook and check if each application is trying to poll all files on the disk, and then see if they are trying to read in specific files like TXT, PDF, etc. Surely it can't be too hard to heuristically determine cryptolockers.
@svettnabb
@svettnabb 6 ай бұрын
Many if not most EPP vendors do, but often they disable/bypass the endpoint protection before encrypting.
@32bitintiger999
@32bitintiger999 6 ай бұрын
I would guess the developers of the ransomware would try this and implement their own, different system.
@sandmanmoderngamer8322
@sandmanmoderngamer8322 6 ай бұрын
For ransomware protection, integrity monitoring-based rules can be highly effective. For example, a robust integrity monitoring service can revert changes made to critical systems. By setting a rule that triggers when more than 100 files are modified at once and is classified as sensitive, the system can automatically revert those 100 files and lock down the endpoint for investigation. Simple rules like this can significantly enhance.
@chrisosborne4731
@chrisosborne4731 6 ай бұрын
I'm well outside my knowledge so take this as you will, but malware and security are at an arms race with each other. You can design security for heuristic checking of that behavior, but malware authors will then build their malware to either circumvent the security or they will attack the security directly before executing their payload. At 2:58, this malware disables services before encrypting the files. I imagine this is done to weaken the system and make the malware more successful. So you're not wrong. I wouldn't be surprised if some antimalware tools already do this. But there is no "permanent" solution either. Malware authors will just work on a workaround, and then you have to defend against that. Endless cycle.
@sandmanmoderngamer8322
@sandmanmoderngamer8322 6 ай бұрын
Hello, Please be aware that, in most cases, software cannot disable the service of EDR solutions due to tamper protection and from reading the service that more of policy and data logs plus services. But it will not be able to target the edr.
@Kokomilenkoski1202
@Kokomilenkoski1202 6 ай бұрын
Second. This sample also attacked Serbia
@nobody-m6f
@nobody-m6f 6 ай бұрын
which company in Serbia?
@Kokomilenkoski1202
@Kokomilenkoski1202 6 ай бұрын
@@nobody-m6f EPS (Elektroprivreda Srbije) experienced the Qilin attack
@Kokomilenkoski1202
@Kokomilenkoski1202 6 ай бұрын
​​@@nobody-m6f Elektroprivreda Srbije got attacked by the said sample
@nobody-m6f
@nobody-m6f 6 ай бұрын
@@Kokomilenkoski1202 ty for resposne
@MashLimit
@MashLimit 6 ай бұрын
It may not have impacted 'ER' as you put it, but: "In total, 1,134 elective surgeries have been postponed as a result of Qilin's attack on Synnovis, which began June 4, and 2,194 outpatient appointments have also been pushed back. The NHS's previous update from June 14, six days prior to its most recent one, stated that around 1,500 surgeries and appointments had been delayed. That was a combined figure, it should be noted, one that has more than doubled in less than a week." The real story here is why the hospital Disaster Recovery plans failed to operate. The reason for these systems failing so badly is that the two key NHS Trusts involved, used each other for their backup - but all used the same single service provider. Most of us would have recognised this potential problem early on. The good news is that many other NHS Trusts and their laborartory services were about to go down the same route - but are now recalualting the risks. Some good may come from this attack.
@sandmanmoderngamer8322
@sandmanmoderngamer8322 6 ай бұрын
In my opinion, the security issue lies in the lack of adequate data integrity monitoring and systems based on data classification.
@wolfbrave4866
@wolfbrave4866 6 ай бұрын
So if the data is in a DVD Disk there is zero chance to encrypt the data xD
@anonuser260
@anonuser260 6 ай бұрын
If you rewrite this virus a little bit then you can do it easily but let's be real, no one uses DVD Disk anymore
@filipstamate1564
@filipstamate1564 6 ай бұрын
@@anonuser260 Yeah? How will you rewrite it to modify the files on a read only disc?
@Wildcard65
@Wildcard65 6 ай бұрын
@@filipstamate1564By hijacking the kernel and overriding the read and write procedures. Write encrypted data to the CD on the first write and encrypt the data during the read process if not already encrypted. Buy lets be real, who thinks a CD-R is more cost effective than CD-RW for data that has to change.
@EgonSorensen
@EgonSorensen 6 ай бұрын
@@filipstamate1564 scramble the output when a file is opened/read
@RaytechHack
@RaytechHack 6 ай бұрын
Yes
@ritajain2453
@ritajain2453 6 ай бұрын
Thanks for the valuable information.
@factswithlouis
@factswithlouis 6 ай бұрын
thanks for another film❤
@psx257
@psx257 6 ай бұрын
Brilliant video. Looking forward to the new Cyber content.
@niazmehedi
@niazmehedi 6 ай бұрын
Can you do a review for the ransomware that took down Change Healthcare in the US?
@adriantarver2229
@adriantarver2229 6 ай бұрын
For the rest of you that don't have any remediation against the London threats, CrowdSec CTI is offering a completely free list of 5k+ ipv4s to block threats like this one.
@ۥۥ0ۥۥ
@ۥۥ0ۥۥ 6 ай бұрын
*From a ransomware attack to canceled cancer surgeries. This is beyond messed up...* Edit: Didn't effect emergency services?
@NetrunnerAT
@NetrunnerAT 6 ай бұрын
Depends on ... are diagonstic systems also infected. Example Work CT scan and Radiodiagnostic record system? If yes "stroke unit" are realy in Trouble. Siemens make a good Job in secure there applience. To prevent infection.
@TheLegitAlpha
@TheLegitAlpha 6 ай бұрын
Malware targeting Linux it’s not something you see every day, But it is definitely something worth investigating. I would suspect the build to target linux users comes from the fact that healthcare is a common user for Linux installations, so the threat is there.
@Rajorsi
@Rajorsi 6 ай бұрын
Is it actually called as killin or chillin instead?
@stevebabiak6997
@stevebabiak6997 6 ай бұрын
I think so, in Chinese that Q is pronounced similarly to how “ch” would be pronounced in English
@bijoychandraroy
@bijoychandraroy 6 ай бұрын
this is unforgivable
@LeonEdwinsHeart
@LeonEdwinsHeart 6 ай бұрын
Very interesting, and thank you for explaining
@aussiegruber86
@aussiegruber86 6 ай бұрын
Can you do some videos on encryption and testing different options? And actually testing it if possible?
@LAZER500SW
@LAZER500SW 6 ай бұрын
What about Black Basta? have you made a video yet?
@adairjanney7109
@adairjanney7109 6 ай бұрын
What should I watch out for more in terms of ransomware I have all of my users well educated on not running stuff and phising, but what can I do otherwise is there anything ransomware is what worries me the most
@EmzyWoo-km6gx
@EmzyWoo-km6gx Ай бұрын
How can I get the builder I want to test it too
@andrewortiz8044
@andrewortiz8044 6 ай бұрын
Could you test the new version of malwarebytes?
@johnbear100
@johnbear100 6 ай бұрын
Thanks for another interesting insight into the world of low life Scammers and Hackers
@MarcinGorski917
@MarcinGorski917 6 ай бұрын
Give IOCs not just onky link to AV vendor.
@btarg1
@btarg1 6 ай бұрын
I'm embarrassed that someone working in my country's healthcare system will run an exe on an NHS computer. Why are there no rules that prevent them from doing that physically on their systems?
@settler8616
@settler8616 6 ай бұрын
Even the health care workers are well trained. There's always a chance a Chinese spy infiltrate to run "Qilin"
@Brodzik-kz8nt
@Brodzik-kz8nt 6 ай бұрын
Evaluating different security vendors, if they can handle different ransomware strains, that's good research paper material.
@monkaSisLife
@monkaSisLife 6 ай бұрын
Software used for Critical Infrastructure should be open source you will not change my mind.
@castoh
@castoh 6 ай бұрын
Would you kindly do a linux illustration on the same.
@Alex35983
@Alex35983 6 ай бұрын
Please do an extensive and deep dive reverse engineering video about this Malware. Get as much technical as possible ! Thanks for the video !
@pHIEU-m2f
@pHIEU-m2f 6 ай бұрын
Does Nomoreransomware have tool to decrypt it ?
@michaelol
@michaelol 6 ай бұрын
Does this type of thing bypass Bitdefenders Ransomware Remediation?
@bird271828
@bird271828 6 ай бұрын
What is the source code for this ransomware? Knowing this helps to prevent it from running.
@12345BoomerSooner
@12345BoomerSooner 6 ай бұрын
The CDK outage in the US has been big.
@HarpreetSingh1025
@HarpreetSingh1025 6 ай бұрын
Anyway to decrypt the effected files ?
@RaytechHack
@RaytechHack 6 ай бұрын
Yes
@lolononojay9010
@lolononojay9010 6 ай бұрын
But how do they actually get them to run their ransomware?
@DeBergeracs-s1n
@DeBergeracs-s1n 6 ай бұрын
? Would allowing private citizens to have and encrypt their own systems would that solve this problem?
@Chaooo
@Chaooo 6 ай бұрын
I'm not sure what being a private citizen has to do with anything, but if you encrypt your data prior to the ransomware affecting the machine, then you will at least be safe from the threat of the ransomware group selling the data. It does not, however, protect you from the denial-of-service attack that inevitably occurs, and will not prevent destruction of data. So, you can solve 1 problem, but the other 2 problems still remain. The problem with performing encryption - especially in real-time, and/or if there are numerous changes that happen constantly (like in a database), and/or if you are working with very large filesizes (at least in the gigabyte range and above) - is that it is extremely expensive in terms of processing power, it's slow to encrypt a large amount of files, and decryption takes even longer. Imagine working with a shared Excel sheet that multiple users are interacting with. It's not impossible to encrypt something like that in real-time (BitLocker is a popular service by Microsoft, for example), but the amount of problems it can/would cause makes it infeasible.
@NikNukem
@NikNukem 6 ай бұрын
Missing the Analysis
@finnderp9977
@finnderp9977 6 ай бұрын
To disable services this would need to be run with admin priviledges? It would be most basic thing to do drop admin priviledges from daily driver accounts but same time apparently impossible.
@antonk.653
@antonk.653 6 ай бұрын
It is just so much more convenient to have admin accounts - and some always sneak in somewhere by someone. So one senior doctor may have acquired admin priviledges by being friends with the IT staff, and therefore just runs all computers in the doctor's offices on his floor with admin priviledges, because it's so much more convenient. One other ignorant employee just needs to click on the wrong phishing e-mail and it's done. So yeah, virtually impossible to have no admin priviledges anywhere.
@ctrlaltdude
@ctrlaltdude 6 ай бұрын
@@antonk.653 If you still have users (and IT admins) with admin rights on their normal accounts and no seperate accounts for admin rights, you are still living in the middel ages. It's really not done anymore.
@antonk.653
@antonk.653 6 ай бұрын
@@ctrlaltdude If you knew how much middle ages you still encounter on a regular basis!
@tech.curiosity
@tech.curiosity 6 ай бұрын
Will such a thread work if the drive is encrypted like in upcoming windows 11 version ? Attacking hospitals is a serious problem for attackers cz if somebody dies because of that, they will be screwed. Thanks for the video.
@noiprocsZ
@noiprocsZ 6 ай бұрын
it will encrypt over already encrypted ones
@crestheproducer
@crestheproducer 4 ай бұрын
@proteckdiamond resolveu o problema do ransomware pel primeira vez em l.G
@OneElkCrew
@OneElkCrew 6 ай бұрын
RaaS works like a business, malware is cross-platform. Truly we live in a future.
@peterwassmuth4014
@peterwassmuth4014 6 ай бұрын
Awesome Thank you for Sharing 💯✴
@ali199472
@ali199472 6 ай бұрын
Great video ❤
@Turco949
@Turco949 6 ай бұрын
Whoever is behind this, is not a normal hacker, a very sick individual to target hospitals. I don't believe the hacker community would be supporting or enjoying anything like this.
@djthashock
@djthashock 6 ай бұрын
What is Better?? Malwarebytes or Windows Defender
@A42yearoldARAB
@A42yearoldARAB 6 ай бұрын
Can you talk about Kaspersky being banned? This is not good one of the best products out there.
@IPendragonI
@IPendragonI 6 ай бұрын
He's paid by them, so he can't. I've been asking for months for him to talk about it
@ArthurRamirezJ
@ArthurRamirezJ 6 ай бұрын
Can you try this against ELK?
@bitanchowdhury4028
@bitanchowdhury4028 6 ай бұрын
My friend What do you mean by ELK ?
@CloudyBogdan
@CloudyBogdan 6 ай бұрын
Password: DONKEY xD I bet Gordon Ramsay is a secret criminal haha
@Graham6410
@Graham6410 6 ай бұрын
Wouldn't be surprised if the virus could be sitting on more hard drives in a hospital just waiting to be activated.
@guilherme5094
@guilherme5094 6 ай бұрын
Thanks.
@matrixmunitions
@matrixmunitions 6 ай бұрын
MSPs are awful, they need to have standards.
@74Gee
@74Gee 6 ай бұрын
Analyzing?
@02468
@02468 6 ай бұрын
Can you talk about the one that just hit all the CDK POS that car dealers are using?
@Darkk6969
@Darkk6969 6 ай бұрын
System and network isolation is the key of protecting critical systems. Normal users should never have direct access to those systems.
@triangle3113
@triangle3113 6 ай бұрын
Is there an antivirus that does NOT include a VPN in it but still the full package?
@enpassantcheckmate
@enpassantcheckmate 6 ай бұрын
bitdefender
@GBR9794
@GBR9794 6 ай бұрын
@@enpassantcheckmate nope, mine installed vpn on its own lmao
@TeenPerspektiva
@TeenPerspektiva 6 ай бұрын
Pretty random request lol. You dont need to use the av vpn
@enpassantcheckmate
@enpassantcheckmate 6 ай бұрын
@@GBR9794 I think you need the antivirus plus one and not total security package
@jakeblue663
@jakeblue663 6 ай бұрын
It is probably carelessness or even working foul play that allowed access
@exitar1
@exitar1 6 ай бұрын
News flash Kaspersky banned in the United States 😮
@IamLookingforWoody_________786
@IamLookingforWoody_________786 6 ай бұрын
Hi
@JorgeLopez-qj8pu
@JorgeLopez-qj8pu 6 ай бұрын
Bye 👋
@miltonthecat2240
@miltonthecat2240 6 ай бұрын
I enjoy this channel, but most of it goes over my head. This is probably too simplistic, but if paying the ransom were made illegal, wouldn't most of it stop? Isn't paying the ransom just financing the victimization of others? It seems immoral to pay the ransom. A couple of probably dumb questions about malwarebytes. How do I know that malwarebytes, or any similar program, isn't itself malware? It looks like malware bytes is targeted at people who know more about software and computers than I do; is that the case?
@ohlordvoldy
@ohlordvoldy 6 ай бұрын
You are the GOAT 🫡
@marcusaurelius3487
@marcusaurelius3487 6 ай бұрын
*cough* *cough* SElinux *cough* *cough*
@wannabedal-adx458
@wannabedal-adx458 6 ай бұрын
But I thought Apple's and Macbook's were immune to malware??!?!?! 🤣😋
@neloangelo__13
@neloangelo__13 6 ай бұрын
ARM is just a CPU architecture, it's not Apple exclusive. You'll see more and more Windows laptops running ARM CPU these days. No one ever claimed Mac is immune to malware, they have a very small market share, so the criminals logically just focus on the bigger slice of the pie - workstations and servers of organisations running Windows.
@wannabedal-adx458
@wannabedal-adx458 6 ай бұрын
@@neloangelo__13 Yeah I know about the ARM architecture. My sarcastic comment was not directed at ARM chips but at Leo's comment that even Apple's we susceptible to malware and hacking. And there are ABSOLUTELY Apple fanboys out there that have said Apple's were immune to hacking for decades! That is what I was making fun of! Thanks.
@Your-Senpai
@Your-Senpai 6 ай бұрын
Wait what, malwarebytes has a dark mode? I no longer have to FRY my eyes every time I scan a selected folder, yay
@ТоварищКамрадовСоциалистКоммун
@ТоварищКамрадовСоциалистКоммун 6 ай бұрын
There is a long story about speculations how linux is not immune, just like any other OS. 1. yes, linux is not immune 2. linux may have some vulnerabilities, just like any other OS. The difference: in linux it's less likely to find any in stable distros, and more likely to find in some rolling/unstable. 3. The viruses are not typical for linux. viruses are typical for windows ) 4. Malware can be tailored for any OS, and it's more about a social engineering. It's just like lure someone into a trap
@WesleySmith-q9c
@WesleySmith-q9c 6 ай бұрын
I got first, that's what's up! I love the videos man keep it up! PS I know ow you like MWB and have done videos on it. Could you do one on malwarebytes threatdown.
@fbiagentmiyakohoshino8223
@fbiagentmiyakohoshino8223 6 ай бұрын
now those brits gotta wait another 60 months for their treatment
@v7lima
@v7lima 6 ай бұрын
Could you analyze the free Steam games "Egg", "Banana", "Cats" and "Banana & Cucumber", to check whether they run anything malicious or mine crypto in the background? These games are extremely popular at the moment and I'm sure a video about them would bring even more visibility to your channel. Love your videos!
@IamLookingforWoody_________786
@IamLookingforWoody_________786 6 ай бұрын
Hacker are now getting devlish or evil for money😢😢😢.
@fndrsm
@fndrsm 6 ай бұрын
hmm indonesia is always be soft target. lol
@ethaniel86
@ethaniel86 6 ай бұрын
China hacker?
@davidhoward4715
@davidhoward4715 6 ай бұрын
Russia hacker?
@RaytechHack
@RaytechHack 6 ай бұрын
Yes
@meerkat5818
@meerkat5818 6 ай бұрын
R*ssians as usual
@Ausf.D.A.K.
@Ausf.D.A.K. 6 ай бұрын
I only trust Kaspersky to ro protect me online.
@rekire___
@rekire___ 6 ай бұрын
The taste of their food and the face of their women made British man the best sailor in the world
@iamwitchergeraltofrivia9670
@iamwitchergeraltofrivia9670 6 ай бұрын
Fucking windows
@davidhoward4715
@davidhoward4715 6 ай бұрын
You didn't bother to watch the video, did you?
@louf7178
@louf7178 6 ай бұрын
Please use some sort of transitions in your videos. Ramming sentences together makes it difficult to listen to.
@TeenPerspektiva
@TeenPerspektiva 6 ай бұрын
What are you talking about lol. What do you want him to do? I think he is very clear and easy to understand. And i have never seen someone complain with something like that before
@louf7178
@louf7178 6 ай бұрын
@@TeenPerspektiva Like it says, jamming edits together without a break between sentences. What to do? Use a break. And now you've seen someone complain about it.
@TeenPerspektiva
@TeenPerspektiva 6 ай бұрын
@@louf7178 well i havent been able to notice the problem you are trying to point out. I dont see this jamming of edits you are talking about. Seems decently paced to me..
@louf7178
@louf7178 6 ай бұрын
@@TeenPerspektiva 2:12 - 3:16 It got info-dense, and I was expecting the rest to be similar. It did get better after that. For people that are not fluently familiar with the content, it gets to be too much.
@TeenPerspektiva
@TeenPerspektiva 6 ай бұрын
@@louf7178 i see. Thats fair enough
@hotsauce2446
@hotsauce2446 6 ай бұрын
So you're british? You dont sound it. Ugh.....
@axelbruv
@axelbruv 5 ай бұрын
Did you stub your toe at the end of that sentence?
@ROBOTRIX_eu
@ROBOTRIX_eu 6 ай бұрын
Kali Linux on Parallels on the MacBook Pro M4 Pro
10:15
BAYGUYSTAN | 1 СЕРИЯ | bayGUYS
36:55
bayGUYS
Рет қаралды 1,9 МЛН
How you get hacked: Undetected Malware
10:01
PC Security Channel
Рет қаралды 78 М.
Best Antivirus/EDR vs Unknown Ransomware
11:38
PC Security Channel
Рет қаралды 132 М.
Ransomware Is An Epidemic And It's Getting Worse | Cryptoland
24:19
How to stop apps from spying on Windows
10:28
PC Security Channel
Рет қаралды 63 М.
NEVER install these programs on your PC... EVER!!!
19:26
JayzTwoCents
Рет қаралды 4,7 МЛН
ThreatLocker: Zero Trust vs Malware & Exploits
11:41
PC Security Channel
Рет қаралды 24 М.
What is Ransomware?
12:48
IBM Technology
Рет қаралды 48 М.
7 Cybersecurity Tips NOBODY Tells You (but are EASY to do)
13:49
All Things Secured
Рет қаралды 1,1 МЛН
Windows Defender vs Top 100 Infostealers
10:00
PC Security Channel
Рет қаралды 78 М.