The BSI (German Federal Office for Information Security) has now published a report explaining the technical details of the attack path. It states that the entry point was a phishing email leading to a fake CAPTCHA prompt.
Many Steps to Compromise
Fake-CAPTCHA attacks are nothing new by now. Over time, they are simply modified and adapted again and again to remain effective. The variant that, according to the BSI, hit the Berlin Senate Administration is called TerminalFix. In this method, a “CAPTCHA” on a compromised website prompts the user to execute program code in the command prompt. However, this code downloads and executes malware. This malware embeds itself in hidden folders and files and creates scheduled tasks as well as registry run entries to ensure it continues to execute.
Importantly: this human error is only the beginning of a chain — the actual compromise of the network and the data exfiltration require significantly more work and time from the attackers, in this case the extortion group Rhysida.
According to the BSI, Rhysida first reconnoitered the IT infrastructure in order to determine, among other things, permission assignments, additional connected systems — particularly servers and their users — as well as backup processes. This allowed the attackers to identify where valuable data was located and how they could access and permanently encrypt it, so that it could no longer be restored even from backups.
Rhysida then exfiltrated the data via cloud storage, using copying tools provided by the cloud provider.
To ensure a persistent connection to the compromised network, Rhysida set up a reverse tunnel to a Python backdoor. This means they could repeatedly and unnoticeably reconnect to the target system and execute arbitrary commands.
Rhysida then attempted to deploy ransomware and demanded 30 Bitcoin from the city. However, the group failed in its extortion attempt, as the city decided not to pay the ransom. 30 Bitcoin currently corresponds to €2,063,900 — a considerable sum. In response, Rhysida made good on its threat and published the exfiltrated data online.
Protection Against Fake CAPTCHAs Is Not Enough
Anyone who believes the current news coverage might think that a single wrong click already leads to a data leak. However, it is not that simple. As illustrated above, most of these attacks require many steps and some time before the perpetrators reach their goal.
It would therefore be incorrect to hold solely the employee who fell for the fake CAPTCHA responsible. There is no such thing as 100% protection against social engineering tricks like fake CAPTCHAs anyway, nor should that be the goal. Only the interplay of multiple security measures limits the damage an intruder can cause. These include, for example:
- Access rights management
- Secure passwords
- Operating system security settings
- Installed updates
- Protection of sensitive data
- Monitoring by security software
This also means, however, that those who decide on the allocation of funds and other resources — and thus on what focus IT security should receive — bear a particular responsibility in preventing such cases.
IT Security Knowingly Neglected
In a ZDF interview, security expert and founder of AG KRITIS, Manuel Atug, explains the serious consequences of this attack.
Among the data accessed are state confidential protection information describing which buildings are to be particularly protected in the event of war. Terrorists, intelligence services, and warmongers now have information on the location of our most sensitive infrastructure, such as heating power plants for hospitals and emergency power systems.
Personal data has also reportedly become known, such as information about the management of arms manufacturers. These individuals reportedly now need personal protection, as the data leak could lead to “killings and hate campaigns” against them.
Manuel Atug does not mince words, stating that those responsible knowingly neglected IT security. The consequences of the leak will persist for decades, he says, since structural conditions cannot simply be changed.
