Listen to this episode

Russian Hackers Hijacked MFA to Exploit Microsoft Vulnerability PrintNightmare

0:0023:14

Recorded March 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this Petronella Technology Group episode, Craig Petronella, Erin Dotsey and BJ discuss an FBI and CISA warning issued at the time of recording about Russian state-sponsored hackers exploiting a misconfigured DUO multi-factor authentication setup and the Windows PrintNightmare vulnerability. Craig explains that attackers used compromised credentials from a brute force password guessing attack to enroll their own device in the victim's MFA, then exploited PrintNightmare, which he says lets bad actors run arbitrary code with system privileges.

He recalls helping a manufacturing client air gap computers when no patch existed, and urges long, complex passwords, encrypted password managers and hardware or proximity tokens. BJ describes how an anonymous hacker used the search engine Shodan to pinpoint internet-connected devices at the Russian ministry of health and slip through an open VNC port with authentication disabled. The group argues that with 65,535 ports per device, people cannot keep up manually, and champions layered defenses, firewalls, vulnerability scanning, security risk assessments and XDR, whose machine learning and honeypots they say can turn defenders from victims into hunters.

Worth remembering

Key takeaways

  1. Craig explains that Russian state-sponsored actors exploited a misconfigured MFA account set to default at an NGO, enrolling their own device to reach the network.
    “as early as may Russian state sponsored cyber actors took advantage of a misconfigured account set to default on MFA protocols at a non-governmental organization or NGO”
  2. Craig warns that the PrintNightmare vulnerability lets attackers run arbitrary code with system-level privileges, and recalls air gapping a manufacturing client when no patch existed.
    “So this print nightmare bug allows the bad actors to run. Arbitrary code with system privileges.”
  3. Craig urges long, complex, unique passwords, an encrypted password manager, and hardware or proximity tokens to strengthen authentication.
    “But don't reuse it on multiple websites and better yet get a password manager that's encrypted and start changing your passwords immediately and maxing out the length.”
  4. Erin and Craig argue that without a patch, a computer must be disconnected from the internet or protected with XDR.
    “So how do you protect yourself if you're not patched? You can't, unless you have something like XDR right.”
  5. BJ describes an anonymous hacker who used Shodan to find IP addresses at the Russian ministry of health and enter through an open VNC port with authentication disabled.
    “They had the authentication disabled and he found this open VNC port and he slid right in.”
  6. Craig says every networked device has up to 65,535 ports, so properly configured firewalls are the first line of defense against hackers scanning for open doors.
    “If your firewall was configured properly. Then you would not be able to get to that ports on the VNC server.”
  7. Craig compares cyber defense to home security layers such as dogs, signs and cameras, while BJ says XDR learns the network and lures attackers into honeypots.
    “Honeypots in your network, in the background so that it can lure bad guys in and then gain threat intelligence from them.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

In this episode, the Petronella Technology Group group discusses how Russian hackers hijacked multi-factor authentication (MFA) methods to exploit a Windows Print Spooler vulnerability called PrintNightmare, and what YOU can do to protect yourself and your business from being the next victim.

Host : Craig Guests : Erin & BJ

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.