Latest / Tech Talks With Kinsoft / Space Bears Ransomware: Landscape, Impact, and Defense
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Great to
- 0:01have you with us. Today, we're tackling something
- 0:03really crucial, the cyber threat landscape. It
- 0:06just keeps changing, doesn't it? Our digital
- 0:08world, it's constantly shifting. And yeah, that
- 0:10brings a whole new set of security challenges.
- 0:12So our mission today is to, well, cut through
- 0:14the noise. We want to zero in on what's genuinely
- 0:16important right now. We'll be looking at key
- 0:18findings from a major industry report, and then
- 0:20we'll connect those broader trends to a very
- 0:24recent, pretty high -profile incident right here
- 0:26in Australia, actually. involving a managed service
- 0:28provider, the goal, to give you insights that
- 0:31aren't just surprising, maybe, but actually actionable,
- 0:35things you can use for your own security posture.
- 0:37Okay, let's get started. Right, first up, let's
- 0:40unpack some crucial new data. It's from the CyberCX
- 0:432025 Threat Report. This report is, well, it's
- 0:47a goldmine for understanding where things stand
- 0:49with cybersecurity. It draws insights straight
- 0:51from CyberCX's digital forensics and incident
- 0:53response team, their DFIR team. These are the
- 0:56folks on the front lines responding to serious
- 0:58incidents all through 2024. So this is, you know,
- 1:01real world, fresh intelligence. And what's really
- 1:04fascinating here, maybe a bit unsettling, too,
- 1:07is how the nature of these attacks is changing
- 1:09subtly, but significantly. And it seems our traditional
- 1:13detection methods, well, they're struggling sometimes
- 1:15to keep pace with certain kinds of threats. Yeah,
- 1:19the report really highlights this pretty astonishing
- 1:21difference in detection times. We call it time
- 1:23to detect, or TTD. Basically, the number of days
- 1:26between when an attack starts and when someone
- 1:28finds it. For espionage incidents, the average
- 1:31TTD is now over 400 days. 400 days. Over 400.
- 1:36Yeah, just think about that for a second. An
- 1:38adversary potentially lurking undetected in the
- 1:41system for, well, more than a year. It's like
- 1:43having a spy living in your house for ages before
- 1:46you even know they're there, just quietly taking
- 1:48your most valuable secrets. Now compare that
- 1:50with financially motivated attacks. Those are
- 1:53detected on average in just 24 days. Wow. So
- 1:56the implications for espionage are huge. These
- 1:58incidents, OK, they make up about 5 percent of
- 2:00the data they looked at, but they represent this
- 2:03persistent, incredibly stealthy threat that's
- 2:05just, well, very hard to dig up. That's an incredible
- 2:08difference over a year versus less than a month.
- 2:11What does that really tell us? I mean, about
- 2:13the nature of these threats? Are we just not
- 2:16equipped to find the stealthy ones or is it baked
- 2:19into their design? It speaks volumes about their
- 2:22goals, doesn't it? Financial attackers, they
- 2:24want a quick payout. So they make noise, demand
- 2:26ransom, obvious stuff. But espionage actors,
- 2:29they prioritize persistent access. Long -term
- 2:31intelligence gathering, that's the aim. They
- 2:33try to blend in, use legitimate tools, make subtle
- 2:36movements. Makes it incredibly hard to spot them
- 2:39against normal network traffic. So this shift,
- 2:41it really highlights a major challenge for defenders.
- 2:45You know, we're often still geared up for those
- 2:46loud, quick financial attacks while the really
- 2:49damaging law. long -term compromises might be
- 2:51slipping right through the net. Right. And speaking
- 2:53of evolving tactics, the report brings up something
- 2:56many of us rely on heavily, multi -factor authentication,
- 2:59MFA. It's crucial. We all know that. But the
- 3:02report suggests it's being bypassed more and
- 3:04more. It's not quite the silver bullet we thought,
- 3:07is it? Precisely. Not anymore. In 2024, get this,
- 3:11a staggering 75 percent, three quarters of business
- 3:15email compromise, BEC attacks involved the attackers
- 3:18bypassing MFA. 75 percent. 75. They're using
- 3:22these sophisticated phishing kits. session hijacking
- 3:26kits, sometimes called adversary in the middle
- 3:28or ATM techniques. So imagine an attacker basically
- 3:31sitting between you and say your Microsoft 365
- 3:34login. They intercept your login details and
- 3:37that act of session token you get. after you
- 3:39MFA. Ah, the token. Exactly. That lets them bypass
- 3:43MFA entirely and just waltz into your account
- 3:45as if they are you. This is a massive jump from,
- 3:48what was it, only 10 % back in 2022? Huge jump.
- 3:51It's not just a number, right? It's a real wake
- 3:53-up call that even our strongest defenses are
- 3:55constantly being tested and, well, broken. The
- 3:59key insight here, I think, is that security isn't
- 4:01just about what tools you have, like MFA. It's
- 4:03also about how resilient you are when things
- 4:05inevitably go wrong, even when trusted things
- 4:07like MFA get bypassed. That is a sobering thought.
- 4:09OK, so we know how attacks are changing, but
- 4:12who are they hitting hardest? Does the report
- 4:14show clear targets? Oh, absolutely. Looking at
- 4:17the 2024 data, health care was hit the most 17
- 4:20percent of incidents, then financial services
- 4:22at 11 percent and education at 8 percent. OK,
- 4:26health care, finance, education. Yeah. And the
- 4:28common thread, it's pretty clear. They all handle
- 4:30huge amounts of sensitive personal data, PII,
- 4:33health records, financial details. That makes
- 4:35them really attractive targets. Doesn't matter
- 4:37what the attacker's ultimate motivation is. Right.
- 4:39The data itself is the prize. Exactly. That old
- 4:42saying, data is the new oil. Maybe now it's the
- 4:45new currency in the cyber underworld. And what
- 4:47about those motivations? Is it still mostly about
- 4:49money or are other reasons creeping up? Financial
- 4:52motivation, yeah, it still dominates. That was
- 4:5465 % of incidents. About 27 % had an unknown.
- 4:57motive. And like we said, 5 % were espionage.
- 5:00But here's another interesting shift within those
- 5:02financial attacks. A big increase in what they
- 5:05call ransomware only incidents. Ransomware only.
- 5:09Meaning ransomware gets deployed, systems get
- 5:12encrypted, but the attackers don't actually steal
- 5:15any data beforehand. That jumped to 38 % of incidents
- 5:18in 2024. It was only 13 % the year before in
- 5:212023. And kind of the flip side. Cases where
- 5:25they only stole data but didn't deploy ransomware,
- 5:27those decreased. That shift to ransomware only
- 5:31is really interesting. So if they're not always
- 5:34stealing the data, what does that tell us? Maybe
- 5:36it's just simpler for them, less risky. I think
- 5:40that's part of it. It simplifies the whole operation
- 5:42for the attacker. No need to worry about storing
- 5:45huge amounts of stolen data, dealing with leak
- 5:47sites, law enforcement tracing data, none of
- 5:49that hassle. They just want the keys. They want
- 5:51the payment to unlock your systems and cause
- 5:53disruption. So even if your data isn't technically
- 5:55stolen and leaked, the paralysis from encrypted
- 5:58systems is still a massive threat. Absolutely.
- 6:01Business grinds to a halt. But, you know, one
- 6:03of the truly... One intriguing findings for me,
- 6:07maybe a bit unsettling, was something that kind
- 6:10of flips the script on ransomware. It's about
- 6:13what happens to the data that is stolen. If the
- 6:15victim doesn't pay the ransom, you'd think, OK,
- 6:17they don't pay. Data gets published. Simple.
- 6:19Yeah. That's the standard threat, isn't it? Pay
- 6:21up or we leak everything. So what did they find?
- 6:24Well, the report found that for about a quarter,
- 6:2725 percent of victims who had. data stolen but
- 6:31did not pay the ransom, that data was never actually
- 6:34advertised on leak sites or forums. A quarter.
- 6:37Yeah. So not paying doesn't automatically mean
- 6:40your data ends up plastered everywhere online.
- 6:43Now, the reasons why it wasn't published, that's
- 6:45the mystery. The report says it's unknown. It
- 6:47opens up a lot of questions, right? What are
- 6:48they doing with that data? Selling it privately,
- 6:50using it for other, maybe more targeted attacks
- 6:53later, intelligence gathering. So the threat
- 6:56landscape is getting murkier. Not paying is still
- 6:58risky. But the outcome isn't as predictable as
- 7:01we thought. Exactly. The threat model itself
- 7:03is becoming more opaque. It really underlines
- 7:06what Hamish Krebs from CyberCX said. He's their
- 7:08executive director of DFIR. He said, essentially,
- 7:12that despite everyone's best efforts, the threat
- 7:15landscape just keeps getting worse. Adversaries
- 7:17evolve. They up the tempo. It's relentless. OK,
- 7:21so these trends, they paint a worrying picture
- 7:23overall. But abstract trends are one thing. What
- 7:26does it look like on the ground? Let's shift
- 7:28gears and look at a very recent incident that
- 7:30really brings this stuff to life. The ransomware
- 7:33attack on Vertel, the Australian managed services
- 7:36provider. Right. This Vertel incident is a perfect
- 7:38example of these trends playing out right now.
- 7:40Vertel, they're based in Sydney, an MSP. They
- 7:43confirmed they had a cybersecurity incident starting
- 7:45around June 13th, 2025. The attackers were a
- 7:49group called Space Bears, relatively new ransomware
- 7:52operation. They listed Vertel on their leak site
- 7:54just five days later, June 18th. Space bears
- 7:57claim they took sensitive data, SQL databases,
- 8:00client TII, financial documents, that sort of
- 8:02thing. And they threatened to publish it all
- 8:04by the end of June if they didn't get paid. OK,
- 8:06standard ransomware playbook there with a threat.
- 8:08How did Voodoo Hotel respond? Their response
- 8:10seems pretty solid, actually. They brought in
- 8:12external cybersecurity experts, including CyberCX,
- 8:15interestingly, and Atmos. They're working with
- 8:18government authorities, too. And crucially, Vertell
- 8:21stated the incident hadn't impacted their ability
- 8:23to actually provide services to customers. That's
- 8:26key for an MSP. Keep the clients running. Absolutely.
- 8:29And they said they'd work directly with any clients
- 8:32who might be impacted as the investigation continues.
- 8:35Sounds like they're handling it professionally.
- 8:36Yeah. But connecting this back. Why MSPs? Why
- 8:40are providers like Vertel such attractive targets?
- 8:43We seem to hear about these attacks quite a bit.
- 8:45Yeah, it really highlights this growing vulnerability.
- 8:48MSPs are definitely prime targets. And this group,
- 8:52Space Bears. They only popped up in April 2024,
- 8:55but the report mentioned they've already hit
- 8:5673 victims. That's fast work. 73 in just over
- 9:00a year. Wow. Yeah. And what's really weird almost
- 9:02about Space Bears is their image. They have this
- 9:05unique kind of corporate persona. It's bizarre.
- 9:07Their leak site uses stock photos and they offer
- 9:10guarantees if you pay the ransom. Guarantees.
- 9:13Things like, you know, they promise to delete
- 9:15the data from their servers, give you the decryption
- 9:17tools, and even offer advice on how to prevent
- 9:19future attacks. Ransomware attackers offering
- 9:22security. advice. That's surreal. It's almost
- 9:24satirical, isn't it? A ransomware gang acting
- 9:26like a professional business offering customer
- 9:29service for extortion shows how businesslike
- 9:32these criminal operations have become. Now, origins.
- 9:35It's hard to pin down for sure, but they are
- 9:37believed to operate out of Moscow. And given
- 9:40the current geopolitical climate, well, these
- 9:43groups often act with a certain level of impunity,
- 9:45unfortunately. But back to your question why
- 9:48MSP is several big reasons. One. Centralized
- 9:51access. Attackers see an MSP as one key that
- 9:54potentially unlocks dozens, even hundreds of
- 9:57client networks. A single point of compromise
- 9:59for widespread impact. The jackpot scenario for
- 10:02them. Exactly. Two, high stakes data. MSPs often
- 10:06manage critical data for their clients. This
- 10:08increases the pressure, the likelihood that someone
- 10:10will pay the ransom because the cost of that
- 10:12data loss is just too high for the end clients.
- 10:14Three, the ripple effect. Hitting an MSP disrupts
- 10:18potentially numerous businesses all at once.
- 10:20once that amplifies the chaos and the pressure
- 10:23to pay quickly. Four, perceived weaknesses. Sometimes
- 10:26there's a perception, fair or not, that MSP security
- 10:29might be stretched thin because they're managing
- 10:31so many diverse clients with different setups
- 10:32and needs. And finally, five, trust and reputation.
- 10:36And MSP's whole business is built on trust. Attackers
- 10:39know this. They exploit it, figuring the MSP
- 10:41might pay just to minimize the reputational damage
- 10:44and restore client confidence fast. That makes
- 10:46perfect sense. So the Vertel attack isn't just
- 10:48some random event. It's a clear illustration
- 10:50of a major strategic vulnerability in the ecosystem.
- 10:53And it really underscores how critical it is
- 10:55for MSPs and honestly for everyone to double
- 10:58down on defenses, especially with groups like
- 11:00Space Bears out there getting more sophisticated,
- 11:02even if their branding is weird. OK, this brings
- 11:06us to the really crucial part. What can you listening
- 11:09right now actually do about all this? We've looked
- 11:11at the threats, how they're changing. The MFA
- 11:13bypasses the real world impact on organizations
- 11:16like Vertel. So let's focus now on actionable
- 11:19strategies. How can you protect yourself and
- 11:21your organization in this pretty challenging
- 11:23environment? Right. Building resilience, especially
- 11:26against ransomware with all these twists we've
- 11:28discussed, it really needs a layered, proactive
- 11:30approach. It's definitely not a one -time fix.
- 11:32It's ongoing. So let's break down some best practices
- 11:35for prevention. First, and you could argue it's
- 11:38the most important, the human element. Comprehensive
- 11:40employee training and awareness programs are
- 11:42just non -negotiable anymore. With that 75 %
- 11:45figure for MFA bypass and BEC attacks, your staff
- 11:50need education not just on basic phishing, but
- 11:52on these more advanced session hijacking attempts,
- 11:55spotting suspicious links, weird login prompts,
- 11:57stuff like that. Teaching them the subtle signs
- 12:00of an ATM attack, for example, makes them your
- 12:02absolute first line of defense, a critical line.
- 12:05Empowering the user. Makes sense. What about
- 12:07the deck side? Okay, technical fortification.
- 12:09This has several key layers. First, robust network
- 12:11security. That means strong firewalls, intrusion
- 12:14detection, intrusion prevention systems, and
- 12:16really critically, network segmentation. Segmentation,
- 12:20like dividing the network up. Exactly. Think
- 12:22of it like watertight compartments on a ship.
- 12:24If one area gets breached, ransomware hits one
- 12:27segment, it doesn't automatically spread and
- 12:29sink the whole ship. the whole network. It limits
- 12:32the blast radius. And of course, keep all your
- 12:34network gear regularly updated and patched. Basic,
- 12:37but vital. Second, advanced endpoint protection.
- 12:41You need solutions that go beyond just signature
- 12:43matching, things that use heuristic analysis,
- 12:46behavior monitoring, maybe AI. These tools look
- 12:49for suspicious activity on laptops, servers like
- 12:51unusual file encryption starting up, or attempts
- 12:54to tamper with system processes. They can often
- 12:56stop brand new, never seen before ransomware.
- 12:59And keep your standard anti -verisanti malware
- 13:01up to date too, naturally. Third, strong authentication.
- 13:05Enforce strong, unique passwords. Use password
- 13:07managers. And yes, even though we know MFA isn't
- 13:10a perfect silver bullet against every attack.
- 13:12Still essential. Still absolutely essential.
- 13:14Use it wherever you possibly can. It still blocks
- 13:17a huge number of attacks and significantly raises
- 13:20the difficulty for attackers. Fourth, data encryption.
- 13:24Encrypt your sensitive data, both when it's stored
- 13:26at rest and when it's moving in transit. If attackers
- 13:30do manage to steal it, strong encryption makes
- 13:32it useless garbage to them. And fifth, reduce
- 13:35your attack surface. Basically, disable any features,
- 13:38services, ports on your systems and applications
- 13:40that you don't actually need. Every unnecessary
- 13:43open door is a potential way in for attackers.
- 13:45Lock them down. Okay, that's a solid set of technical
- 13:48defenses. Human element, network, endpoint, authentication,
- 13:52encryption, reducing the surface. What else?
- 13:54Beyond those preventative tech measures, there's
- 13:56the ultimate safety net, regular data backup,
- 13:58and importantly, validation, testing those backups.
- 14:01Backups, always crucial. absolutely critical
- 14:03and they need to be stored securely off -site.
- 14:05Follow the 3 -2 -1 rule if you can. Three copies
- 14:09of your data on two different types of media
- 14:11with at least one copy off -site, and you must
- 14:13test them regularly to make sure you can actually
- 14:15restore from them. In a ransomware attack, having
- 14:18good tested backups is often the fundamental
- 14:20difference between getting back online relatively
- 14:23quickly and facing catastrophic, potentially
- 14:26business -ending data loss. And finally, preparation.
- 14:30Develop a proper, well -defined incident response
- 14:33plan. Know exactly what steps to take if an attack
- 14:35happens. Who does what? How do you contain it?
- 14:38Who communicates with whom? What are the recovery
- 14:40procedures? Having that plan ready before disaster
- 14:42strikes can drastically reduce the impact. And
- 14:44remember, all of this, it's an ongoing process.
- 14:47Prevention requires constant vigilance, constant
- 14:49adaptation to keep pace with these evolving threats.
- 14:51That's a really comprehensive rundown. And it
- 14:53hits home. The security isn't just a product
- 14:55you buy. It's a continuous process, a journey
- 14:57of adapting. So thinking about everything we've
- 15:00covered today, you know, the sophisticated MFA
- 15:03bypasses, these new ransomware groups like Space
- 15:06Bears with their weird corporate thing, those
- 15:08incredibly long dwell times for espionage, what
- 15:11really stands out to you listening about just
- 15:13how fast this cyber threat landscape is evolving?
- 15:16And maybe what continuous steps does your organization
- 15:19need to take to genuinely try and stay ahead?
- 15:22It really is a constant cat and mouse game, isn't
- 15:24it? And understanding the speed and the cleverness
- 15:27of the mouse is absolutely key for the cat. Something
- 15:29to think about. Well, that brings us to the end
- 15:31of another session here on Tech Talks with Kinsoft.
- 15:34We really hope this exploration of cyber trends
- 15:36for 2025 has given you some valuable insights,
- 15:39maybe some actionable knowledge to help protect
- 15:41your digital world. Staying informed, staying
- 15:43proactive. It's just more critical than ever
- 15:46in cybersecurity right now. And look, if you
- 15:48are looking to discuss your own security and
- 15:50IT needs, or maybe you want to learn more about
- 15:53how to protect your organization in this changing
- 15:55environment we've been talking about, you can
- 15:57find more information and reach out to the experts
- 15:59over at www .kinsoft .com .au. Thanks so much
- 16:03for tuning in, and we look forward to having
- 16:05you with us again next time on Tech Talks with
- 16:07Kinsoft.