The cyber actors took advantage of a misconfigured account set to default multifactor authentication protocols at a nongovernmental organization as early as May 2021. This allowed them to enroll a new device for multifactor authentication and access the victim’s network. They then exploited the PrintNightmare critical vulnerability. This allowed them to run arbitrary code with system privileges and access cloud and email accounts for document exfiltration.
The joint advisory includes indicators of compromise and mitigations. It also includes network, remote work, security and user awareness best practices.
Recommended mitigations include:
1. Enforcing multifactor authentication and reviewing configuration policies to protect against “fail open” and re-enrollment scenarios.
2. Ensuring inactive accounts are disabled uniformly across the active directory and multifactor authentication systems.
3. Patch all systems and prioritize patching for known exploited vulnerabilities.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.