Six Government Agencies on Two Continents Just Warned About a Ransomware Franchise. It Even Rewrote Its Own Victim's MFA to Let Itself In.
On August 10, the FBI, CISA, the NSA, the US Secret Service, the Department of Defense Cyber Crime Center, and South Korea's National Police jointly warned about a ransomware operation that doesn't run like a gang anymore — it runs like a franchise. The people breaking in and the people who wrote the software are no longer the same people. One documented intrusion is the kind of detail that changes how you think about multi-factor authentication. Here's how the operation is structured, what actually happened, and what stops it.
Most of the ransomware coverage in this series has described a single group doing everything: breaking in, moving around, encrypting, extorting. The operation described in this joint advisory works differently, and the difference matters, because it's where a lot of modern ransomware is heading.
Rather than one team running start to finish, the people who built the ransomware now license it out. They provide the software, a management dashboard, and instructions. Independent criminals — sometimes explicitly recruited former penetration testers, people who understand how networks are broken into professionally — do the actual break-ins, using the provided toolkit. The proceeds get split. Nobody involved needs to be a programmer, and nobody involved needs to be a burglar. The roles are separated, the way a franchise separates the person who owns the brand from the person who runs the shop.
across two continents co-signed a single advisory about one ransomware operation
The advisory carries the joint authority of the FBI, CISA, the NSA, the US Secret Service, the Department of Defense Cyber Crime Center, and South Korea's National Police Agency — built on forensic detail from real investigated intrusions. Coordination at that scale reflects a group whose targets already span government, critical infrastructure and commercial organisations across multiple continents, and whose franchise model is actively expanding its reach.
How the franchise is structured
The operation first appeared as ordinary ransomware. What changed it into something worth six agencies' attention was a business decision: rather than keep growing one team, the operators opened the software up as a service, complete with the infrastructure that implies.
What one investigated intrusion actually looked like
The advisory is built on forensic detail from real cases, not a general description. Two findings from those investigations are worth understanding on their own.
The one piece of genuinely good news
Buried in the technical detail is something unusual: researchers examining the ransomware's Linux-targeting component found that it generates its encryption keys so poorly that, in some cases, defenders can reconstruct them from other evidence on the system and recover files without paying anything. This is rare — most ransomware implements its cryptography competently, because getting it wrong is bad for the operators' business model.
What this means for a small business specifically
The targets named in the advisory are large — governments, critical infrastructure, sizeable commercial organisations. It's tempting to read that as reassurance. It shouldn't be, for the same reason the franchise structure exists in the first place: affiliates are independent operators looking for targets, and a franchise model rewards volume over selectivity. The tools that get an affiliate into a well-defended government network work just as well, with less resistance, against a small business running the same category of exposed VPN appliance with the same unpatched firmware.
The techniques in this advisory are also not exotic. Exposed remote-access infrastructure, credential harvesting from a directory service, log deletion to buy time — every one of these is a documented, addressable weakness, not a capability unique to a nation-state.
Five things to check this week
Patch internet-facing VPN and firewall equipment first
Free · Do firstThis was the documented entry point. Remote-access infrastructure sits permanently exposed to the internet and is exactly what affiliates scan for. Confirm with whoever manages your systems that firmware and software on these devices is current, and ask when it was last checked.
Protect your directory service like the crown jewel it is
Review · FreeThe domain controller that manages every account's access is a single point that, once reached, hands an attacker the keys to everything. Ask whether it's monitored for unusual access attempts and whether administrative access to it is tightly restricted and logged.
Send your logs somewhere the attacker can't reach them
Low costEvidence deletion is a standard step in this playbook, and it works because logs usually live on the same systems the attacker already controls. Forwarding logs to a separate, restricted system means deleting the local copy no longer erases the trail — and gives investigators something to work with if the worst happens.
Keep offline, tested backups — because encryption isn't the only threat
EssentialDouble-extortion means backups solve only half the problem: they get you your systems back, but they don't undo data already stolen. Still essential, still non-negotiable, and worth confirming — as our earlier post on this topic put it — that a restore has actually been tested, not just configured.
Have a written incident response plan, and know who to call
FreeGiven the rare possibility of recovering without paying in some cases, speed and the right expertise on the first call matter enormously. A documented plan with named decision-makers and a response contact already identified is the difference between an organised response and a panicked one.
The short version
This isn't one sophisticated group anymore — it's a platform, licensed out to whoever wants to run it, expanding specifically because the model works. Six government agencies across two continents thought that expansion was worth a joint warning. One of the investigated intrusions shows attackers who didn't just get past multi-factor authentication, they rewrote what it meant for a code to be valid.
None of the fixes are exotic. Patch the internet-facing edge, protect the directory that controls every account, get your logs somewhere safe, keep backups that have actually been tested, and know who you're calling before the day you need to. The operation scaled by industrialising the attack. The defence hasn't had to change to match it — it's the same list this series has repeated all year, and it still works.
Find out whether the openings this advisory describes exist in your business.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series — Read the full series

Comments
Post a Comment