This nasty ransomware hacks your VPN to break into your device

cybercriminal
Image Credit: Pixabay (Image credit: Pixabay)

Cybercriminals have begun exploiting vulnerabilities in VPN servers in order to infect devices and corporate networks with the Cring ransomware according to new research from Kaspersky.

At the beginning of this year, a series of attacks was launched using this new ransomware and at the time, it was unclear how the attackers responsible were able to infect the network of an unspecified organization in Europe. However, following an investigation conducted by Kapsersky ICS CERT experts, it was revealed that unpatched VPN vulnerabilities were to blame.

Back in 2019, the CVE-2018-13379 vulnerability in Fortigate VPN servers became widely known. While the issue was addressed and patched by the company, some organizations did not update their VPN servers. In fact, so many companies failed to do so that ready-made lists containing the IP addresses of vulnerable servers and internet-facing devices began appearing on dark web forums last fall.

TechRadar needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

With these IP addresses in hand, cybercriminals are able to connect to a vulnerable VPN server remotely and access the session file which contains usernames and passwords stored in clear text.

Cring ransomware

According to Kaspersky's investigation, attackers are exploiting the CVE-2018-13379 vulnerability in Fortigate VPN servers to gain access to enterprise networks and infect organizations with the Cring ransomware. 

In a press release, security expert at Kaspersky Vyacheslav Kopeytsev provided further insight on the attack that occurred at the beginning of this year, saying:

“Various details of the attack indicate that the attackers had carefully analyzed the infrastructure of the targeted organization and prepared their own infrastructure and toolset based on the information collected at the reconnaissance stage. For example, the host server for the malware from which the Cring ransomware was downloaded had infiltration by IP address enabled and only responded to requests from several European countries. The attackers’ scripts disguised the activity of the malware as an operation by the enterprise’s antivirus solution and terminated the processes carried out by database servers (Microsoft SQL Server) and backup systems (Veeam) that were used on systems selected for encryption.” 

The ICS CERT experts at Kaspersky believe that the lack of timely database updates for the affected organization's security solution also played a key role as this prevented it from detecting and blocking the threat. Additionally, some components of their antivirus solution were disabled and this left them more vulnerable.

To protect networks and devices from the Cring ransomware, Kaspersky recommends that organizations keep their VPN Gateway firmware updated to the latest version, keep endpoint protection solutions and databases updated to the latest versions, restrict VPN access between facilities and close all ports that are not required.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Interlock ransomware attacks highlight need for greater security standards on critical infrastructure
A person holding out their hand with a digital AI symbol.
This ransomware gang is using SSH tunnels to target VMware appliances
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Huge cyber attack under way - 2.8 million IPs being used to target VPN devices
data recovery
Ghost ransomware has hit firms in over 70 countries, FBI and CISA warn
Best free Linux firewalls
Fortinet warns a critical vulnerability in its systems could let attackers breach company networks
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Latest in VPN Privacy & Security
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Google TV onscreen interface showing streaming apps
Why do streaming services geo-restrict content?
Pirate key on computer keyboard
Italy to require VPN and DNS providers to block pirated content
piracy
Canal+ wants to block VPN usage – and VPN providers are fuming
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day