Axis Postmortem And Answers on Cyberattack

Published Feb 28, 2022 14:25 PM

After a cyberattack resulted in many Axis services being offline for a week, Axis has published a postmortem plus answered 7 questions from IPVM about the attack.

IPVM Image

In this note, we examine Axis postmortem, their responses to IPVM, and contrast it to the 2021 Verkada hack.

UPDATE: ******** ********

**** *** ******** *********** ********, ******* ****(****-**-** **:**). **** **** **** **** staff ******* *********** *** *******. **** report **** "*** ******** ************* ***** no *********** **** *** ********-, *******-, supplier-, ******* **** ** ****** **** was ********." **** ******** *** ******** in ********** **** ****.

**** ****** **** ******** ******** *** forensic ******* ** ******** *** ****** before *** *** **** *** ********. Therefore, ********-******* ******** **** ****. ***** services ******** **** *** **** ** that ******** ******** ***** ** **** for ******* ***** **** ****** ********* analysis.

**** *** *** ******** *** ******* of *** ******, ** **** **** down ******* ****** ** ***** ** determined. **** ******, "*** ************* ******** no ********** ******** ***** *** ****** to ***** ******** ************ ***** ** efficiently **** ******* *** ********* ****** completion, ***-******."

**** *** **** ** ****** *** threat ***** ******** ****: "******** *******, providing ********* **** ****** ******* ************, has **** ******* **********, ******** *** eradicated. ** ****** ** ********** ** other ******* ******* ******* *** **** found."

** *** *********** ******* ********* **** will **** *******.

IPVM Image

**********

************* ** ****** ** **** ****** page*** ******** ********* **** ** **.

IPVM Image

Social ***********

****** *********** *** **** ****** **** emphasized **** *** "******* ********** ********** such ** *********** **************" ***** *******.

********

"**** ****** ********* ******* ******* ******** "

** **** ******* ****** *** ***** of *** ****** *** ** ***** start *** ************* ****** * ****** of ***** ** ***** *******

No ****** *****

**** **** **** *** ****** ** the ******* ** ******* ** ****:

*** ******** ******* *** *** ****** is *******. ** **** **** ** stop *** ****** ** *** ***** stages ****** *** ***** ****** *** known. ** ********* ******* **** **** found ** ***.

*** ********* ****** **** ***** ******* to * ****** ******** ** **********.

Not ********** / ** *******

**** *** **** **** **** ** knowledge **** **** ** ********** *** that "** *****’* *** *** ******* with *** *********."

Country / ****** ** ********* ***********

** ***** **** **** **** ***** the *********, *.*., **** ******* **** were **** *** **** ******** ** share *** ***********, "*** ******** *******, we **** *** ******** ******* ********* the ****** ** *** ******."

Risks **** ****** ** *** ***

*** **** ******** ** ******* *** same **** ****** ******* *******, ***** has ****** **** ** ********* **** Russia *** ****** ****. *******, ** do *** **** ** **** *** simply ************.

**** ** **** ** **** ** attacks **** *** *** ***** **** video ************ ** ** ****** **** in ******** ************** ** *** ** and ***.

No ******** ** ******* ****

***** **** **** ** *** ********** that ** ******** **** *** ********, they ***** **** ** "******* ******* data" ** ******** ** * ******** from **** ***** **** ****** **** being ********:

** *** ** *** ************* *** shown ** ***, ** ****** *** attack ***** *** ******* ** **** it ****** *** ***** ****** *** done. ** ****no *********** that customer ** ******* ******* **** *** **** ******** in any way.

Shut ****, *** ***** ****

**** ********** **** **** **** **** their ******* *** **** *** ***** down, ****** ** **** *** *** shut **** ***** ******* **** ***** have ****** ***** ***** **** ** other ********* ********.

**** **** **** **** **** **** down ******* **** **** ***** ****** to *** **** **** ********:

** ***** ** **** ** ******* attack *******, *** ******** ** **** down ******** ******* ****** **** ******** systems **** **** ***** ****** ** be *********** **** *** **********. ** the ******, ** *** ******* ** securely ** ***** *** ******* *** production *****. ******** ***** ********* ***** time **** ** **** ******* ****** technically **********. ********* ** * ****** way ******* *** ******* ********.

Push ************* ******

*** ******* ** ****'* ******** ** take **** ***** ******* *** * lack ** ************ ** *********, ********* in *********** ********* ****** *** ***** 2 **** ***** **** *** *********. We ***** **** "**** *********** ** customers ** **** ** ********* ** some **** ** **** ************* *** outages" *** **** *********:

***. ** ***** ************ *** ******* our ******** *** *** ********* ******** in ***** *** **** ** **** educated ********* ***** ***** ***********.

Verkada **********

**** ** *** ******* ****** ************'* **** * **** ***. **** ******** **** ***** **** Verkada:

  • ******* *** * ***** ***** ******** that *** ******* ********.
  • ******* *** *** **** *********** ************** enabled *** ****.
  • *** ** *******'* ******* **** ******* as *** ******** ***** ******** ******* to ********'* *******.

******* **** * ****** ** ********* errors **** ****** ****.

** ********, ***** ** ** ********** Axis **** **** ********, **** ******** are ***** **** ****:

  • *** ******* ****** *** ***** ** to ***** * ***** ***** ********** and ******** ********* *** **** **** and *** ******* ****. *** **** hackers *** ******* *** ******** **** Axis ** ******* ***** ***** ********, it ****** ** * **** ******* attacker *** *** **** ** ** being *****-*********. ********, *** **** *** attacker **** ** ******* ***** ** less ****** **** **** ******** ******** to **** ***** *** **** ****** they ****** ********* ******** **** ****.
  • *** **** ****** **** ** *** roughly * ****. ***** **** * small ********** ** **** ********* *** Axis ***** ********, **** ***** ** likely ** ** * *********** ****** of ********* ***** **** ****.
  • **** ** * **** ******** **** critical ************** ***** ************ ********, ** any ****** ***** ** ************* **** of * **** **** *** ******* companies **** *** **** ******** **** in *** **********.

Shutting **** ******

*** ******* ******* ** *** **** disconnected *** ******* ****** ** ** increased ************** *** ****** ********* ******** problems.

*******, ****** **********"**** *** ******** ********* ******* ***********":

Stop ********** **** ****. Take all affected equipment offline immediately — but don’t turn any machines off until the forensic experts arrive.

** ** ************ ******** **** ******* ********** ******* (****** ***** **** says ** ********** **** **** ***). They ********* "****** *** ******* *********** offline" "** *** ****** *****" ****** "it *** *** ** ******** ** disconnect ********** ******* ****** ** ********":

IPVM Image

Comments (17)
UI
Undisclosed Integrator #1
Feb 28, 2022

****.*** ***** ***** ** **** **** issues.

**** **** ** *** ******* *** some ***** *** ******.

*** ********* ** ****.*** **** ***.****.***

(4)
(4)
UM
Undisclosed Manufacturer #5
Feb 28, 2022

* **** ******** ***** *** *** version ** ***** *******, *** **** is ** ******* ***** ** *** them ** ****** **** ** *** old ***...***

(2)
(12)
Avatar
Walter Holm
Mar 01, 2022
IPVMU Certified

* **** * ***** ** **** but **'* ******** **** *** ***** used ** *** ****** ************ **** axis.com ** ***.****.*** *** ** **** mitigate **, **** ******** ******* *** DNS ********** ** *** ****** ****.

(1)
UI
Undisclosed Integrator #2
Feb 28, 2022

*** ******** *** ***** ** ********** all ******** ************ *********** ** * way ** ******* *** ********* ***.

**** *** * **** ******* *******, but **** **** *********. ** **** had *** **** ****, ****** ***** have ****** **** ***, ** ********* could **** ***** ******** ****** *** moving ****** ***** ********** (******** **** were).

*** ** **** ********* *** "***". Typically, *** ******* ******** *******. ** the ****, **** **** ** *** bad, *** *** **** *** *** it *** ***, ** **** *** to ******************* *********** ********. ** ******* ************** pointed ***, ******** **** ******** *** not *** *******. *** *** ********* did ****** ********* ********, ***** *** incredible ***** ****** *** *******. *** the ******** **** *** ****** ** less *******, ****** ***** **** **** downhill.

******** **** *** ******** ** ***** and ******* *** ******** ********** ***** immediately **** *** ********* ** ******* and ********* ****** **** ** ****** operational ******.

***** *** ******* ****** *****"****** **** *****". **** *** ******, ******** ******* the ********, ********* *** ********* ******, and ******* **** ******. *** ** reinforce *** ********** ** ****** *******.

****, ******* ** ***** ********* *** identifying **** ********. ** *** ***'* log, *** *** *** **** ** able ** *** **** *** ******** compromised, *** ***** ****** ** ********** who **** **** *** **** **** were ****** ** **.

***** ******* ************ ** ****** ***********, attackers **** **** ** **** ** as * **** ******* ********** ********** such ** *********** **************.

****** **** ****** ** *** ******* link ** ********. ******. *** *** buy * ****** ********, * ******* IDS/IPS, *********/******** **********, ******* ****** ********* and ***, *** *** ***'* *** around ****** ***** ********* **** **** to ****** *** ******. *** ** you **** ******, *** *** ***** to **** ** **** **** ****** engineering.

---

* ***** **** ***** ** *** them ****** ********** ** * ****** site ****** * *** ** **, to ******** *********. **'* ******** **** the ************** ** *** ****** ***** that *** ****** ***** *** ******** been ******* ****. *** ****** **** could **** ****** **** **. ** you *********** **** ****** **** ****** or *****, **'* ******** **** ***** Sunday ******* *** *** ***** ** the **** **** ** ********* **** backup ***** **** **********. ********* **** will *** **** ** ** *********** to ******** ***** ******** ********** ***** so **** **** *** ****** **** if **** *** ** ****** **** this ** *** ******.

(6)
(9)
Avatar
Walter Holm
Mar 01, 2022
IPVMU Certified

******* ** *** *** ******* ****, SMS ** **** ******** *** ** is *****. **** ****** *** * bad **** ***, *** **** ** use ***** **** ******, *** ******** supports ***** *** **** **** **** out *** ***** ***.

** ******** *** ** ******** *** token, ** ******** ** **** ******** or ***** *** *** **** ** physically ***** *** ****** ** ******** so ** ****** ** ******** *********.

UM
Undisclosed Manufacturer #8
Mar 01, 2022

**** ********* ** *** *** *** Microsoft ************* *** ***. *** **** about *** **** ** *** *****.

(1)
Avatar
Walter Holm
Mar 02, 2022
IPVMU Certified

**** **** ***** ****, *********, *** and ***** ***** *** ***** ** used ** ******** *** **** ** these ********. *** ** *** *** just ******* ******* ****** *** ** not *********. ** ******* ***** *** how *** ** *********** *** ******* or *** *** ** ****** ** exclusive ** *** **** *** ***** or ***** ********.

***** *** ***** ****** *** *** best *** ** ****** ******** *** the ******** **** ** ***** ****** it ** **'* ********* (******** *** token, ***. *** *** **** ***) and *** *** ** ****** **** and *** **** ***** ** **** point ** *** **** ***** ******* you **** **** ******, *** **** do **** ******** ***** ** ******* too.

**** ** **** *** **** ** these ************* ****. ******* ***** ***** tokens *** *** ** ************* *** which ******** *** *** * ****** to *** (*** ** ***-* ** Apple *********).

***** ** ******* **** ***** ***** this ***** * ***:

********* *************: * ***** ***** ** Security? - ******** ******** ****

** ***** **** **** **'* *** site *** ********, *** ***** *** the **************.

(1)
UI
Undisclosed Integrator #3
Feb 28, 2022

* **** **** ****** ** ****** an *** ********* **** ** ********* 4. ********** ******** ** ** **** up *** ******* ** * **** out ** *** **** *****. **** to **** *** *** *** ********* have ******** **** **** ** ******** to *** ** *** *** ****. I **** ***** ** ******* *** firmware *** ********** *** ** *** functions ***** **** ** ******** ******** and ****** ** ********** **** *** site. ** ****** *** ****** ** the *.**.*.* ******** **** **** *** send ** ***** ** ******* ***********. Customers **** ** **** ***** * can *** **** ****.

(1)
(1)
Avatar
Brian Karas
Feb 28, 2022
Pelican Zero

** **** ** **** ** *******, but *** ******** ****** ** ***********:

****** ******** ******** ******* ********** ***** suspected ***** ******

(1)
(1)
Avatar
Brian Anderson, CPP®
Feb 28, 2022
IPVMU Certified

********** ****** ** ***** *** ********* to ** **** ****.

(4)
(1)
UI
Undisclosed Integrator #4
Feb 28, 2022

** ** ** *********** **** ** coincided **** *** ******* ********. ******* soldiers **** **** ****** ** ***** shooting *** ******** ******* *** **** was ****** **** ******* ****** ** help ****.

**********, ****** *** *** ***** **** for ****** ***** ***.

(3)
UI
Undisclosed Integrator #2
Feb 28, 2022

**** *** **** ***** **** ****:

** *** ***** ******* ********, ******** 19 *** ******, ******** **, **** was *** ******* ** * ***** attack. ** ***** **** ** ***** more *********** ***** **** ******** **** you.

What *** ********?

**** ****** ********* ******* ********** ********** behavior ** *** ******** *** ********** to ********** *** ******* *** ********. Details *** ** ***** ** * post-incident ****** ********.****.***.

How *** **** *******?

** ***** ** **** *** ****** quickly, **** ************ ****** *** ******* to ******* *** ********, ********* *** their ****. ** **** **** ******** services *** **** *****, **** ** in- *** ******** *****. ******* ******** were **** ******** ********.****** ********* ***** ***********.

How *** ** ****** **** *** *** *********?

***** ******** ****** *** *********** *********, Axis ***** ********* ******** ** * pace ******** ** ******** ******** ***** our ******* ********. *** ***** ********-****** services **** **** ********* ****** *******. Gradually ** *** **** *****, **** external ******** **** *******, *** *** majority *** *** ********* *****.

** *****, ** **** ******* ***** of ******** ************, *** ** *** able ** *******:

• ** ******** **** ** *********** was ***********.

• ** ************* *******, ********/******** ** development, ** ********/******** ********* *** ******** were ********. *** *** *** ******** development ********.

• ********* *** **** ******** ** installed **** ********* **** ** **** Camera ******* **** *** *********** ** the ******, ****** ******** **** **** Secure ****** ****** **** ****** *** as * **********.

• *** ****** ********** *** ****** chain ******** ******* ********** ******* *** entire ******.

What ** *** ****** ** **** ****** ******* ******* ******?

*** ******* ****** ** **** ****** for *********** ******** ******* **** ** normal. **** ****** ******* ************** *** activate ******** *** *** ****** *** through **** *-****** *******. *** ********* awaiting ****** ** ******* ****, ** are ********* ** *** **** ****** back ****** ** ** **** ** accept *** ****** *** ********.

Why **** ******** **** **** *** ***** **** ****? **** ** *** ****** ***?

*** *** ******** ** *** *********, our **** ****** ** ****** *** to ** **** ****** **** ***** ensuring ****** *** *********** *********. **** currently ******** ** * ********** ****. This **** ******** ** **** ** the ******** ************* ** ******* *** until *** ******** *** *********** ** completed.

** ** ******** **, **** ******** facing ******** **** **** ******** **** some ***** ******** ******** *********. ** expect *** ***** ***** ** *** customer ****** ******** ** ** ********** available ****** * *** ****.

What **** ****** ***** *******?

**** *** ******* **** **** ******** and *** ************* *** *********, **** incident **** ** ******** *********** ** determine *********** **** *****. ** ***** like ** ****** *** **** **** incident **** ********** *** ******** ********** to *** ********** ** ************* *** to **** **********. ** **** ******* future ********** ** **** ******** ** heighten *** ********** ** ********, ******** and *********.

***** *** *** **** ******* *** cooperation. ** *** **** *** *********, please ** *** ******** ** ******* your ******** **** **************.

**** *******,

**** **************

(1)
UE
Undisclosed End User #6
Feb 28, 2022

***. ** ***.

UI
Undisclosed Integrator #7
Mar 01, 2022

********** *** *** ********* ******** ******* are * *** ****.

*** ** **** *******. **'* **** so **********.........

*** *** ***** ****. ***'* ** the ****.

(2)
Avatar
Walter Holm
Mar 01, 2022
IPVMU Certified

**** *** ******* ***** * *** slower **** ****** ***. * *** taken **** *** * ****** **** someone ******** ** ***** ********* ***** working, *** * **** **** ** people ** ******** *** ******.****.*** ** well.

* ****** **** ***** ***** ***** services ** ** *****'* ********* ******* firewall ******* ** ******** *** ****** hosting ** **** **** ** ******** to ** ******** ***********.

Avatar
John Scanlan
Mar 07, 2022
IPVM • IPVMU Certified

**** ****** *** **** ******* **** the ********* ******* ***** ** *** forensic ******** **** **** ******:

UPDATE: ******** ********

**** *** ******** * *********** ******** ******, ******* ****(****-**-** **:**). **** **** **** **** staff ******* *********** *** *******. **** report **** "*** ******** ************* ***** no *********** **** *** ********-, *******-, supplier-, ******* **** ** ****** **** was ********." **** ******** *** ******** in ********** **** ****.

**** ****** **** ******** ******** *** forensic ******* ** ******** *** ****** before *** *** **** *** ********. Therefore, ********-******* ******** **** ****. ***** services ******** **** *** **** ** that ******** ******** ***** ** **** for ******* ***** **** ****** ********* analysis.

**** *** *** ******** *** ******* of *** ******, ** **** **** down ******* ****** ** ***** ** determined. **** ****** "*** ************* ******** no ********** ******** ***** *** ****** to ***** ******** ************ ***** ** efficiently **** ******* *** ********* ****** completion, ***-******."

**** *** **** ** ****** *** threat ***** ******** ****: "******** *******, providing ********* **** ****** ******* ************, has **** ******* **********, ******** *** eradicated. ** ****** ** ********** ** other ******* ******* ******* *** **** found."

** *** *********** ******* ********* **** will **** *******.

IPVM Image

(2)
Avatar
Dave Chisholm
Mar 08, 2022

* ******** **** *** ******* ** double ***** *** *** ********* ** some ***** ****** ** *** ****** manager *** **** ******** ******** ****** the ******* ****** ******** ** *********** Axis's ********* ******* *** ***********. * only *** * *** ** **** checking, *** **** *** *******.

* **** ********* **** ** ******* they ***** ***** *** ********** ** their ********, *** **** ****** ** least ********* ** *** ****.

** ***** ******** ** *****, ***** response ***** ********** ** **.

(2)