Ransomware isn’t anything new, but the ways in which hackers are exploiting accounts are changing. AI-driven attacks coupled with sophisticated technology have generated new tactics in just the last couple of years.
Phishing schemes and malicious links aren’t going anywhere; however, newer ransomware tactics are focused on speed, aggressive social engineering, and extortion without the need for file encryption.
The compressed timeline means that a user’s accounts or entire device can be compromised in less than an hour a significant departure from the days-long process back in the early 2000’s.
These new ransomware tactics are threatening the cybersecurity world as a whole. Individuals’ private information is more at risk, and organizations are having to change their security infrastructures to ensure their data remains safe.
One part of the system that remains a critical security risk, particularly because of these advanced tactics, is unmanaged local administrator accounts.
Keep reading to learn more about what constitutes an unmanaged local administrator account, how ransomware tactics are exploiting these accounts, and how to best protect your network.
To put it simply, unmanaged local administrator accounts are responsible for an individual workstation, as opposed to an entire domain. They are built-in or manually created high-privilege logins on individual devices.
They often fail to use unique passwords, which puts them at risk for cybersecurity attacks.
A common example is generic local accounts used by a company’s IT support or helpdesk team. These accounts are shared by multiple users and use a common password, which is verbally shared or written down among technical support staff.
Another example is the default built-in local administrative accounts on a Windows workstation. These servers likely have the same factory password across hundreds of machines.
If you’re unsure if your organization has unmanaged local administrator accounts, you can find them by cross-referencing any account names against corporate directory policies or centralized password managers, such as LAPS.
An endpoint inventory report can also be used to identify any accounts that lack centralized management.
A cybersecurity vendor can also help find unmanaged local administrator accounts by leveraging specialized tools for asset discovery and privilege auditing.
Because unmanaged local administrator accounts share the same username and password across multiple devices, they present a security risk known as “pass-the-hash.”
Also known as a lateral movement vulnerability, this means that if an attacker can break into one device, they can access every other device across the shared network via Server Message Block (SMB) or Remote Desktop Protocol (RDP).
Moreover, it’s hard to detect the initial break-in because there is no audit trail from one device to the next.
Another reason why newer tactics are exploiting these accounts is because of a phenomenon known as “living-off-the-land,” or LOTL. By using legitimate access credentials, bad actors blend in with normal behavior.
This makes it more challenging for security systems to detect actors in the first place, granting them access to the entire network before they corrupt the system entirely.
Once they are inside the system, they can disable any antivirus software, wipe event logs, and delete shadow copies to block recovery mechanisms.
Sophisticated actors can complete these steps relatively quickly, making it nearly impossible for the organization to regain its once-protected data.
But it’s not only gaining access and breaking down systems quickly that bad actors are interested in. Many are invested in the long-term, meaning they are focused on long-term data exfiltration.
Unmanaged local administrator accounts are perfect for maintaining silent access because they lack oversight and standard monitoring. With this, bad actors can be granted access to an entire network for an extended period of time.
Having this type of access can create chaos, as they deploy rogue tasks, modify registry Run keys, or create shadow admin accounts to mimic different types of software.
New ransomware tactics are becoming more sophisticated by the minute, which is why removing any unmanaged local admin accounts needs to be a priority.
As mentioned, these accounts give hackers easy access to an entire network and can cause both short- and long-term damage.
Once any unmanaged local admin accounts are identified, you can work to create unique passwords for every local admin.
This can be completed automatically using Microsoft LAPS, and any remote access can be blocked via Remote Desktop or PowerShell.
Again, a third-party cybersecurity vendor can assist in this process if you or your IT team lacks the time, tools, or internal staff expertise to secure these local accounts.
Next, be sure to set group policies to stop new local accounts from being created. Educating your staff on the risks of having unmanaged local admin accounts can be beneficial, and it never hurts to over-communicate cybersecurity risks in today’s digital-focused, remote working environment.
Lastly, continue to watch for any suspicious activity. Just because accounts have been disabled doesn’t mean you’re off the hook from any type of attack.
Turn on security logs to send alerts when a local admin logs in, and continuously audit and monitor administrative access as a preventative measure.
Setting these protocols in place will safeguard your network, catching unauthorized access early and stopping attackers before they cause detrimental damage.
Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…
Dark Caracal has returned with a new tool that helps attackers stay connected when defenders…
Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via…
The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as…
Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on…
More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter…