Showing posts with label Kaspersky Lab. Show all posts
Showing posts with label Kaspersky Lab. Show all posts

Wednesday, October 25, 2017

Bad Rabbit Ransomware: ‘This Is A Targeted Attack’

ransomware


The Bad Rabbit ransomware is spreading across Europe not long after the WannaCry and NotPetya outbreaks. But Bad Rabbit is a “targeted attack” with widespread implications.


A new cyber attack is affecting numerous computer systems around Europe. The new strain of ransomware known as “Bad Rabbit” is believed to be behind all of the trouble.  Bad Rabbit has spread to Russia, Ukraine, Turkey, and Germany. Cybersecurity firm Kaspersky Lab, which is monitoring the malware, has compared it to the WannaCry and Petya attacks that caused so much chaos earlier in the year.


According to the Kaspersky Lab, the majority of victims are located in Russia, and the ransomware appears to have infected devices through the hacked websites of Russian media organizations. Interfax and Fontanka in Russia have both been hit by a cyber attack, as have Odessa Airport and the Kiev Metro in Ukraine.


“Based on our investigation, this is a targeted attack against corporate networks, using methods similar to those used in the ExPetr attack,” Kaspersky Lab has said. “However, we cannot confirm it is related to ExPetr.” According to Secure Lst,  ExPetr is a wiper, not ransomware. “The dangerous aspect is the fact that it was able to infect many institutions which constitute critical infrastructure in such a short timeframe,” says Robert Lipovsky, a malware researcher at ESET, “which indicates a well-coordinated attack.”



Kaspersky also found strong evidence tying the new attack to the creators of NotPetya. After the June NotPetya outbreak, the company’s analysts found that one Ukrainian news site, Bahmut.com.ua, had been hacked to deliver the malware, along with dozens of other sites that were similarly corrupted—but hadn’t yet been activated to start infecting victims. Now Kaspersky has found that 30 of those hacked sites began to distribute the BadRabbit malware on Tuesday. –Wired



“This indicates that the actors behind ExPetr/NotPetya have been carefully planning the BadRabbit attack since July,” writes Costin Raiu, the director of Kaspersky’s global research and analysis team, in a note to Wired.


The cyber criminals behind Bad Rabbit are locking computers down and demanding 0.05 Bitcoin (roughly $277 at the time of this article’s construction) from victims, in exchange for the restoration of their devices. However, security experts always advise people against paying the ransom. This is because it encourages more attacks, and there’s no guarantee the attackers will actually honor their word and remove the malware from your device once you’ve paid the fee.


According to the Bad Rabbit ransom screen, the demanded fee will rise in the near future too.  NotPetya took down a number of Ukrainian government agencies and businesses in June, before spreading rapidly through corporate networks of multinationals with operations or suppliers in eastern Europe. According to Wire, Bad Rabbit is linked to NotPetya.

Monday, October 16, 2017

"Not The Russians" - British MPs Blame Iran For "Brute Force" Hack

Yet another purported example of Russia-linked hackers infiltrating the email accounts of powerful government officials    has been conclusively debunked.


The Guardian is reporting that a June incident where the accounts of dozens of UK ministers of parliament were infiltrated by shadowy hackers has been traced back to Iran. The UK intelligence community’s initial conclusion – that the attacks originated in Russia – has been refuted by an as-yet-unpublished report on the incident compiled by British intelligence.


Indeed, the intelligence community’s initial assumption appears to be another example of investigators jumping to a conclusion before a thorough analysis of the evidence has been completed. In a way, it echoes the response by several US states last month to the revelation that hackers had attempted to compromise their voting systems. Some states, including California and Wisconsin, apparently assumed the attacks were linked to Russia, until DHS informed them that it had found no evidence to support this conclusion.



The June 23 cyberattack affected the accounts of dozens of MPs, including Prime Minister Theresa May and several senior other senior ministers. The network that was compromised is used by every MP for interactions with constituents, the Guardian reported.


Initially, UK intelligence determined that hackers had attempted to gain access to accounts protected by weak passwords – despite repeated warnings to choose strong, hard-to-crack passwords.


An anonymous “security source” cited by the Guardian said the hackers used unsophisticated “brute force” attacks where the hackers use specifically designed programs to test out hundreds of thousands of different passwords combinations. “It was a brute-force attack. It appears to have been state-sponsored. The nature of cyber-attacks means it is notoriously difficult to attribute an incident to a specific actor.”


Conservative MP Andrew Bridgen added that the attack “absolutely” could leave some people open to blackmail. “Constituents want to know the information they send to us is completely secure,” he said.


Initially, suspicion had fallen upon foreign governments such as Russia and North Korea, both of which have been accused of orchestrating previous hacking attempts in the UK.


Liam Fox, the international trade secretary, said the incident reinforced the notion that MPs need to take extra precaution when securing their data.


“We know that our public services are attacked, so it is not at all surprising that there should be an attempt to hack into parliamentary emails,” he said. “And it’s a warning to everybody, whether they are in parliament or elsewhere, that they need to do everything possible to maintain their own cybersecurity.”


Given the furor that erupted after DHS ordered US government agencies to immediately remove security software designed by Russia-based firm Kaspersky Labs, the revelation about Iran’s involvement in the UK hacks should give intelligence agencies – not to mention lawmakers who seemingly blame Russia for every incidence of cyber meddling uncovered by US intelligence – pause. After the WSJ reported that Kaspersky’s software was essentially being leveraged by the Russian government to create an international spy network, German intelligence announced that they had found no evidence to support this claim.


And while many have blamed Russia-linked hackers for last year’s hack of DNC emails, including emails sent by Hillary Clinton Campaign Chairman John Podesta, Wikileaks’ Julian Assange is reportedly offering President Donald Trump conclusive evidence that he says would debunk this claim.


However, Chief of Staff John Kelly has rebutted one Congressman’s attempts to bring the deal to President Trump. But as the multiple investigations into whether Trump campaign colluded with the Russian government to sway the election in the president’s favor have apparently hit a wall, Assange’s evidence might be the key to silencing these suspicions, which have cast an unsubstantiated pall of illegitimacy over Trump’s first term in office.
 

Sunday, May 14, 2017

"Over 200,000 Infected": Europol Fears Computers Simply Won't Start Monday After "Unrivalled" Global Cyberattack

There was a silver lining in what has been dubbed the "world"s biggest ransomware attack" - it struck on Friday mid-afternoon (in Europe), just as businesses were winding down for the weekend, and as a result the full impact of the forced system shutdowns would not be fully felt over the weekend when businesses and infrastructure are generally operating at a subdued pace. However, with the weekend coming to a close, the full extent of the inflicted damage may become apparent in just a few hours.


That was the warning by Europol Executive Director Rob Wainwright who on ITV’s “Peston on Sunday” broadcast, said that additional disruptions are likely as people return to work Monday and turn on their desktop systems, and as a result the "unrivaled" global cyberattack is poised to continue claiming victims.



Speaking to ITV’s, Wainwright added the attack was indiscriminate across the private and public sectors.


“At the moment we are in the face of an escalating threat, the numbers are going up, I am worried about how the numbers will continue to grow when people go to work and turn their machines on Monday morning."


“The latest count is over 200,000 victims in at least 150 countries. Many of those will be businesses including large corporations.”


“We’ve seen the rise of ransomware becoming the principal threat, I think, but this is something we haven’t seen before -- the global reach is unprecedented,” Wainwright also said. He also said that organisations across the globe, including investigators from the National Crime Agency (NCA), are now working non-stop to hunt down those responsible for the ransomware.


As we reported on Saturday, the initial attack was halted when a security researcher disabled a key mechanism used by the worm to spread, but experts said the hackers were likely to mount a second attack because so many users of personal computers with Microsoft operating systems couldn’t or didn’t download a security patch released in March that Microsoft had labeled “critical.” Microsoft said in a blog post Saturday that it was taking the “highly unusual“ step of providing the patch for older versions of Windows it was otherwise no longer supporting, including Windows XP and Windows Server 2003.




As the WSJ confirms, the attacks could worsen on Monday morning because of how the virus works.





The virus contains two parts. One is the ransomware, which locks the computer files and displays a message saying that the files will be locked and eventually destroyed unless the user sends payment over the internet to the hacker.



The other part is known as the "spreader." Once the virus makes its way onto one computer--perhaps when a user opens an infected email attachment--the spreader transmits itself to other computers on the network.



The British researcher, who wishes to be identified only as MalwareTech, found a kill switch in the spreader. The spreader was designed to contact a web address to see whether it should further spread itself, but hackers hadn"t bought that web address. So MalwareTech did, and effectively stopped the virus"s spread. It meant that one computer in a network could be infected, but the worm wouldn"t spread to the rest of the network.



Cybersecurity experts expect the latest versions of the worm to have no kill switch for the spreader. So when workers return to the office Monday morning and turn on their computers, they might open an infected email attachment or connect an already-infected laptop to their organization"s non-security-patched network and spread the worm.



There was some good news: having tipped their hand on Friday, and allowing hacking countermeasures to be implemented, about 97% of U.K. facilities and doctors disabled by the attack were back to normal operation, Home Secretary Amber Rudd said Saturday after a government meeting. As reported on Friday, at the height of the attack Friday and early Saturday, 48 organizations in the NHS were affected, and hospitals in London, North West England and Central England urged people with non-emergency conditions to stay away as technicians tried to stop the spread of the malicious software.


“There will be lessons to learn from what appears to be the biggest criminal cyber-attack in history,” Rudd said cited by Bloomberg in response to a letter from Jonathan Ashworth, the shadow secretary of state for health.


Meanwhile, according to Tom Robinson, chief operating officer and co-founder of Elliptic Enterprises Ltd., a ransomware consultant that works with banks and companies, victims have already paid about $30,000 in ransom so far, with the total expected to rise substantially next week, said . Robinson, in an interview by email, said he calculated the total based on payments tracked to Bitcoin addresses specified in the ransom demands. The number, which is likely a conservative estimate, will only embolden the hackers to become even more aggressive in their next attack.





Ransomware is a particularly stubborn problem because victims are often tricked into allowing the malicious software to run on their computers, and the encryption happens too fast for security software to catch it. Some security expects calculate that ransomware may bring in as much as $1 billion a year in revenue for the attackers.



According to Bloomberg, last year an acute-care hospital in Hollywood paid $17,000 in bitcoin to an extortionist who hijacked its computer systems and forced doctors and staff to revert to pen and paper for record-keeping.


On one hand, it is probable that the weekend gave many companies the opportunity to prepare for the next ransomware attack: "While any sized company could be vulnerable, many large organizations with robust security departments would have prioritized the update that Microsoft released in March and wouldn’t be vulnerable to Friday’s attack."


Even so, it does not explain why some of the world"s biggest corporations were so strikingly unprepared for Friday"s events. 





A spokesman for Spain’s Telefonica SA said the hack affected some employees at its headquarters, but the phone company is attacked frequently and the impact of Friday’s incident wasn’t major. FedEx said it was “experiencing interference,” the Associated Press reported.



Renault halted production at some factories to stop the virus from spreading, a spokesman said Saturday, while Nissan’s U.K. car plant in Sunderland, in northeast England, was affected without causing any major impact on business, an official said.



In Germany, Deutsche Bahn faced “technical disruptions” on electronic displays at train stations, but travel was unaffected, the company said in a statement on its website. Newspaper reports showed images of a ransomware message on display screens blocking train information.



Russia’s Interior Ministry, with oversight of the police forces, said about “1,000 computers were infected,” which it described as less than 1 percent of the total, according to its website.



Indonesia’s government reported two hospitals in Jakarta were affected.



Meanwhile, the latest anti-Russia narrative is growing.


"There is a high probability that Russian-language cybercriminals were behind the attack" said Aleks Gostev, chief cybersecurity expert for Kaspersky Labs. “Ransomware is traditionally their topic,” he said. “The geography of attacks that hit post-Soviet Union most also suggests that.” In retrospect, what more convenient confluence of events could there be than having a handy justification for Q2 GDP missing again - just blame it on the computer virus - and accusing Russia of being responsible for the latest global slowdown.