Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

Thursday, December 21, 2017

Kim Orders Military To Test Anthrax: North Korea Will ‘Take Revenge’ On US

nkbomb


The leader of North Korea, Kim Jong-Un, has said he will take revenge on the United States for Washington’s accusal that the rogue regime was responsible for the WannaCry ransomware attack earlier this year. In timely fashion, Kim has also ordered his military to begin the testing of the chemical agent anthrax.


North Korea has been loading anthrax into int’s controversial ballistic missiles. But the regime and military scientists have been trying to ensure that anthrax would survive the high temperatures generated when the missiles re-enter the Earth’s atmosphere.  Anthrax is a serious infectious disease caused by gram-positive, rod-shaped bacteria known as Bacillus anthracis. The regime today rejected the claim as “groundless” and insisted it was fulfilling its obligations under the Biological Weapons Convention (BWC) which prohibits the production or stockpile of biowarfare weapons.


North Korean state television reported last month the launch of a new intercontinental ballistic missile, Hwasong 15, which is a nuclear-capable weapon which could fly as far as America.


A report in Japan’s Asahi newspaper warned the regime may have “already succeeded” in its experiments. The article, which cites an anonymous source connected to South Korean intelligence, says: “North Korea has started experiments such as heat and pressure equipment to prevent anthrax from dying even at a high temperature of over 7,000 degrees generated at the time of ICBM’s re-entry into the atmosphere. In part, there is unconfirmed information that it has already succeeded in such experiments.”


This comes as the regime warns the United States that they will enact revenge for the accusation that North Korea was responsible for the WannaCry ransomware attack that affected 230,000 computers.  “The [WannaCry] attack was widespread and cost billions, and North Korea is directly responsible,” Thomas P. Bossert, Trump’s homeland security adviser, said in an op-ed published in the Wall Street Journal on Monday. “We do not make this allegation lightly. It is based on evidence. We are not alone with our findings, either.”


“This was a reckless attack and it was meant to cause havoc and destruction,” Bossert said at a news conference. Drawing a connection between North Korea’s alleged cyber activities and its development of nuclear weapons, he added, “I think, at this point, North Korea has demonstrated that they want to hold the entire world at risk, whether it be through its nuclear program or cyberattacks.”


“The DPRK, as a state party to the BWC, maintains its consistent stand to oppose development, manufacture, stockpiling and possession of biological weapons,” said North Korean state-run propaganda media. “The more the US clings to the anti-DPRK stifling move, the more hardened the determination of our entire military personnel and people to take revenge will be.”


Despite the North’s denials, experts believe Kim may have one of the largest arsenals of bioweapons in the world.

Wednesday, October 25, 2017

Bad Rabbit Ransomware: ‘This Is A Targeted Attack’

ransomware


The Bad Rabbit ransomware is spreading across Europe not long after the WannaCry and NotPetya outbreaks. But Bad Rabbit is a “targeted attack” with widespread implications.


A new cyber attack is affecting numerous computer systems around Europe. The new strain of ransomware known as “Bad Rabbit” is believed to be behind all of the trouble.  Bad Rabbit has spread to Russia, Ukraine, Turkey, and Germany. Cybersecurity firm Kaspersky Lab, which is monitoring the malware, has compared it to the WannaCry and Petya attacks that caused so much chaos earlier in the year.


According to the Kaspersky Lab, the majority of victims are located in Russia, and the ransomware appears to have infected devices through the hacked websites of Russian media organizations. Interfax and Fontanka in Russia have both been hit by a cyber attack, as have Odessa Airport and the Kiev Metro in Ukraine.


“Based on our investigation, this is a targeted attack against corporate networks, using methods similar to those used in the ExPetr attack,” Kaspersky Lab has said. “However, we cannot confirm it is related to ExPetr.” According to Secure Lst,  ExPetr is a wiper, not ransomware. “The dangerous aspect is the fact that it was able to infect many institutions which constitute critical infrastructure in such a short timeframe,” says Robert Lipovsky, a malware researcher at ESET, “which indicates a well-coordinated attack.”



Kaspersky also found strong evidence tying the new attack to the creators of NotPetya. After the June NotPetya outbreak, the company’s analysts found that one Ukrainian news site, Bahmut.com.ua, had been hacked to deliver the malware, along with dozens of other sites that were similarly corrupted—but hadn’t yet been activated to start infecting victims. Now Kaspersky has found that 30 of those hacked sites began to distribute the BadRabbit malware on Tuesday. –Wired



This indicates that the actors behind ExPetr/NotPetya have been carefully planning the BadRabbit attack since July,” writes Costin Raiu, the director of Kaspersky’s global research and analysis team, in a note to Wired.


The cyber criminals behind Bad Rabbit are locking computers down and demanding 0.05 Bitcoin (roughly $277 at the time of this article’s construction) from victims, in exchange for the restoration of their devices. However, security experts always advise people against paying the ransom. This is because it encourages more attacks, and there’s no guarantee the attackers will actually honor their word and remove the malware from your device once you’ve paid the fee.


According to the Bad Rabbit ransom screen, the demanded fee will rise in the near future too.  NotPetya took down a number of Ukrainian government agencies and businesses in June, before spreading rapidly through corporate networks of multinationals with operations or suppliers in eastern Europe. According to Wire, Bad Rabbit is linked to NotPetya.

Thursday, July 6, 2017

Ransomware Slams Hospitals; Surgeries Delayed; Computer Network Destroyed

Ransomware Hits Hospitals; Surgeries Delayed; Computer Network Destroyed

Image source: Pixabay.com



A ransomware attack delayed surgeries and shut down laboratories and diagnostic facilities at two hospitals in Pennsylvania last week and also shut down the computer network at a hospital in West Virginia.


“Thank God I was able to get my surgery,” patient Brenda Pisarsky posted to Facebook on June 28.


Pisarsky was in the Heritage Valley Beaver Hospital in Beaver, Pa., for a gallbladder operation when the ransomware hit, The Pittsburgh Post-Gazette reported.


Surgeries at the two hospitals operated by Heritage Valley Health were rescheduled and laboratories shut down. At least one patient, Dorothy Tully, was told to come back in five to seven days, Action News 4 reported.


Learn How To Make Powerful Herbal Medicines, Right in Your Kitchen!


Computer monitors were turned off and nurses were scurrying around with stacks of paper at the Pennsylvania hospitals. One unidentified patient was in the operating room when his surgery was delayed.


Meanwhile, the Princeton Community Hospital in Bluefield, W.Va, was forced to rebuild its computer network because of the same ransomware, known as Petya.


“As a precaution to prevent any computer re-infection, the hospital will rebuild its computer network from scratch,” hospital marketing director Richard Hypes told The Bluefield Daily Telegraph.


Petya apparently infected around 100 computers at the West Virginia facility.


“As a result, a handful of non-emergency early morning procedures were canceled,” Hypes said.


Petya appears to be ransomware, which locks users out of computers and demands $300 worth of bitcoin for access.


What is your reaction? Share it in the section below:  

Thursday, June 29, 2017

Ransomware Still Only Makes Up Small Share Of Growing Malware Threat

One type of malware has captured the attention of the world. Recent ransomware attacks show the devastating effects it can have on business and infrastructure.


After a worldwide attack with a cryptoworm called "WannaCry" in May, another attack with a strain of ransomware called "Petya" started on Tuesday and kept on spreading around the world on Wednesday.


As Statista"s Dyfed Loesche notes, malware has come a long way in the last ten years, as the infographic below shows.


Infographic: Ransomware Makes up Small Share of Growing Malware Threat | Statista


You will find more statistics at Statista


According to analysts with IT-security software firm G Data, the number of new malware specimen is likely to reach more than 7.4 million this year alone. Albeit this number seems to spell bad news only, the data also indicates that the malware growth rate is slowing.


It is also important to note that according to data provided by IT-security institute AV-Test, ransomware (such as "WannaCry" and "Petya") only makes up a very small share of all malware detected worldwide.


However, this just goes to show that the number of specimen of a certain kind of malware does not reflect its actual potential for damage.

Wednesday, June 28, 2017

New Ransomware Shutting Down Banks, ATMs, Computers Worldwide

New Ransomware Shutting Down Banks, ATMs, Computers Worldwide

Image source: Pixabay.com



A new variant of the WannaCry ransomware that may have originated in North Korea was attacking banks and other vital infrastructure around the world Tuesday – and it has yet to stop.


The cyber weapon had hit Russia, the Ukraine, the United Kingdom and the United States and was demanding payment in bitcoin before the virus could be removed. In the Ukraine, it knocked out ATMs and supermarket cash registers, in addition to computers at banks, the Kiev airport, and the power grid.


It also had impacted Russian banks, and in the U.S., the pharmaceutical company Merck.


“We are urgently responding to reports of another major ransomware attack on businesses in Europe,” Rob Wainwright, executive director of Europol, wrote on Twitter. Europol is the European Union’s law enforcement agency.


Discover How To Become Invisible In Today’s Surveillance State!


Other targets included the world’s largest advertising agency, WPP; international law firm DLA Piper; French construction company St. Gobain; the Russian oil company Rosneft; and the Danish shipping firm AP Moller-Maersk.


Some were calling the new ransomware “Petya.”


The source of Petya was unknown but it is similar to ransomware that disrupted operations at the British National Health Service in May. Experts believe that attack originated in North Korea, the BBC reported.


The malicious code used in May, said cybersecurity researcher Adrian Nish, is identical to code found in earlier cyberweapons that were blamed on the Lazarus Group, which works for North Korea’s Kim Jong-un.


“It seems to tie back to the same code-base and the same authors,” Nish says. “The code overlaps are significant.”


The Lazarus Group is one of the world’s most active gangs of hackers. Nish thinks it was responsible for the theft of $81 million from Bangladesh’s central bank in 2016. Lazarus also was blamed for hacking Sony Pictures in 2014 in an attempt to prevent the release of a movie that mocked North Korea.


“It was one of the biggest bank heists of all time in physical space or in cyberspace,” Nish said.


The purpose of the earlier ransomware attack was to extort money from users, Nish said. WannaCry locks users of computers, and then demands $383.67 in bitcoin to regain access. The Petya virus was doing the same thing on Tuesday.


“Just because you roll out a patch doesn’t mean it’ll be put in place quickly,” said Carl Herberger, vice president of security at Radware, told The New York Times. “The more bureaucratic an organization is, the higher chance it won’t have updated its software.”


What is your reaction? Share it in the section below:

Thursday, May 25, 2017

This Is The World's Most Active Battlefield - Watch Cyber-War In Real-Time

Today’s most active battlefield is not located on the ground, in the air, or on the mighty seas. It’s taking place on the internet – and, as Visual Capitalist"s Jeff Desjardins notes, if you’re still a non-believer, spend a few minutes with the following live map to watch a representation of cyber attacks as they happen...


Created by Norse Corporation, a cyber intelligence firm that claims to get instant attack telemetry from over eight million sensors deployed worldwide, the map visualizes cyberwar in real-time and organizes attacks by type, origin, and target. (A full-screen version is also available.)



Source: Visual Capitalist


PREDATOR AND PREY


Who is responsible for these attacks, and who is the target?


In our few minutes of watching, the United States received nearly 70% of incoming attacks:


Cyberwar and types of attacks


While we were not expecting this live visualization to literally cover every single hack worldwide, this does seem to match up with the ratio from other sources. For example, in a previous infographic on cyberwar, we noted that the U.S. is targeted in 66% of web application attacks, and in 54% of cyber espionage hacks.


In our few minutes of watching, about half of the attacks also originated from the United States. However, many also were launched from other countries such as China, Ukraine, and The Netherlands.


THE SCALE IS REAL


While the idea of cyber warfare still seems like science fiction for many people, recent events such as the WannaCry ransomware attack have made the scale and potential implications of cyber warfare much more real.


WannaCry Map


The above map from AFP shows that the WannaCry attack was unprecedented in scale, infecting more than 230,000 computers in over 150 countries. Using an exploit developed by the NSA, WannaCry infected Britain’s National Health Service (NHS), Spain’s Telefónica, FedEx, and Deutsche Bahn, along with many other companies or countries.


Ultimately, the hack had a built-in “killswitch” that was discovered by internet security experts. It also seemed to be relatively ineffective at collecting hefty amounts of ransom. Despite all of this, the reality is that the hack shut down hospitals and other businesses, giving us a true taste of the scale and impact that a professionally-executed cyber attack could have in the future.

Wednesday, May 24, 2017

WannaCry Attackers Have Links To North Korea's Lazarus Group

Cybersecurity researchers at Symantec say they"ve found linkes between the WannaCry Ransomware attackers was likely carried out by a hacking group with ties to North Korea.


In a blog post, Symantec said the “Tools and infrastructure used in the WannaCry ransomware attacks have strong links to Lazarus, the group that was responsible for the destructive attacks on Sony Pictures and the theft of $81 million from the Bangladesh Central Bank.”


Here"s a summary of links provided by Symantec:


  • Following the first WannaCry attack in February, three pieces of malware linked to Lazarus were discovered on the victim’s network: Trojan.Volgmer and two variants of Backdoor.Destover, the disk-wiping tool used in the Sony Pictures attacks.

  • Trojan.Alphanc, which was used to spread WannaCry in the March and April attacks, is a modified version of Backdoor.Duuzer, which has previously been linked to Lazarus.

  • Trojan.Bravonc used the same IP addresses for command and control as Backdoor.Duuzer and Backdoor.Destover, both of which have been linked to Lazarus.

  • Backdoor.Bravonc has similar code obfuscation as WannaCry and Infostealer.Fakepude (which has been linked to Lazarus).

  • There is shared code between WannaCry and Backdoor.Contopee, which has previously been linked to Lazarus.

Symantec discovered that the WannaCry attackers used some of the same hacking tools that were previousky used in other Lazarus Group attacks. There are also, the group reported, “a number of links between WannaCry itself and Lazarus.”


The WannaCry ransomware, for example, shares some code with a piece of malware that has previously been linked to Lazarus.




Symantec also found that the WannaCry attackers used some of the same network infrastructure as the Lazarus Group. “There are a number of crossovers seen in the C&C servers used in the WannaCry campaigns and by other known Lazarus tools.”


Beginning a week ago Friday, the WannaCry virus infected thousands of computers around the world, threatening to destroy users" data unless a ransom was paid in bitcoin. Ultimately, the group received less than $100,000, and most of the data were destroyed.

Tuesday, May 23, 2017

Cyber Attacks Are The Perfect Trigger For A Stock Market Crash

Cyber Attacks Are The Perfect Trigger For A Stock Market Crash | cyber-grenade | Economy & Business Science & Technology Sleuth Journal Special Interests


The world has been stunned over the past few days by the advent of “Ransomware;” the use of sophisticated cyber attacks on vital systems in order to (supposedly) extort capital from target businesses and institutions. I am always highly suspicious whenever a large scale cyber incident occurs, primarily because the manner in which these events are explained to the public does not begin to cover certain important realities. For example, the mainstream media rarely if ever discusses the fact that many digital systems are deliberately designed to be vulnerable.


Software and internet corporate monoliths have long been cooperating with the NSA through programs like PRISM to provide government agencies backdoor access to computer systems worldwide. Edward Snowden vindicated numerous “conspiracy theorists” in 2013 with his comprehensive data dumps, exposing collusion between corporations and the NSA including Microsoft, Skype, Apple, Google, Facebook and Yahoo. And make no mistake, nothing has changed since then.



The level of collusion between major software developers and the establishment might be shocking to some, but it was rather well known to alternative analysts and researchers. The use of legislation like the Foreign Intelligence Surveillance Act (FISA) to skirt Constitutional protections within the 4th Amendment has been open policy for quite some time. It only made sense that government agencies and their corporate partners would use it as a rationale to develop vast protocols for invading people’s privacy, including American citizens.


The issue is, in the process of engineering software and networks with Swiss cheese-like defenses in the name of “national security,” such exploits make vast spreads of infrastructure vulnerable to attack. I think it likely this was the intention all along. That is to say, the NSA and other agencies have created a rather perfect breeding ground for false flag attacks, real attacks and general crisis.


It should be noted that the Ransomware attacks which struck systems around the world used “Wannacrypt,” derived from an NSA exploit called “Eternalblue.” This program was designed to specifically target Microsoft Windows machines, no doubt using vulnerabilities which Microsoft ENGINEERED into their own software. Now, interestingly, a batch of NSA exploits was published online by a hacker group called “the shadow brokers” only last month. From the information I have gathered so far, it seems that “Eternalblue” was part of that data dump and that the Ransomware incident is directly connected.


Something else that is very interesting about Eternalblue — as CNN notes, similar exploits were used not long ago by the NSA to get backdoor access to financial data within the SWIFT banking system. This was rather odd because through international agreements the NSA already had front door access to such data. However, front door access can be tracked and traced and any illicit activity can be exposed. Therefore, the NSA must have had something more nefarious in mind than simply looking for terrorist activity, such as testing the effectiveness of their own exploits for future use in attacks.


I mention the incident with SWIFT because it brings up a potential danger that I don’t think many people have considered. First, let’s assume for a moment that groups like the “shadow brokers” actually exist and aren’t some kind of NSA created front. These groups are using the considerable weaknesses that corporations like Microsoft put in place for the NSA in order to reap profits through criminal enterprise or to commit terrorist acts. The NSA and its Silicon Valley partners literally created this monster; a monster which has the capacity to attack otherwise secure banking networks like SWIFT.


This begs the question — how much of the global banking system and global stock exchanges are open to attack with these same NSA exploits. I would suggest that ALL of them are.


Second, let’s consider for a moment the possibility that groups like the “shadow brokers” are mostly fraudulent fronts for establishment agencies and elitists. Consider that maybe, just maybe, the NSA is releasing some of these exploits on purpose to the public. Why? Well, one might consider that issue complicated, but to summarize, it may be very advantageous for international banks and governments to deliberately place financial systems at risk.


In my article The Economic End Game Explained, I outline in detail with evidence why the establishment is seeking a major economic crisis within the near term. Organizations like the IMF have been talking excitedly for the past few years about something they call “the great global economic reset.” The details behind this “reset” are rather vague, but the general notion is that the economic systems of today are going to evolve in a painful way and that certain elements of our fiscal structure could be wiped clean altogether. In order for such a “reset” to take place, some kind of crisis event would be needed or would happen inevitably as a consequence.


In order for a new economic system to be entrenched, the old system has to be dismantled; but how can banking moguls and globalist interests succeed in doing this without taking the blame for the ultimate social and geopolitical suffering and carnage that would result? Well, they would need scapegoats.


Some of these scapegoats will be political in origin. For example, the mainstream media has been pumping out non-stop rhetoric suggesting that the next global crisis will be a direct result of the “rise of populism and nationalism” within Western societies. Meaning conservatives, classical liberals and sovereignty champions are the new patsies for economic instabilities that the globalists built into the system long ago.


Some of these scapegoats, though, will be far more illusory and intangible.



It is my belief that agencies like the NSA are unleashing some of their own exploits to the public on purpose. But what does this accomplish?  For one, it makes the use of false flag attacks more viable. If attacks like Ransomware continue to escalate, the public may in a sense become normalized to them. What if one of these attacks targets major financial elements? Say the large networks of algorithmic computers that dominate stock transactions today come under threat; what would be the result? Most likely complete market disaster. And, almost everyone in the world will believe the culprit was some kind of terrorist hacking group, rather than the establishment itself, which has the most to gain from this brand of catastrophe.


Also, the establishment may simply be hoping that if they release enough of these exploits which they have been devising for years, someone will use them to attack the financial system autonomously. That is to say, the establishment does not necessarily need to use false flag attacks to bring down stock markets or banking networks. All they need to do is put the weapons out in the open and wait for someone to fall to temptation and do their dirty work for them.


I would compare this to the act of forcefully injecting millions of Muslim immigrants into western nations without a rational vetting process. If the elites want more terrorism in Europe, for instance, they don’t have to do all the work of forming domestic cells and training the members as they have done in the Middle East with ISIS. All they have to do is leave the front door wide open in the name of “humanitarianism” and allow the enemy to waltz right in.


This strategy gives the establishment plausible deniability while also giving them the crisis environment they secretly desire.


Our economy and the economies of most nations today stand upon a razor’s edge. Historically negative data is now reported weekly. Hard and “soft” data indicates a massive downturn is lurking under the surface. In fact, the ONLY elements of the economy which remain “positive” are stocks and some currencies. This is what we call a bubble scenario. The globalists have managed to stretch equities markets for years on the back of untold stimulus measures, but this illusion is quickly coming to an end.


Central banks are backing away from quantitative easing and steadily increasing interest rates, removing cheap debt as a tool to prop up stocks. The era of easy money is almost over. It seems to me that this is a perfect time for a trigger event that is completely unrelated to the financial elites, an event that will distract the public away from their culpability. This is not to say that a cyber attack on our market networks will be the only trigger event or distraction, but I am starting to think it will be a primary measure, no doubt while the world is mesmerized by James Comey “memos” and other such nonsense.


The NSA and other organizations have handcrafted global networks to fail, and not just fail, but fail spectacularly leaving maximum destruction in their wake. I do not think this was done without foresight. Events like Ransomware might only be the beginning. Watch this trend carefully, and be extra vigilant if cyber attacks begin to target financial institutions and systems. If this does happen, the “great economic reset” may not be far away.



This article was republished from Alt-Market.com.


After 8 long years of ultra-loose monetary policy from the Federal Reserve, it’s no secret that inflation is primed to soar. If your IRA or 401(k) is exposed to this threat, it’s critical to act now! That’s why thousands of Americans are moving their retirement into a Gold IRA. Learn how you can too with a free info kit on gold from Birch Gold Group. It reveals the little-known IRS Tax Law to move your IRA or 401(k) into gold. Click here to get your free Info Kit on Gold.


If you would like to support the publishing of articles like the one you have just read, visit our donations page here.  We greatly appreciate your patronage.

Thursday, May 18, 2017

Ransomware Is Tip Of The Iceberg: “You Could See 90% Of Americans Die As A Result Of A Prolonged Power Outage Because The Grid Gets Hacked” (VIDEO)

Ransomware Is Tip Of The Iceberg: “You Could See 90% Of Americans Die As A Result Of A Prolonged Power Outage Because The Grid Gets Hacked” (VIDEO) | power-outage | Multimedia Science & Technology Sleuth Journal Special Interests US News


The Ransomware that began spreading across the globe on Friday is still going with more computers reportedly being affected today by new variants of the virus.


What we’ve learned is that the attack hasn’t just taken down personal computers, but core government and business networks affecting everything from health care systems and transportation in Europe, to ATM withdrawals in China.



It’s massive, to be sure. But in the grand scheme of things, up to this point, it has been a fairly minor inconvenience.


But as Joe Joseph warns in his latest news report at The Daily Sheeple, this is just the tip of the iceberg, because now that we’ve seen how quickly such an attack can spread, it’s only a matter of time before rogue groups or state-sponsored players make a direct attempt at taking down core systems that keep millions of people in America alive. As we’ve previously noted, U.S. cyber command has warned that power grids, physical infrastructure and commerce systems will be a major target of future cyber attacks, and the latest Ransomware attack utilizing NSA-created exploits proves just how serious the damage could be:



Experts are saying this is just the tip of the iceberg… what the NSA has done and the damage they have caused as the result of coming up with these exploits in the first place is criminal… but it’s beyond criminal… in our society we have become so dependent on technology.. our computers… our cell phone…


We’ve become so hooked on it that if something happens and it looks like it can very easily happen… where some of these hacks are exploited… we could see an instantaneous change in the way that we live… to the point where you could see upwards of 80% or 90% of the population just in the United States dying as a result of a prolonged power outage because the grid gets hacked…




(Watch full report at Youtube)


Joseph’s figure of a 90% die off in the event of a grid failure is based on the work of EMP researcher Dr. Peter Pry, who recently testified before a Congressional panel on the dangers of “grid down” scenarios resulting from electro-magnetic pulse attack. Though Pry’s research is primarily based on the threat of a nuclear device being detonated a couple hundred miles above the central United States taking out the entirety of the domestic power grid, the end result of a grid-down scenario, whether initiated by a cyber attack or something else, is very much the same.


Without the grid, all life in America would come to a standstill. Gas station pumps wouldn’t work, which means trucks couldn’t deliver food to grocery stores. And even if your local store still had food on the shelves, cash registers and bank payment verification systems would be unavailable, making hard currency like gold and silver the only means of transacting. As we’ve seen in China over the weekend, ATM’s would likely be inaccessible. So, too, would be your access to clean water, as most utility plants are tied to the power grid.


In short, within about 72 hours, there would be pandemonium in the streets, as highlighted by The Prepper’s Blueprint author Tess Pennington in her article The Anatomy of a Breakdown:



3-5 days following a disaster is the bewitching hour. During this short amount of time, the population slowly becomes a powder keg full of angry, desperate citizens. A good example is the chaos that ensued in New Orleans following the absence of action from the local government or a timely effective federal response in the aftermath of Hurricane Katrina. In such troubled times, people were forced to fend for themselves and their families, by any means necessary. This timeline of Hurricane Katrina effectively illustrates “the breakdown,” and within three days, the citizens of New Orleans descended into anarchy, looting and murder.



If the crisis extends for any more than about a week, you can expect full-out war on the streets of America as people race to acquire the last remaining resources.


Within one year, predicts Peter Pry, nine out of ten Americans would be dead because of starvation or violence.


It may sound incredible, but if you consider the reality of our dependence on technology, a multi-week or multi-month hiccup in the system will be enough to bring the entire thing crashing down.


Even the Department of Homeland Security recently warned about the potential for devastating cyber attacks, going so far as to recommend that families need to prepare at least two weeks of food and emergency supplies because the federal government may be overwhelmed and unable to provide assistance.

Tuesday, May 16, 2017

How The NSA Started A Worldwide Ransomware Attack

How The NSA Started A Worldwide Ransomware Attack

Image source: Pixabay.com



The NSA is to blame for the ransomware that spread worldwide in recent days and hit Britain’s hospitals and even FedEx, Microsoft is alleging.


“The WannaCrypt exploits used in the attack were drawn from the exploits stolen from the National Security Agency, or NSA, in the United States,” Microsoft President and Chief Legal Officer Brad Smith wrote in a May 14 blog post. “An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen.”


Smith is referring to the Wannacry ransomware, which froze computers and disrupted service at several hospitals run by Britain’s National Health Service (NHS). The attack caused emergency rooms to turn away ambulances and led to the cancellation of some operations, The Guardian reported.


Wannacry takes over computers and demands that users pay $300 in bitcoin to get access to their own data. The NHS was simply one of many victims of Friday’s cyberwarfare attack. The attack is one of the largest in history and may have affected 200,000 computers in 150 countries, the Europol law enforcement agency estimated.


Are Your Prepared If A Cyberattack Cripples The Power Grid? Get Backup Electricity Today!


The ransomware took advantage of a weakness in the Microsoft operating system – a weakness that the NSA knew about but decided to keep to itself so it could use it to penetrate computers.


“We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world,” Smith wrote. “Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. … And this most recent attack represents a completely unintended but disconcerting link between the two most serious forms of cybersecurity threats in the world today – nation-state action and organized criminal action.”


The NSA and CIA should alert software companies of weaknesses so they can be fixed, he added.


“The governments of the world should treat this attack as a wake-up call,” Smith wrote. “They need to take a different approach and adhere in cyberspace to the same rules applied to weapons in the physical world. We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits.”


What is your reaction? Share it in the section below:

Monday, May 15, 2017

Cyberattacks expected to spread Monday as Europol fears computer systems simply won’t start

Update: confirming our earlier report that Monday could get ugly for global computer system, the WSJ writes on Sunday afternoon that Cybersecurity experts are expecting another wave of computer-system attacks that encrypt files and demand ransom to unlock them on Monday, as companies and government agencies are seeking to restore normal operations and figure out the roots of the attack.



The attacks, which made over 200,000 victims in at least 150 countries, affect only computers running Microsoft Corp.’s Windows that haven’t installed the security patch that the company released in March, or the emergency patch it released for older Windows systems over the weekend. The problem is that it can take organizations, especially large ones, a long time to install these patches.


“I think there’s going to be a lot of infections Monday morning,” said Ofer Israeli, chief executive of Tel Aviv-based cybersecurity firm Illusive Networks.



“Time will tell how quickly people are going to patch their systems.” If the answer is “not fast enough”, what started off as a modest crippling of global Windows-based system, could become a full-blown global paralysis.


Earlier


There was a silver lining in what has been dubbed the “world’s biggest ransomware attack” – it struck on Friday mid-afternoon (in Europe), just as businesses were winding down for the weekend, and as a result the full impact of the forced system shutdowns would not be fully felt over the weekend when businesses and infrastructure are generally operating at a subdued pace. However, with the weekend coming to a close, the full extent of the inflicted damage may become apparent in just a few hours.


That was the warning by Europol Executive Director Rob Wainwright who on ITV’s “Peston on Sunday” broadcast, said that additional disruptions are likely as people return to work Monday and turn on their desktop systems, and as a result the “unrivaled” global cyberattack is poised to continue claiming victims.


Speaking to ITV’s, Wainwright added the attack was indiscriminate across the private and public sectors.


At the moment we are in the face of an escalating threat, the numbers are going up, I am worried about how the numbers will continue to grow when people go to work and turn their machines on Monday morning.”


“The latest count is over 200,000 victims in at least 150 countries. Many of those will be businesses including large corporations.”


“We’ve seen the rise of ransomware becoming the principal threat, I think, but this is something we haven’t seen before — the global reach is unprecedented,” Wainwright also said. He also said that organisations across the globe, including investigators from the National Crime Agency (NCA), are now working non-stop to hunt down those responsible for the ransomware.


As we reported on Saturday, the initial attack was halted when a security researcher disabled a key mechanism used by the worm to spread, but experts said the hackers were likely to mount a second attack because so many users of personal computers with Microsoft operating systems couldn’t or didn’t download a security patch released in March that Microsoft had labeled “critical.” Microsoft said in a blog post Saturday that it was taking the “highly unusual“ step of providing the patch for older versions of Windows it was otherwise no longer supporting, including Windows XP and Windows Server 2003.


As the WSJ confirms, the attacks could worsen on Monday morning because of how the virus works.



The virus contains two parts. One is the ransomware, which locks the computer files and displays a message saying that the files will be locked and eventually destroyed unless the user sends payment over the internet to the hacker.


The other part is known as the “spreader.” Once the virus makes its way onto one computer–perhaps when a user opens an infected email attachment–the spreader transmits itself to other computers on the network.


The British researcher, who wishes to be identified only as MalwareTech, found a kill switch in the spreader. The spreader was designed to contact a web address to see whether it should further spread itself, but hackers hadn’t bought that web address. So MalwareTech did, and effectively stopped the virus’s spread. It meant that one computer in a network could be infected, but the worm wouldn’t spread to the rest of the network.


Cybersecurity experts expect the latest versions of the worm to have no kill switch for the spreader. So when workers return to the office Monday morning and turn on their computers, they might open an infected email attachment or connect an already-infected laptop to their organization’s non-security-patched network and spread the worm.



There was some good news: having tipped their hand on Friday, and allowing hacking countermeasures to be implemented, about 97% of U.K. facilities and doctors disabled by the attack were back to normal operation, Home Secretary Amber Rudd said Saturday after a government meeting. As reported on Friday, at the height of the attack Friday and early Saturday, 48 organizations in the NHS were affected, and hospitals in London, North West England and Central England urged people with non-emergency conditions to stay away as technicians tried to stop the spread of the malicious software.


“There will be lessons to learn from what appears to be the biggest criminal cyber-attack in history,” Rudd said cited by Bloomberg in response to a letter from Jonathan Ashworth, the shadow secretary of state for health.


Meanwhile, according to Tom Robinson, chief operating officer and co-founder of Elliptic Enterprises Ltd., a ransomware consultant that works with banks and companies, victims have already paid about $30,000 in ransom so far, with the total expected to rise substantially next week, said . Robinson, in an interview by email, said he calculated the total based on payments tracked to Bitcoin addresses specified in the ransom demands. The number, which is likely a conservative estimate, will only embolden the hackers to become even more aggressive in their next attack.



Ransomware is a particularly stubborn problem because victims are often tricked into allowing the malicious software to run on their computers, and the encryption happens too fast for security software to catch it. Some security expects calculate that ransomware may bring in as much as $1 billion a year in revenue for the attackers.



According to Bloomberg, last year an acute-care hospital in Hollywood paid $17,000 in bitcoin to an extortionist who hijacked its computer systems and forced doctors and staff to revert to pen and paper for record-keeping.


On one hand, it is probable that the weekend gave many companies the opportunity to prepare for the next ransomware attack: “While any sized company could be vulnerable, many large organizations with robust security departments would have prioritized the update that Microsoft released in March and wouldn’t be vulnerable to Friday’s attack.”


Even so, it does not explain why some of the world’s biggest corporations were so strikingly unprepared for Friday’s events.



A spokesman for Spain’s Telefonica SA said the hack affected some employees at its headquarters, but the phone company is attacked frequently and the impact of Friday’s incident wasn’t major. FedEx said it was “experiencing interference,” the Associated Press reported.


Renault halted production at some factories to stop the virus from spreading, a spokesman said Saturday, while Nissan’s U.K. car plant in Sunderland, in northeast England, was affected without causing any major impact on business, an official said.


In Germany, Deutsche Bahn faced “technical disruptions” on electronic displays at train stations, but travel was unaffected, the company said in a statement on its website. Newspaper reports showed images of a ransomware message on display screens blocking train information.


Russia’s Interior Ministry, with oversight of the police forces, said about “1,000 computers were infected,” which it described as less than 1 percent of the total, according to its website.


Indonesia’s government reported two hospitals in Jakarta were affected.



Meanwhile, the latest anti-Russia narrative is growing.


“There is a high probability that Russian-language cybercriminals were behind the attack” said Aleks Gostev, chief cybersecurity expert for Kaspersky Labs. “Ransomware is traditionally their topic,” he said. “The geography of attacks that hit post-Soviet Union most also suggests that.” In retrospect, what more convenient confluence of events could there be than having a handy justification for Q2 GDP missing again – just blame it on the computer virus – and accusing Russia of being responsible for the latest global slowdown.


Via Zero Hedge


(Photo Credit: photosteve101/Flickr)

Saturday, May 13, 2017

The NSA’s Virus Can Still Destroy Your Data, Here Are 5 Ways to Make Sure It Won’t




Thanks to the NSA’s apparent lust to know and see everything, agency-designed ransomware virus was unleashed on the planet yesterday, leaving anyone using a Windows system — corporations, governments, and even those who only post cat pictures online — vulnerable to exploitation for a price.


That price — $300 in Bitcoin, increasing after a given time period — would theoretically have to be paid in order to rid the infected computer of the WanaCrypt ransomware, or the victim would lose everything on their system. Ransomware literally holds your data hostage until the fee asked by attackers is paid — but if you don’t pay, you lose everything.


Everything.


WanaCrypt0r, alternately known as WanaCry, WanaCrypt, or WCry, is believed to have infected no less than 126,500 computers in 99 countries prior to the threat being partially abated — but not before it had wrought havoc on the U.K.’s National Health Service, FedEx, Spanish telecommunications company, Telefónica, and other systems around the globe.


“This is one of the largest global ransomware attacks the cyber community has ever seen,” Splunk director of threat research, Rich Barger, told Reuters. Splunk is one of several firms who divined WanaCrypt0r’s origins with the National Security Agency.


Analysts say the particularly infectious worm exploited a Microsoft software flaw, and, although the company issued a patch in March after identifying WCry in February, not all users had updated their systems accordingly.


Cybersecurity experts worked at a fever pitch to stop the malicious worm, but it took what the Guardian termed an “accidental hero” to bring a tentative halt to the pandemonium. Reports the outlet, a Twitter user, “tweeting as @malwaretechblog, with the help of Darien Huss from security firm Proofpoint, found and inadvertently activated a ‘kill switch’ in the malicious software.”


He “halted the global spread of an unprecedented ransomware attack by registering a garbled domain name hidden in the malware has warned the attack could be rebooted.”


And payment of the $10.69 registration fee — temporary, though the end to the exploit may be — was all it took.


A significant risk could still be lurking — after all, the attackers used tools designed by the NSA, whose entire collection of older hacking tools were leaked online last month by an entity calling itself the Shadow Brokers, and WCry could yet mutate or be altered — but there are a few ways to stay safe and prevent having precious data and files wrested from you.



1. Update, update, update


As tech outlet, Tom’s Guide, notes, “If you’ve not installed the March, April or May Windows Update bundles, do so immediately. It’s worth shutting down your system for a few minutes if it gives you a chance to avoid this.”


Windows Vista users will be protected through the March or April update bundles, and Microsoft has since issued a patch for Windows XP and its 2003 server — while the company released information to help customers cope with the ransomware virus.


2. Don’t fall hook, line, or sinker


Although WanaCrypt exploits the aforementioned Windows vulnerability, people must be vigilant — as always — not to fall for online phishing schemes, as this malware could also have been spread randomly in hopes people would open email from an unfamiliar source.


Be exceedingly cautious when visiting websites and opening attachments — WanaCry could be ready to pounce. Use common sense — and pepper it with extraordinary discretion.


3. Back it up


Cybersecurity experts constantly harangue the rest of us to backup important data and files, and — while that directive might generate an eyeroll, and grumblings about time and energy — backing up one’s system is an imperative which now cannot be ignored.


Storing vital information in a secondary location, such as a USB storage stick or external hard drive, could save you tears and headaches in the long run — particularly if WCry or another variant takes control of your system. Cloud storage could be an option — depending on which cloud you use, as the original NSA leaker and insider, Edward Snowden, has warned — but would also leave your data vulnerable in other ways.


4. Get your defenses up


Install solid, reputable antivirus software — particularly one targeting ransomware — as a line of defense against the intrusion. Experts now say WanaCrypt appears to be “wormable,” which, Tom’s Guide explains, means it spreads “from system to system by itself as a computer worm, rather than relying on human interaction as a Trojan horse, or infecting desktop applications like a traditional computer virus.”


Since most antivirus software protects and updates in real time, even if the worm breaks through your defenses, RT points out, “chances are good that within a short while an automatic antivirus update will clear the intruder from your system. Most antivirus companies offer trial versions free of charge to test before subscribing for a paid service, which should be enough if one needs to urgently remove a stray malware.”


Forbes reports, “If you have up-to-date malware protection software from a reputable cybersecurity company such as Avast installed on your computer, you are probably protected.  Check your cybersecurity company’s website to make sure you are. WanaCry is a world-wide, runaway threat. If your cybersecurity company’s website has nothing to say about it, don’t assume you are protected. Make sure you are running the current version of Windows.”


5. Keep your money


Perhaps the most basic instruction most analysts and security pros emphasize is also difficult for many to swallow. Don’t shell out the money they’re demanding — be it Bitcoin, dollars, gold, or any other iteration.


Of course, those holding your files hostage for money hope to exploit you in two insidious ways — first, by locking down your data, but second, through your emotional panic resultant from having your critical files abruptly unavailable. That alarm pumps you full of adrenaline, and could provoke a response which seems the simplest solution in the moment — forking over the funds.


If you do that, cybersecurity analysts say, no guarantee exists you’ll actually get your data back — and your willingness to do so could make you a target for future exploits — which, again, could be coming around anytime.


***


Considering the scope of the documents leaked by the Shadow Brokers, virtually anything could be possible now. This basic list will only help to an extent, and should not be considered comprehensive — nor should it be considered, of course, expert advice.


That said, the precautions offered are a bit better than leaving your system naked to malicious infection.



That “accidental hero” credited with truncating the worm’s virulent proliferation admonished the public to be wary and alert, because — although altered or ‘improved’ iterations of WanaCrypt have yet to appear online — “they will.”


“This is not over,” he told the Guardian. “The attackers will realise how we stopped it, they’ll change the code and then they’ll start again. Enable Windows update, update and then reboot.”

24 Hrs Later: What You Need to Know About the ‘Biggest Ransomware Attack in History’

(ZHE) 24 hours after it first emerged, it has been called the first global, coordinated ransomware attack using hacking tools developed by the NSA, crippling over a dozen hospitals across the UK, mass transit around Europe, car factories in France and the UK, universities in China, corporations in the US, banks in Russia and countless other mission-critical businesses and infrastructure.





According to experts, “this could be one of the worst-ever recorded attacks of its kind.” The security researcher who tweets and blogs as MalwareTech told The Intercept, “I’ve never seen anything like this with ransomware,” and “the last worm of this degree I can remember is Conficker.” Conficker was a notorious Windows worm first spotted in 2008; it went on to infect over 9 million computers in nearly 200 countries.



The fallout, according to cyber-specialists, has been “unprecedented”: it has left unprepared governments, companies and security experts from China to the United Kingdom on Saturday reeling, and racing to contain the damage from the audacious cyberattack that spread quickly across the globe, raising fears that people would not be able to meet ransom demands before their data are destroyed.







As reported yesterday, the global efforts come less than a day after malicious software, transmitted via email and stolen from the National Security Agency, exposed vulnerabilities in computer systems in almost 100 countries in one of the largest “ransomware” attacks on record. The cyberattackers took over the computers, encrypted the information on them and then demanded payment of $300 or more from users in the form of bitcoin to unlock the devices.


The ransomware was subsequently identified as a new variant of “WannaCry” that had the ability to automatically spread across large networks by exploiting a known bug in Microsoft’s Windows operating system.


ransomware nsa







The hackers, who have not come forward to claim responsibility or otherwise been identified, likely made it a “worm”, or self spreading malware, by exploiting a piece of NSA code known as “Eternal Blue” that was released last month by a group known as the Shadow Brokers (see “Hacker Group Releases Password To NSA’s “Top Secret Arsenal” In Protest Of Trump Betrayal“) , researchers with several private cyber security firms said.


“This is one of the largest global ransomware attacks the cyber community has ever seen,” said Rich Barger, director of threat research with Splunk. The extremely well coordinated attack first emerged in the United Kingdom around noon on Friday and spread like wildefire around the globe. According to the Times “it has set off fears that the effects of the continuing threat will be felt for months, if not years” and raised questions about the intentions of the hackers: Did they carry out the attack for mere financial gain or for other unknown reasons?


The animated map below shows the speed and scale of the global infestation which took just a few hours to cover the globe:



Meanwhile, some of the world’s largest institutions and government agencies have been affected, including the Russian Interior Ministry, FedEx in the United States and Britain’s National Health Service. As people fretted over whether to pay the digital ransom or lose data from their computers, experts said the attackers might pocket more than $1 billion worldwide before the deadline ran out to unlock the machines.


Across Asia, several universities and organizations said they had been affected. In China, the virus hit the computer networks of both companies and universities, according to the state-run news media. News about the attack began trending on Chinese social media on Saturday, though most attention was focused on university networks, where there were concerns about students losing access to their academic work. The attack, however, focused on the UK and Europe where in addition to the British healthcare system, companies like Deutsche Bahn, the German transport giant; Telefónica, a Spanish telecommunications firm; and Renault, the French automaker, said some of their systems had been affected.


“Seeing a large telco like Telefonica get hit is going to get everybody worried,” said Chris Wysopal, chief technology officer with cyber security firm Veracode.


The British National Health Service said that 45 of its hospitals, doctors’ offices and ambulance companies had been crippled — making it perhaps one of the largest institutions affected worldwide. Surgical procedures were canceled and some hospital operations shut down as government officials struggled to respond to the attack.


“We are not able to tell you who is behind that attack,” Amber Rudd, Britain’s home secretary, told the British Broadcasting Corporation on Saturday. “That work is still ongoing.”


Things only got worse on Saturday as auto production facilities across Europe have been shuttered, including car plants in the UK and France, in the aftermath of the cyberattack.








In total, more than 75,000 computers in 99 countries were compromised in Friday’s attack, with a heavy concentration of infections in Russia and Ukraine, according to Dutch security company Avast Software BV. Russia’s Interior Ministry, with oversees the country’s police forces, said “around 1,000 computers were infected,” which it described as less than 1 percent of the total, the New York Times reported. The ministry said technicians had stopped the attack and were updating the department’s “antivirus defense systems,” according to the Times. Russia’s RIA reported that the central bank said on Saturday it had detected “massive” cyber attacks on domestic banks, which successfully thwarted them.


* * *


There has been some good news: an ingenious discovery appears to have halted the spread of the virus for now.


As part of the digital attack, the hackers included a way of disabling the malware in case they wanted to shut down their activities, Ars Technica reported. To do so, the assailants included code in the ransomware that would stop it from spreading if the virus sent an online request to a website created by the attackers. The kill switch would stop the malware from spreading as soon as the website went online and communicated with the spreading digital virus.


A British-based researcher, who declined to give his name, registered a domain that he noticed the malware was trying to connect to, limiting the worm’s spread. When the 22-year-old British researcher, whose Twitter handle is @MalwareTechBlog, confirmed his involvement but insisted on anonymity because he did not want the public scrutiny, saw that the kill switch’s domain name — a long and complicated set of letters — had yet to be registered, he bought it himself. By making the site go live, the researcher shut down the hacking attack before it could fully spread to the United States.


However, this temporary workaround will only last for a few days if not hours.


“I will confess that I was unaware registering the domain would stop the malware until after I registered it, so initially it was accidental,” wrote the @MalwareTechBlog researcher. “So long as the domain isn’t revoked, this particular strain will no longer cause harm, but patch your systems ASAP as they will try again.






“The kill switch is why the U.S. hasn’t been touched so far,” said Matthieu Suiche, founder of Comae Technologies, a cybersecurity company in the United Arab Emirates. “But it’s only temporary. All the attackers would have to do is create a variant of the hack with a different domain name. I would expect them to do that.”


Adds Reuters: “We are on a downward slope, the infections are extremely few, because the malware is not able to connect to the registered domain,” said Vikram Thakur, principal research manager at Symantec.


“The numbers are extremely low and coming down fast.” But the attackers may yet tweak the code and restart the cycle. The British-based researcher who may have foiled the ransomware’s spread told Reuters he had not seen any such tweaks yet, “but they will.”


* * *


Meanwhile, questions are mounting why code created by the NSA. has i) fallen in the wrong hands and ii) is being used to hold the world hostage. As the NYT notes, the ability of the cyberattack to spread so quickly was partly because of its high level of sophistication.


The malware, experts said, was based on a method that the N.S.A. is believed to have developed as part of its arsenal of cyberweapons. Last summer, a group calling itself the “Shadow Brokers” posted online digital tools that it had stolen from the United States government’s stockpile of hacking weapons.  The connection to the N.S.A. is likely to draw further criticism from privacy advocates who have repeatedly called for a clampdown on how the agency collects information online.


Brian Lord, a former deputy director for intelligence and cyber operations at Government Communications Headquarters, Britain’s equivalent to the N.S.A., said that any investigation, which would include the F.B.I. and the National Crime Agency of Britain, would take months to name the potential attackers, if it ever does. And by focusing the attacks on large institutions with a track record of not keeping their technology systems up-to-date, global criminal organizations were cherry-picking easy targets that were highly susceptible to such hacks, according to Mr. Lord.


“Serious organized crime is looking to these new technologies to the maximum effect,” Mr. Lord said. “With cybercrime, you can operate globally without leaving where you already are.”<


He added of this attack: “It was well thought-out, well timed and well coordinated. But, fundamentally, there is nothing unusual about its delivery. It is still fundamentally robbery and extortion.”


For now, the victims – both actual and potential – may have bought themselves some time. As part of the efforts to combat the attack, Microsoft, whose Windows software lies at the heart of the potential hacking vulnerability, released a software update available to those affected by the attack and others who could be potential targets. Microsoft took the “highly unusual” step of securing early operating systems in the wake of a massive ransomware attack that wreaked havoc on global computer networks, including the UK’s National Health Service. Overnight, Microsoft XP received the new security patch three years after the computer giant discontinued support for the OS.


“Seeing businesses and individuals affected by cyberattacks, such as the ones reported today [Friday], was painful,” a Microsoft statement read. “We are taking the highly unusual step of providing a security update for all customers to protect Windows platforms that are in custom support only, including Windows XP, Windows 8, and Windows Server 2003.”


Security experts however said the upgrade came too late for many of the tens of thousands of machines that were locked out and whose data could be erased if people did not pay the ransom. Earlier this year, Microsoft created a patch called MS17-010 to guard against the virus. But older, unsupported operating systems were not included in the update.


Making matters worse, government officials and industry watchers also warned on Saturday that other hackers might now try to use the global ransomware attack for their own means, potentially tweaking the code and developing their own targets for new cyberattacks.


* * *


Finally, there is the question who is behind this coordinated global attack. Not surprisingly, Russia has been named. There is a high-probability that Russian-language cyber-criminals were behind the attack, said Aleks Gostev, chief cybersecurity expert for Kaspersky Labs. “Ransomware is traditionally their topic,” he said cited by Bloomberg. “The geography of attacks that hit post-Soviet Union most also suggests that.”


Whoever is the responsible party behind this first, global, coordinated ransomware attack, the have demonstrated one thing: the world is thoroughly unprepared for cyberwar.


“As with everything in cyber, we’re now waiting for the next type of attack,” Paul Bantick, a cyber security expert at Beazley, a global insurance underwriter, told the NYT.


“Ransomware like this has been on the rise over the last 18 months,” he added. “This represents the next step that people were expecting.”


As such, it is only a matter of time now before an even greater, more destructive cyberattack is unleashed on the world.


By Tyler Durden / Republished with permission / Zero Hedge / Report a typo






"Massive Disturbances" In German Rail System Due To Ransomware Attack

Germany"s WAZ reports massive disturbances in local and long-distance rail traffic on Friday evening due to what appears to be the same ransomware attack that is spreading across the globe.


Numerous social media accounts are showing the following images...



More details to follow...


Local reports say that the situation in Germany is getting chaotic.


Friday, May 12, 2017

Ransomware Virus Cripples Hospital Computers; Operations Cancelled; Emergency Rooms Closed

Ransomware Virus Cripples Hospital Computers; Operations Cancelled; Emergency Rooms Closes


Hospitals, clinics and ambulance services across the United Kingdom were disrupted by one the largest ransomware attacks in history Friday.


At least 16 hospitals operated by the National Health Service (NHS) in England were affected by the attack, which impacted tens of thousands of computers across the globe, including FedEx’s computers in the U.S., The Independent reported.


Operations were cancelled and ambulances were turned away from the emergency room at one London hospital, CNN reported. Barts Health NHS Trust in London reported “experiencing a major IT disruption and there are delays at all of our hospitals.”


The ransomware apparently took over the switchboards and shut down the phone system.


Are You Prepared For A Cyberattack? Get Backup Electricity Today!


“We are aware of a major IT secure system attack,” an NHS trust in Derbyshire tweeted. “All IT systems have been temporarily shut down. More information will be available shortly.”


The ransomware, identified as the Wanna Decryptor, asked hospital personnel for 300 bitcoins to get access to their computers, The Independent reported. Since a bitcoin was trading for $1,760.99 on May 12, the ransomware bandits were demanding $528,297 for access.


But Wanna Decryptor is spreading far beyond the UK, The Independent reported.


“This cyberattack is much larger than just the NHS,” Travis Farral, director of security strategy for the cybersecurity firm Anomali Labs, told the newspaper. “It appears to be a giant campaign that has hit Spain and Russia the hardest.”


What is your reaction? Share it in the section below:  

Global ransomware attacks 74 nations

Update 2: Security firm Kaspersky Lab has recorded more than 45,000 attacks in 74 countries in the past 10 hours. Most of the attacks have targeted Russia.


*  *  *


Update 1: In a shocking revelation, The FT reports that hackers responsible for the wave of cyber attacks that struck organisations across the globe used tools stolen from the US National Security Agency.


A hacking tool known as “eternal blue”, developed by US spies has been weaponised by the hackers to super-charge an existing form of ransomware known as WannaCry, three senior cyber security analysts said. Their reading of events was confirmed by western security officials who are still scrambling to contain the spread of the attack. The NSA’s eternal blue exploit allows the malware to spread through file-sharing protocols set up across organisations, many of which span the globe.




*  *  *


We earlier reported in the disturbing fact that hospitals across the United Kingdom had gone dark due to a massive cyber-attack…



Hospitals across the UK have been hit by what appears to be a major, nationwide cyber-attack, resulting in the loss of phonelines and computers, with many hospitals going “dark” and some diverting all but emergency patients elsewhere. At some hospitals patients are being told not to come to A&E with all non-urgent operations cancelled, the BBC reports.


The UK National Health Service said: “We’re aware that a number of trusts that have reported potential issues to the CareCERT team. We believe it to be ransomware.” It added that trusts and hospitals in London, Blackburn, Nottingham, Cumbria and Hertfordshire have been affected and are reporting IT failures, in some cases meaning there is no way of operating phones or computers.


At Lister Hospital in Stevenage, the telephone and computer system has been fully disabled in an attempt to fend off the attack.


NHS England says it is aware of the issue and is looking into it.



UK Prime Minister Theresa May confirms today’s massive cyber hit on NHS is part of wider international attack and there is no evidence patient data has been compromised.




The situation has got significantly worse as The BBC reports the ransomware attack has gone global.


Screenshots of a well known program that locks computers and demands a payment in Bitcoin have been shared online by parties claiming to be affected.



It is not yet clear whether the attacks are all connected. One cyber-security researcher tweeted that he had detected 36,000 instances of the ransomware, called WannaCry and variants of that name.



“This is huge,” he said.



There have been reports of infections in the UK, US, China, Russia, Spain, Italy, Vietnam, Taiwan and others.


The BBB details a number of Spanish firms were among the apparent victims elsewhere in Europe.



Telecoms giant Telefonica said in a statement that it was aware of a “cybersecurity incident” but that clients and services had not been affected.


Power firm Iberdrola and utility provider Gas Natural were also reported to have suffered from the outbreak.


There were reports that staff at the firms were told to turn off their computers.



In Italy, one user shared images appearing to show a university computer lab with machines locked by the same program.



itcoin wallets seemingly associated with the ransomware were reported to have already started filling up with cash.



“This is a major cyber attack, impacting organisations across Europe at a scale I’ve never seen before,” said security architect Kevin Beaumont.



According to security firm Check Point, the version of the ransomware that appeared today is a new variant.



“Even so, it’s spreading fast,” said Aatish Pattni, head of threat prevention for northern Europe.



Several experts monitoring the situation have linked the attacks to vulnerabilities released by a group known as The Shadow Brokers, which recently claimed to have dumped hacking tools stolen from the NSA.


Via Zero Hedge


Featured Image: Sarah/Flicker