SMOKESCREENUkraines cyber police said in a statement on Thursday morning that it had received 1,500 requests for help from individuals and .John Hultquist, a cyber intelligence analyst with FireEye, said the failed ransomware attack disguises an as yet unseen destructive motive.Ukrainian politicians were quick on Tuesday to blame Russia, but a Kremlin spokesman dismissed "unfounded blanket accusations"."Petya is proving to be more sophisticated than WannaCry in terms of scope, ability to be neutralized, and apparently, the motivation behind its launch," corporate security consulting firm Kroll has advised its clients."Since the virus was modified to encrypt all data and make decryption impossible, the likelihood of it being done to install new malware is high," the official, who declined to https://www.reducerfactory.net/product/swl-series-screw-lifter/ be identified, wrote in a phone text message to Reuters.Cyber security firms are trying to piece together who was behind the computer worm, dubbed NotPetya by some experts, which has paralyzed thousands of machines worldwide, shutting down ports, factories and offices as it spread through internal organizational networks to an estimated 60 countries."Its highly likely that during this attack new attacks were set up," said ISSP chairman Oleg Derevianko. "Why didnt they all go offline? We are trying to understand what they might have left on those machines that werent hit. companies in connection with the virus.So far, NotPetya appears only to have been distributed inside Ukraine via a handful of so-called "watering-hole attacks" - by piggy-backing on the software updating feature of a popular national tax accounting program known as MEDoc.International firms appear to have been hit through their operations in the country.A top Ukrainian police official told Reuters that the extortion demands were likely a smokescreen, echoing working hypotheses from top cyber security firms, who consider NotPetya a "wiper", or tool for destroying data and wiping hard disks clean, that is disguised as ransomware.Some cyber security researchers have said the fact that the Kremlins two flagship energy companies are victims of the attack could suggest Moscow was not behind it.By contrast, NotPetya does not randomly scan the Internet to find new computers to infect.DESTRUCTIVE INTENTTechnical experts familiar with the recent history of the cyber escalation between Russia and Ukraine, say these latest attacks are part of the wider political and military conflict, although no "smoking gun" has been found to identify the culprits. "If it were an attack masquerading as crime, that would not be unprecedented at all," Hultquist said. It only spreads itself inside organizational networks, taking advantage of a variety of legitimate network administration tools.reducerfactory."NotPetya .ISSP said that given that few people actually paid the $300 demanded for removing the virus, money was unlikely to be the primary object of the attack.For technical reasons, NotPetya appears to be more targeted than last months global ransomware attack, known as WannaCry.The malicious code in the new virus encrypted data on computers and demanded victims pay a $300 ransom, similar to the extortion tactic used in a global WannaCry ransomware attack in May.The primary target of a crippling computer virus that spread from Ukraine across the world this week is highly likely to have been that countrys computer infrastructure, a top Ukrainian police official told Reuters on Thursday.This makes it far harder for anti-virus software or network security technicians to detect."In all of the known cases, the companies were first infected through a Ukrainian subsidiary," the German official said.Information Systems Security Partners (ISSP), a Kiev-based cyber research firm that has investigated previous cyber attacks against Ukraine, is pursuing the same line of inquiry.Kaspersky, a global cyber security firm based in Russia, also said they found a second distribution point on a local news site in the city of Bakhmut, Ukraine, which infected visitors who clicked on the site with the ransomware-like attack."Ukraines National Security and Defence Council Secretary Oleksandr Turchynov said the virus was first and foremost spread through an update issued by an accounting services and business management software.A growing consensus among security researchers, armed with technical evidence, suggests the main purpose of the attack was to install new malware on computers at government and commercial organizations in Ukraine. It also gives it the capacity to infect other Windows computers, even those with the latest security patches, several security firms warned on Thursday.Russian oil major Rosneft was one of the first companies to reveal it had been compromised by the virus and sources told Reuters on Thursday computers at state gas giant Gazprom had also been infected.Arne Schoenbohm, president of BSI, Germanys federal cyber security agency, told Reuters in an interview on Thursday that most of the damage from the attack had hit Ukraine, and Russia to a lesser extent, with only a few dozen German firms affected.."Our analysis indicates the main purpose of the attack was not financial gain, but widespread destruction," said Costin Raiu, Kaspersky’s global head of research. Rather than extortion, the goal may be to plant the seeds of future sabotage, experts said. Kiev has accused Moscow of two previous cyber strikes on the Ukrainian power grid and other attacks since Russia annexed Crimea in 2014. "At almost all organizations whose network domains were infected, not all computers went offline," he said by phone.combined elements of a targeted watering hole attack we’ve traditionally seen used by nation states with traditional software exploitation to devastate a specific user base," Lesley Carhart, a Chicago-based security researcher, wrote in a blog widely shared online by top security experts..Slovakian security software firm ESET released statistics on Thursday showing 75 percent of the infections detected among its global customer base were in Ukraine, and that all of the top 10 countries hit were located in central, eastern or southern Europe."Also involved was the hosting service of an internet provider, which the SBU (Ukraines state security service) has already questioned about cooperation with Russian intelligence agencies," he said, according to a statement. When first infected by WannaCry, computers scanned the internet globally for other vulnerable machines

コメント

最新の日記 一覧

<<  2025年7月  >>
293012345
6789101112
13141516171819
20212223242526
272829303112

お気に入り日記の更新

テーマ別日記一覧

まだテーマがありません

日記内を検索