{"id":33416,"date":"2017-06-30T07:21:52","date_gmt":"2017-06-30T07:21:52","guid":{"rendered":"http:\/\/www.biphoo.com\/bipnews\/?p=33416"},"modified":"2017-06-30T07:21:52","modified_gmt":"2017-06-30T07:21:52","slug":"cyberattack-hits-ukraine-then-spreads-internationally","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/cyberattack-hits-ukraine-then-spreads-internationally.html","title":{"rendered":"Cyberattack Hits Ukraine Then Spreads Internationally"},"content":{"rendered":"<h2 style=\"text-align: justify\"><span style=\"font-size: 18pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Cyberattack Hits Ukraine Then Spreads Internationally<\/span><\/strong><\/span><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Computer systems from Ukraine to the United States were struck on Tuesday in an international cyberattack that was similar to a recent assault that crippled tens of thousands of machines worldwide.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In Kiev, the capital of Ukraine, A.T.M.s stopped working. About 80 miles away, workers were forced to manually monitor radiation at the old Chernobyl nuclear plant when their computers failed. And tech managers at companies around the world \u2014 from Maersk, the Danish shipping conglomerate, to Merck, the drug giant in the United States \u2014 were scrambling to respond. Even an Australian factory for the chocolate giant Cadbury was affected.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">It was unclear who was behind this cyberattack, and the extent of its impact was still hard to gauge Tuesday. It started as an attack on Ukrainian government and business computer systems \u2014 an assault that appeared to have been intended to hit the day before a holiday marking the adoption in 1996 of Ukraine\u2019s first Constitution after its break from the Soviet Union. The attack spread from there, causing collateral damage around the world.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The outbreak was the latest and perhaps the most sophisticated in a series of attacks making use of dozens of hacking tools that were stolen from the National Security Agency and leaked online in April by a group called the Shadow Brokers.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Like the WannaCry attacks in May, the latest global hacking took control of computers and demanded digital ransom from their owners to regain access. The new attack used the same National Security Agency hacking tool, Eternal Blue, that was used in the WannaCry episode, as well as two other methods to promote its spread, according to researchers at the computer security company Symantec.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The National Security Agency has not acknowledged its tools were used in WannaCry or other attacks. But computer security specialists are demanding that the agency help the rest of the world defend against the weapons it created.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cThe N.S.A. needs to take a leadership role in working closely with security and operating system platform vendors such as Apple and Microsoft to address the plague that they\u2019ve unleashed,\u201d said Golan Ben-Oni, the global chief information officer at IDT, a Newark-based conglomerate hit by a separate attack in April that used the agency\u2019s hacking tools. Mr. Ben-Oni warned federal officials that more serious attacks were probably on the horizon.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The vulnerability in Windows software used by Eternal Blue was patched by Microsoft in March, but as the WannaCry attacks demonstrated, hundreds of thousands of groups around the world failed to properly install the fix.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cJust because you roll out a patch doesn\u2019t mean it\u2019ll be put in place quickly,\u201d said Carl Herberger, vice president for security at Radware. \u201cThe more bureaucratic an organization is, the higher chance it won\u2019t have updated its software.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Because the ransomware used at least two other ways to spread on Tuesday \u2014 including stealing victims\u2019 credentials \u2014 even those who used the Microsoft patch could be vulnerable and potential targets for later attacks, according to researchers at F-Secure, a Finnish cybersecurity firm, and others.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">A Microsoft spokesman said the company\u2019s latest antivirus software should protect against the attack.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The Ukrainian government said several of its ministries, local banks and metro systems had been affected. A number of other European companies, including Rosneft, the Russian energy giant; Saint-Gobain, the French construction materials company; and WPP, the British advertising agency, also said they had been targeted.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Ukrainian officials pointed a finger at Russia on Tuesday, although Russian companies were also affected. Home Credit bank, one of Russia\u2019s top 50 lenders, was paralyzed, with all of its offices closed, according to the RBC news website. The attack also affected Evraz, a steel manufacturing and mining company that employs about 80,000 people, the RBC website reported.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In the United States, the multinational law firm DLA Piper also reported being hit. Hospitals in Pennsylvania were being forced to cancel operations after the attack hit computers at Heritage Valley Health Systems, a Pennsylvania health care provider, and its hospitals in Beaver and Sewickley, Penn., and satellite locations across the state.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The ransomware also hurt Australian branches of international companies. DLA Piper\u2019s Australian offices warned clients that they were dealing with a \u201cserious global cyber incident\u201d and had disabled email as a precautionary measure. Local news reports said that in Hobart, Tasmania, on Tuesday evening, computers in a Cadbury chocolate factory, owned by Mondelez International, had displayed ransomware messages that demanded $300 in bitcoins.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Qantas Airways\u2019 booking system failed for a time on Tuesday, but the company said the breakdown was due to an unrelated hardware issue.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The Australian government has urged companies to install security updates and isolate any infected computers from their networks.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cThis ransomware attack is a wake-up call to all Australian businesses to regularly back up their data and install the latest security patches,\u201d said Dan Tehan, the cybersecurity minister. \u201cWe are aware of the situation and monitoring it closely.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">A National Security Agency spokesman referred questions about the attack to the Department of Homeland Security. \u201cThe Department of Homeland Security is monitoring reports of cyberattacks affecting multiple global entities and is coordinating with our international and domestic cyber partners,\u201d Scott McConnell, a department spokesman, said in a statement.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Computer specialists said the ransomware was very similar to a virus that emerged last year called Petya. Petya means \u201cLittle Peter,\u201d in Russian, leading some to speculate the name referred to Sergei Prokofiev\u2019s 1936 symphony \u201cPeter and the Wolf,\u201d about a boy who captures a wolf.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Reports that the computer virus was a variant of Petya suggest the attackers will be hard to trace. Petya was for sale on the so-called dark web, where its creators made the ransomware available as \u201cransomware as a service\u201d \u2014 a play on Silicon Valley terminology for delivering software over the internet, according to the security firm Avast Threat Labs.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">That means anyone could launch the ransomware with the click of a button, encrypt someone\u2019s systems and demand a ransom to unlock it. If the victim pays, the authors of the Petya ransomware, who call themselves Janus Cybercrime Solutions, get a cut of the payment.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">That distribution method means that pinning down the people responsible for Tuesday\u2019s attack could be difficult.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">A screenshot of what appeared to be the ransomware affecting systems worldwide on Tuesday. The Ukrainian government posted the shot to its official Facebook page.<\/span><br \/>\n<span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The attack is \u201can improved and more lethal version of WannaCry,\u201d said Matthieu Suiche, a security researcher who helped contain the spread of the WannaCry ransomware when he created a kill switch that stopped the attacks.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In just the last seven days, Mr. Suiche noted, WannaCry had tried to hit an additional 80,000 organizations but was prevented from executing attack code because of the kill switch. Petya does not have a kill switch.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Petya also encrypts and locks entire hard drives, whereas the earlier ransomware attacks locked only individual files, said Chris Hinkley, a researcher at the security firm Armor.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The hackers behind Petya demanded $300 worth of the cybercurrency Bitcoin to unlock victims\u2019 machines. By Tuesday afternoon, online records showed that 30 victims had paid the ransom, although it was not clear whether they had regained access to their files. Other victims may be out of luck, after Posteo, the German email service provider, shut down the hackers\u2019 email account.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In Ukraine, people turned up at post offices, A.T.M.s and airports to find blank computer screens, or signs about closures. At Kiev\u2019s central post office, a few bewildered customers milled about, holding parcels and letters, looking at a sign that said, \u201cClosed for technical reasons.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The hackers compromised Ukrainian accounting software mandated to be used in various industries in the country, including government agencies and banks, according to researchers at Cisco Talos, the security division of the computer networking company. That allowed them to unleash their ransomware when the software, which is also used in other countries, was updated.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The ransomware spread for five days across Ukraine, and around the world, before activating Tuesday evening.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cIf I had to guess, I would think this was done to send a political message,\u201d said Craig Williams, the senior technical researcher at Talos.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">One Kiev resident, Tetiana Vasylieva, was forced to borrow money from a relative after failing to withdraw money at four automated teller machines. At one A.T.M. in Kiev belonging to the Ukrainian branch of the Austrian bank Raiffeisen, a message on the screen said the machine was not functioning.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Ukraine\u2019s Infrastructure Ministry, the postal service, the national railway company, and one of the country\u2019s largest communications companies, Ukrtelecom, had been affected, Volodymyr Omelyan, the country\u2019s infrastructure minister, said in a Facebook post.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Officials for the metro system in Kiev said card payments could not be accepted. The national power grid company Kievenergo had to switch off all of its computers, but the situation was under control, according to the Interfax-Ukraine news agency. Metro Group, a German company that runs wholesale food stores, said its operations in Ukraine had been affected.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">At the Chernobyl plant, the computers affected by the attack collected data on radiation levels and were not connected to industrial systems at the site, where, although all reactors have been decommissioned, huge volumes of radioactive waste remain. Operators said radiation monitoring was being done manually.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Cybersecurity researchers questioned whether collecting ransom was the true objective of the attack.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cIt\u2019s entirely possible that this attack could have been a smoke screen,\u201d said Justin Harvey, the managing director of global incident response at Accenture Security. \u201cIf you are an evildoer and you wanted to cause mayhem, why wouldn\u2019t you try to first mask it as something else?\u201d<\/span><\/p>\n<p><span style=\"font-size: 8pt\">Source:-\u00a0https:\/\/www.nytimes.com\/2017\/06\/27\/technology\/ransomware-hackers.html<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/cyberattack-hits-ukraine-then-spreads-internationally.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>Cyberattack Hits Ukraine Then Spreads Internationally Computer systems from Ukraine to the United States were struck on Tuesday in an international cyberattack that was similar to a recent assault that crippled tens of thousands of machines worldwide. In Kiev, the capital of Ukraine, A.T.M.s stopped working. About 80 miles away, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":33418,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[20608,20607,20605,20606],"class_list":["post-33416","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-cyber-attack-on-ukraine-power-grid","tag-cyber-attack-ukraine","tag-cyber-attack-ukraine-power-grid","tag-cyber-attack-ukraine-power-plant"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/33416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=33416"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/33416\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/33418"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=33416"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=33416"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=33416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}