{"id":48644,"date":"2017-10-25T06:22:28","date_gmt":"2017-10-25T06:22:28","guid":{"rendered":"https:\/\/www.biphoo.com\/bipnews\/?p=48644"},"modified":"2017-10-25T06:22:28","modified_gmt":"2017-10-25T06:22:28","slug":"new-ransomware-attack-hits-russia-and-spreads-around-globe","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/new-ransomware-attack-hits-russia-and-spreads-around-globe.html","title":{"rendered":"New ransomware attack hits Russia and spreads around globe"},"content":{"rendered":"<h2 style=\"text-align: justify\"><span style=\"font-size: 18pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">New ransomware attack hits Russia and spreads around globe<\/span><\/strong><\/span><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">New ransomware attack hits Russia and spreads around globe:- The U.S. government has issued a warning about a new ransomware attack that spread through Russia and Ukraine and into other countries around the world.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Cybersecurity experts said the ransomware &#8212; which posed as an Adobe update before locking down computers and demanding money for people to get their files back &#8212; targeted Russian media companies and Ukrainian transportation systems. It has also been detected in other countries including the U.S., Germany, Japan, Turkey and Bulgaria.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">The U.S. Computer Emergency Readiness Team said late Tuesday it &#8220;has received multiple reports of ransomware infections &#8230; in many countries around the world.&#8221;<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Dubbed &#8220;Bad Rabbit,&#8221; the virus is the latest example of cybercriminals using ransomware to try to extort money from victims across the globe. Two major international attacks earlier this year &#8212; NotPetya and Wannacry &#8212; caused widespread disruption affecting businesses, government institutions and hospitals.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">When Bad Rabbit infects a computer, it seizes files and demands a ransom. Experts and government agencies advise victims not to pay up, warning that there&#8217;s no guarantee they will get their files back.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">On Tuesday, the virus attacked Russian media groups Interfax and Fontanka, and transportation targets in Ukraine including Odessa&#8217;s airport, Kiev&#8217;s subway and the country&#8217;s Ministry of Infrastructure of Ukraine, according to Russian cybersecurity firm Group-IB. Interfax confirmed its servers had gone down due to a cyberattack.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Most of the victims were located in Russia, but attacks were also observed in Ukraine, Turkey, and Germany. Cybersecurity firm ESET also identified cases of Bad Rabbit in Japan and Bulgaria. Avast says the ransomware has been detected in the U.S.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Ties to previous attack<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">The number of victims appeared to be significantly smaller than the NotPetya attack, which struck Ukraine and spread to other countries in June, doing hundreds of millions of dollars of damage to some major companies.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Experts said there were clear links between the two viruses.<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Vyacheslav Zakorzhevsky, head of the anti-malware research team at Russian cybersecurity firm Kaspersky Lab, said the company&#8217;s investigation shows the Bad Rabbit attack targeted corporate networks using similar methods as NotPetya.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Costin Raiu, director of the Global Research and Analysis Team at Kaspersky Lab, said in a message the Bad Rabbit attack was launched through &#8220;an elaborate network of hacked websites,&#8221; with a link to NotPetya.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Group-IB also identified similarities between the NotPetya code and that of Bad Rabbit.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Virus used popular malware trick<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">The Bad Rabbit ransomware infiltrated computers by posing as an Adobe Flash installer on compromised news and media websites. It serves as a reminder that people should never download apps or software from pop-up advertisements or websites that don&#8217;t belong to the software company.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">ESET says once the ransomware infected a machine, it scanned the network for shared folders with common names and attempted to steal and exploit user credentials to get on other computers.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Researchers say Bad Rabbit doesn&#8217;t use EternalBlue, the Windows exploit that was leaked in a batch of hacking tools believed to belong to the U.S. National Security Agency. The NotPetya and WannaCry ransomware attacks did use EternalBlue.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">It&#8217;s unclear who&#8217;s behind Bad Rabbit, but the attackers appear to be &#8220;Game of Thrones&#8221; fans. The ransomware code contains references to characters from the popular book and TV series like Grey Worm and Daenerys&#8217; dragons.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Many anti-virus software detects Bad Rabbit, including Windows Defender. A researcher from Cybereason discovered a &#8220;vaccine&#8221; that the company said can protect machines from infection.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">According to malware researcher James Emery-Callcott, the ransomware campaign is slowly dying down.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">&#8220;As far as I can see, the attacker&#8217;s server is no longer live and most of the infected sites hosting the script that gives the Flash update prompt&#8221; have fixed the issue, he said. &#8220;Fake Flash updates are an incredibly popular method of distributing malware these days. Hopefully people will start to realize that when you get an unsolicited Flash update, it&#8217;s generally going to be bad.&#8221;<\/span><\/p>\n<p><span style=\"font-size: 8pt;font-family: Arial, Helvetica, sans-serif\">Source:-\u00a0http:\/\/money.cnn.com\/2017\/10\/24\/technology\/bad-rabbit-ransomware-attack\/index.html<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/new-ransomware-attack-hits-russia-and-spreads-around-globe.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>New ransomware attack hits Russia and spreads around globe New ransomware attack hits Russia and spreads around globe:- The U.S. government has issued a warning about a new ransomware attack that spread through Russia and Ukraine and into other countries around the world. Cybersecurity experts said the ransomware &#8212; which [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":48647,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[974,13],"tags":[83720,83718,83719,83725,83723,83724,83721],"class_list":["post-48644","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-technology","tag-cybersecurity-experts","tag-new-ransomware-attack","tag-russia-and-ukraine","tag-russian-cybersecurity-firm","tag-russian-media-companies","tag-u-s-computer-emergency-readiness-team","tag-ukrainian-transportation-systems"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/48644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=48644"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/48644\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/48647"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=48644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=48644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=48644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}