Cyberattack Hits Ukraine Then Spreads Internationally – The …
Like the WannaCry attacks in May, the latest global hacking took control of computers and demanded digital ransom from their owners to regain access. The new attack used the same National Security Agency hacking tool, Eternal Blue, that was used in the WannaCry episode, as well as two other methods to promote its spread, according to researchers at the computer security company Symantec.
The National Security Agency has not acknowledged its tools were used in WannaCry or other attacks. But computer security specialists are demanding that the agency help the rest of the world defend against the weapons it created.
The N.S.A. needs to take a leadership role in working closely with security and operating system platform vendors such as Apple and Microsoft to address the plague that theyve unleashed, said Golan Ben-Oni, the global chief information officer at IDT, a Newark-based conglomerate hit by a separate attack in April that used the agencys hacking tools. Mr. Ben-Oni warned federal officials that more serious attacks were probably on the horizon.
The vulnerability in Windows software used by Eternal Blue was patched by Microsoft in March, but as the WannaCry attacks demonstrated, hundreds of thousands of groups around the world failed to properly install the fix.
Just because you roll out a patch doesnt mean itll be put in place quickly, said Carl Herberger, vice president for security at Radware. The more bureaucratic an organization is, the higher chance it wont have updated its software.
Because the ransomware used at least two other ways to spread on Tuesday including stealing victims credentials even those who used the Microsoft patch could be vulnerable and potential targets for later attacks, according to researchers at F-Secure, a Finnish cybersecurity firm, and others.
A Microsoft spokesman said the companys latest antivirus software should protect against the attack.
Governments and companies in Europe and the United States have been impacted. Here are several:
The Ukrainian government said several of its ministries, local banks and metro systems had been affected. A number of other European companies, including Rosneft, the Russian energy giant; Saint-Gobain, the French construction materials company; and WPP, the British advertising agency, also said they had been targeted.
Ukrainian officials pointed a finger at Russia on Tuesday, although Russian companies were also affected. Home Credit bank, one of Russias top 50 lenders, was paralyzed, with all of its offices closed, according to the RBC news website. The attack also affected Evraz, a steel manufacturing and mining company that employs about 80,000 people, the RBC website reported.
In the United States, the multinational law firm DLA Piper also reported being hit. Hospitals in Pennsylvania were being forced to cancel operations after the attack hit computers at Heritage Valley Health Systems, a Pennsylvania health care provider, and its hospitals in Beaver and Sewickley, Penn., and satellite locations across the state.
The ransomware also hurt Australian branches of international companies. DLA Pipers Australian offices warned clients that they were dealing with a serious global cyber incident and had disabled email as a precautionary measure. Local news reports said that in Hobart, Tasmania, on Tuesday evening, computers in a Cadbury chocolate factory, owned by Mondelez International, had displayed ransomware messages that demanded $300 in bitcoins.
Qantas Airways booking system failed for a time on Tuesday, but the company said the breakdown was due to an unrelated hardware issue.
The Australian government has urged companies to install security updates and isolate any infected computers from their networks.
This ransomware attack is a wake-up call to all Australian businesses to regularly back up their data and install the latest security patches, said Dan Tehan, the cybersecurity minister. We are aware of the situation and monitoring it closely.
A National Security Agency spokesman referred questions about the attack to the Department of Homeland Security. The Department of Homeland Security is monitoring reports of cyberattacks affecting multiple global entities and is coordinating with our international and domestic cyber partners, Scott McConnell, a department spokesman, said in a statement.
Computer specialists said the ransomware was very similar to a virus that emerged last year called Petya. Petya means Little Peter, in Russian, leading some to speculate the name referred to Sergei Prokofievs 1936 symphony Peter and the Wolf, about a boy who captures a wolf.
Reports that the computer virus was a variant of Petya suggest the attackers will be hard to trace. Petya was for sale on the so-called dark web, where its creators made the ransomware available as ransomware as a service a play on Silicon Valley terminology for delivering software over the internet, according to the security firm Avast Threat Labs.
That means anyone could launch the ransomware with the click of a button, encrypt someones systems and demand a ransom to unlock it. If the victim pays, the authors of the Petya ransomware, who call themselves Janus Cybercrime Solutions, get a cut of the payment.
That distribution method means that pinning down the people responsible for Tuesdays attack could be difficult.
The attack is an improved and more lethal version of WannaCry, said Matthieu Suiche, a security researcher who helped contain the spread of the WannaCry ransomware when he created a kill switch that stopped the attacks.
In just the last seven days, Mr. Suiche noted, WannaCry had tried to hit an additional 80,000 organizations but was prevented from executing attack code because of the kill switch. Petya does not have a kill switch.
Petya also encrypts and locks entire hard drives, whereas the earlier ransomware attacks locked only individual files, said Chris Hinkley, a researcher at the security firm Armor.
The hackers behind Petya demanded $300 worth of the cybercurrency Bitcoin to unlock victims machines. By Tuesday afternoon, online records showed that 30 victims had paid the ransom, although it was not clear whether they had regained access to their files. Other victims may be out of luck, after Posteo, the German email service provider, shut down the hackers email account.
In Ukraine, people turned up at post offices, A.T.M.s and airports to find blank computer screens, or signs about closures. At Kievs central post office, a few bewildered customers milled about, holding parcels and letters, looking at a sign that said, Closed for technical reasons.
The hackers compromised Ukrainian accounting software mandated to be used in various industries in the country, including government agencies and banks, according to researchers at Cisco Talos, the security division of the computer networking company. That allowed them to unleash their ransomware when the software, which is also used in other countries, was updated.
The ransomware spread for five days across Ukraine, and around the world, before activating Tuesday evening.
If I had to guess, I would think this was done to send a political message, said Craig Williams, the senior technical researcher at Talos.
One Kiev resident, Tetiana Vasylieva, was forced to borrow money from a relative after failing to withdraw money at four automated teller machines. At one A.T.M. in Kiev belonging to the Ukrainian branch of the Austrian bank Raiffeisen, a message on the screen said the machine was not functioning.
Ukraines Infrastructure Ministry, the postal service, the national railway company, and one of the countrys largest communications companies, Ukrtelecom, had been affected, Volodymyr Omelyan, the countrys infrastructure minister, said in a Facebook post.
Officials for the metro system in Kiev said card payments could not be accepted. The national power grid company Kievenergo had to switch off all of its computers, but the situation was under control, according to the Interfax-Ukraine news agency. Metro Group, a German company that runs wholesale food stores, said its operations in Ukraine had been affected.
At the Chernobyl plant, the computers affected by the attack collected data on radiation levels and were not connected to industrial systems at the site, where, although all reactors have been decommissioned, huge volumes of radioactive waste remain. Operators said radiation monitoring was being done manually.
Cybersecurity researchers questioned whether collecting ransom was the true objective of the attack.
Its entirely possible that this attack could have been a smoke screen, said Justin Harvey, the managing director of global incident response at Accenture Security. If you are an evildoer and you wanted to cause mayhem, why wouldnt you try to first mask it as something else?
An earlier version of this article referred incorrectly to the occupation of Justin Harvey. He is the managing director of global incident response at Accenture Security, not the chief security officer for the Fidelis cybersecurity company.
Reporting was contributed by Liz Alderman, Andrew E. Kramer, Iuliia Mendel, Ivan Nechepurenko and Isabella Kwai.
A version of this article appears in print on June 28, 2017, on Page A1 of the New York edition with the headline: A Cyberattack Hits Ukraine, Then Spreads.
Go here to see the original:
Cyberattack Hits Ukraine Then Spreads Internationally - The ...
- Trump says it may be better to let Ukraine and Russia fight for a while - The Guardian - June 5th, 2025 [June 5th, 2025]
- Stop Asking How To Make Putin Walk Away From Ukraine. Its the Wrong Question. - Politico - June 5th, 2025 [June 5th, 2025]
- Exclusive | U.S. Is Redirecting Critical Antidrone Technology From Ukraine to U.S. Forces - WSJ - June 5th, 2025 [June 5th, 2025]
- Are the surprise airfield attacks a turning point for Ukraine? - BBC - June 5th, 2025 [June 5th, 2025]
- Trump compares Ukraine-Russia war to kids brawl: Sometimes youre better off letting them fight - CNN - June 5th, 2025 [June 5th, 2025]
- Trump says it may be better to let Ukraine, Russia 'fight for a while' as Merz blames Putin for war - AP News - June 5th, 2025 [June 5th, 2025]
- Russias Battlefield Woes in Ukraine - CSIS | Center for Strategic and International Studies - June 5th, 2025 [June 5th, 2025]
- Trump says he might let Russia and Ukraine fight it out a while longer - Axios - June 5th, 2025 [June 5th, 2025]
- Russia says it will respond to Ukraine attacks, Trump downplays immediate peace prospects - Reuters - June 5th, 2025 [June 5th, 2025]
- Russian strike kills 5 in Ukraine, including a 1-year-old, hours after Trump-Putin call - AP News - June 5th, 2025 [June 5th, 2025]
- Russias war on Ukraine intensifies as peace talks appear at dead end - Al Jazeera - June 5th, 2025 [June 5th, 2025]
- Ukraine war briefing: Dont be weak, Zelenskyy tells allies, after Putin threats - The Guardian - June 5th, 2025 [June 5th, 2025]
- Putin Believes Russia Is Winning the War in Ukraine. The Battlefield Picture Tells a Different Story. - The Moscow Times - June 5th, 2025 [June 5th, 2025]
- To free Russia from Putin we need to save Ukraine first, Russian opposition tells EU - politico.eu - June 5th, 2025 [June 5th, 2025]
- Ukraine crushes Putins bombers, but can China and Russia do the same to the US? - Fox News - June 5th, 2025 [June 5th, 2025]
- Trump administration redirecting anti-drone tech from Ukraine to US forces in Middle East, WSJ reports - The Kyiv Independent - June 5th, 2025 [June 5th, 2025]
- Opinion | Is the Ukraine War the Next Afghanistan? - The New York Times - June 5th, 2025 [June 5th, 2025]
- Trump says Putin to retaliate over Ukraine attacks as peace remains distant - The Washington Post - June 5th, 2025 [June 5th, 2025]
- Trump, Germany's Merz kick off friendly meeting with talks on Ukraine and trade - Reuters - June 5th, 2025 [June 5th, 2025]
- Ukraine's drone attack on Russian warplanes was a serious blow to the Kremlin's strategic arsenal - AP News - June 5th, 2025 [June 5th, 2025]
- The Senates New Ukraine Bill Will Not WorkBut Here Is How to Fix It - Council on Foreign Relations - June 5th, 2025 [June 5th, 2025]
- Putin Intends to Respond to Ukraine Strikes on Russian Bombers, Trump Says - The New York Times - June 5th, 2025 [June 5th, 2025]
- Ukraine's drone triumph opens window to the future of war - Axios - June 5th, 2025 [June 5th, 2025]
- Ukraine seeks air defense systems as Western backers meet without the Pentagon chief - AP News - June 5th, 2025 [June 5th, 2025]
- Trump says Putin told him he'll retaliate against Ukraine, casting doubt on peace progress - NBC News - June 5th, 2025 [June 5th, 2025]
- Ukraine warns Trump admin Russia planning new offensive - The Hill - June 5th, 2025 [June 5th, 2025]
- Britain pledges to deliver 100,000 drones to Ukraine by April 2026 - Reuters - June 5th, 2025 [June 5th, 2025]
- Hegseth will skip a meeting on organizing military aid to Ukraine in a first for the US - AP News - June 5th, 2025 [June 5th, 2025]
- Fibre optic drones: The terrifying new weapon changing the war in Ukraine - BBC - May 28th, 2025 [May 28th, 2025]
- Ukraine Demands Russia Present Peace Plan Immediately Instead Of Waiting For Talks Next Week - Radio Free Europe/Radio Liberty - May 28th, 2025 [May 28th, 2025]
- In Oklahoma, Role-Playing Battles Borrow From the Russia-Ukraine War - The New York Times - May 28th, 2025 [May 28th, 2025]
- Ukraine and Russia set to meet for new round of talks in Istanbul - The Washington Post - May 28th, 2025 [May 28th, 2025]
- Germany and Ukraine to jointly develop new long-range weapons as U.N. experts accuse Russia of war crimes - CBS News - May 28th, 2025 [May 28th, 2025]
- Trump gives Putin 2 weeks for action on Ukraine as relationship frays - politico.eu - May 28th, 2025 [May 28th, 2025]
- Vladimir Putin issues his conditions for ending the war in Ukraine - New York Post - May 28th, 2025 [May 28th, 2025]
- Trump attacks Putin over Ukraine onslaught but will he impose consequences? - ABC News - May 28th, 2025 [May 28th, 2025]
- Russia proposes to hold next talks with Ukraine in Istanbul on June 2 - Reuters - May 28th, 2025 [May 28th, 2025]
- Germany and Ukraine sign 5B deal on long-range weapons cooperation - politico.eu - May 28th, 2025 [May 28th, 2025]
- Ukraine braces for expected Russian summer offensive in the east - The Washington Post - May 28th, 2025 [May 28th, 2025]
- Ukraine-Russia war: Germany to make long-range missiles with Ukraine and gives 5bn more in military aid as it happened - The Guardian - May 28th, 2025 [May 28th, 2025]
- Trump says Putin 'playing with fire' as US weighs new sanctions over Ukraine - France 24 - May 28th, 2025 [May 28th, 2025]
- Russia says Ukraine, backed by Europe, is trying to wreck peace talks - Reuters - May 28th, 2025 [May 28th, 2025]
- Putin Wants End to NATO Expansion, Sanctions Relief for Peace in Ukraine Reuters - The Moscow Times - May 28th, 2025 [May 28th, 2025]
- Trumps frustration with Putin boils over with no Ukraine peace deal in sight - The Washington Post - May 28th, 2025 [May 28th, 2025]
- Russia's advance in Ukraine's north east may be bid to create 'buffer zone' - BBC - May 28th, 2025 [May 28th, 2025]
- Trump warns Putin he is playing with fire after Russian attack on Ukraine - The Guardian - May 28th, 2025 [May 28th, 2025]
- Trump holds off on sanctions to push Ukraine-Russia peace efforts - The Kyiv Independent - May 28th, 2025 [May 28th, 2025]
- Russia Bombards Ukraine With One of Largest Air Assaults of the War - The New York Times - May 28th, 2025 [May 28th, 2025]
- Russia Defies Trump With Largest-Ever Drone-and-Missile Attack on Ukraine - WSJ - May 28th, 2025 [May 28th, 2025]
- US and Russia clash over intensifying Ukraine war - USA Today - May 28th, 2025 [May 28th, 2025]
- Russia proposed new date and location for peace talks with Ukraine, Medinsky says - The Kyiv Independent - May 28th, 2025 [May 28th, 2025]
- Trump says he will call Putin, then Zelenskyy, on Monday to push for Ukraine ceasefire - AP News - May 17th, 2025 [May 17th, 2025]
- Trump and Putin Say They Will Discuss Ukraine Peace Proposals on Monday - The New York Times - May 17th, 2025 [May 17th, 2025]
- The chilling moment in Russia-Ukraine peace talks - as Putin makes mockery of Trump's efforts to end war - Sky News - May 17th, 2025 [May 17th, 2025]
- I was U.S. ambassador to Ukraine. I resigned because of Trump's foreign policy. | Opinion - Detroit Free Press - May 17th, 2025 [May 17th, 2025]
- Trump and Putin to talk about possible ceasefire between Ukraine and Russia - MSNBC News - May 17th, 2025 [May 17th, 2025]
- Russia says Ukraine talks yielded a prisoner swap deal and an agreement to keep talking - Reuters - May 17th, 2025 [May 17th, 2025]
- The Kremlin fixes conditions for new Ukraine talks, Trump to speak with Putin on Monday - France 24 - May 17th, 2025 [May 17th, 2025]
- As political theater took center stage in Turkey, the war went on in Ukraine. Kyiv has few options - AP News - May 17th, 2025 [May 17th, 2025]
- Zelensky insists he will only join Ukraine-Russia talks in Turkey this week if Putin is present - CNN - May 17th, 2025 [May 17th, 2025]
- A day of confusion and chaos as Russia and Ukraine agree to first direct talks in 3 years - CNN - May 17th, 2025 [May 17th, 2025]
- Russia and Ukraine far apart on ceasefire in first meeting in 3 years - Axios - May 17th, 2025 [May 17th, 2025]
- US says Trump and Putin needed for breakthrough in Ukraine talks - BBC - May 17th, 2025 [May 17th, 2025]
- Trump says Ukraine-Russia peace 'not going to happen' without Putin meet - ABC News - May 17th, 2025 [May 17th, 2025]
- Former US ambassador to Ukraine says she resigned because of Trump's foreign policy - Reuters - May 17th, 2025 [May 17th, 2025]
- Ukraine war latest: Russia 'demands five Ukrainian regions' in talks; father, mother and daughter 'among nine killed' in bus strike - Sky News - May 17th, 2025 [May 17th, 2025]
- Russia and Ukraine are due to meet. But with Putin a no-show, confusion reigns. Heres what we know - CNN - May 17th, 2025 [May 17th, 2025]
- Ukraine-Russia war latest: Trump will speak with Putin on Monday - The Telegraph - May 17th, 2025 [May 17th, 2025]
- New head of Russian land forces distinguished himself in Ukraine - Reuters - May 17th, 2025 [May 17th, 2025]
- Trumps Ukraine Policy Pressured the Victim, Former Ambassador Says - The New York Times - May 17th, 2025 [May 17th, 2025]
- Putin Still Holds All the Cards in Ukraine, With No Reason to Fold - Bloomberg - May 17th, 2025 [May 17th, 2025]
- Kremlin says a Putin-Trump meeting on Ukraine is essential but needs advance preparation and must yield results - Reuters - May 17th, 2025 [May 17th, 2025]
- Vatican could be a venue for Russia-Ukraine talks, Rubio says, after pope renews an offer to help - AP News - May 17th, 2025 [May 17th, 2025]
- Trump 'starting to doubt' that Ukraine will reach deal with Russia - Reuters - May 11th, 2025 [May 11th, 2025]
- Ukraine in maps: Tracking the war with Russia - BBC - May 11th, 2025 [May 11th, 2025]
- Ukraine: What Trump does next is key - and he could go either way - BBC - May 11th, 2025 [May 11th, 2025]
- Turkey ready to host Russia-Ukraine peace talks, Erdogan tells Putin - Reuters - May 11th, 2025 [May 11th, 2025]
- Never again war: Pope Leo calls for peace in Ukraine in first Sunday address - The Guardian - May 11th, 2025 [May 11th, 2025]
- Trump urges Ukraine to meet with Russia in Turkey to negotiate a possible end to the bloodbath - The Hill - May 11th, 2025 [May 11th, 2025]
- Never again war! Pope Leo calls for peace in Ukraine and Gaza in first Vatican address since his election - CNN - May 11th, 2025 [May 11th, 2025]