Cyberattack Hits Ukraine Then Spreads Internationally – The …
Like the WannaCry attacks in May, the latest global hacking took control of computers and demanded digital ransom from their owners to regain access. The new attack used the same National Security Agency hacking tool, Eternal Blue, that was used in the WannaCry episode, as well as two other methods to promote its spread, according to researchers at the computer security company Symantec.
The National Security Agency has not acknowledged its tools were used in WannaCry or other attacks. But computer security specialists are demanding that the agency help the rest of the world defend against the weapons it created.
The N.S.A. needs to take a leadership role in working closely with security and operating system platform vendors such as Apple and Microsoft to address the plague that theyve unleashed, said Golan Ben-Oni, the global chief information officer at IDT, a Newark-based conglomerate hit by a separate attack in April that used the agencys hacking tools. Mr. Ben-Oni warned federal officials that more serious attacks were probably on the horizon.
The vulnerability in Windows software used by Eternal Blue was patched by Microsoft in March, but as the WannaCry attacks demonstrated, hundreds of thousands of groups around the world failed to properly install the fix.
Just because you roll out a patch doesnt mean itll be put in place quickly, said Carl Herberger, vice president for security at Radware. The more bureaucratic an organization is, the higher chance it wont have updated its software.
Because the ransomware used at least two other ways to spread on Tuesday including stealing victims credentials even those who used the Microsoft patch could be vulnerable and potential targets for later attacks, according to researchers at F-Secure, a Finnish cybersecurity firm, and others.
A Microsoft spokesman said the companys latest antivirus software should protect against the attack.
Governments and companies in Europe and the United States have been impacted. Here are several:
The Ukrainian government said several of its ministries, local banks and metro systems had been affected. A number of other European companies, including Rosneft, the Russian energy giant; Saint-Gobain, the French construction materials company; and WPP, the British advertising agency, also said they had been targeted.
Ukrainian officials pointed a finger at Russia on Tuesday, although Russian companies were also affected. Home Credit bank, one of Russias top 50 lenders, was paralyzed, with all of its offices closed, according to the RBC news website. The attack also affected Evraz, a steel manufacturing and mining company that employs about 80,000 people, the RBC website reported.
In the United States, the multinational law firm DLA Piper also reported being hit. Hospitals in Pennsylvania were being forced to cancel operations after the attack hit computers at Heritage Valley Health Systems, a Pennsylvania health care provider, and its hospitals in Beaver and Sewickley, Penn., and satellite locations across the state.
The ransomware also hurt Australian branches of international companies. DLA Pipers Australian offices warned clients that they were dealing with a serious global cyber incident and had disabled email as a precautionary measure. Local news reports said that in Hobart, Tasmania, on Tuesday evening, computers in a Cadbury chocolate factory, owned by Mondelez International, had displayed ransomware messages that demanded $300 in bitcoins.
Qantas Airways booking system failed for a time on Tuesday, but the company said the breakdown was due to an unrelated hardware issue.
The Australian government has urged companies to install security updates and isolate any infected computers from their networks.
This ransomware attack is a wake-up call to all Australian businesses to regularly back up their data and install the latest security patches, said Dan Tehan, the cybersecurity minister. We are aware of the situation and monitoring it closely.
A National Security Agency spokesman referred questions about the attack to the Department of Homeland Security. The Department of Homeland Security is monitoring reports of cyberattacks affecting multiple global entities and is coordinating with our international and domestic cyber partners, Scott McConnell, a department spokesman, said in a statement.
Computer specialists said the ransomware was very similar to a virus that emerged last year called Petya. Petya means Little Peter, in Russian, leading some to speculate the name referred to Sergei Prokofievs 1936 symphony Peter and the Wolf, about a boy who captures a wolf.
Reports that the computer virus was a variant of Petya suggest the attackers will be hard to trace. Petya was for sale on the so-called dark web, where its creators made the ransomware available as ransomware as a service a play on Silicon Valley terminology for delivering software over the internet, according to the security firm Avast Threat Labs.
That means anyone could launch the ransomware with the click of a button, encrypt someones systems and demand a ransom to unlock it. If the victim pays, the authors of the Petya ransomware, who call themselves Janus Cybercrime Solutions, get a cut of the payment.
That distribution method means that pinning down the people responsible for Tuesdays attack could be difficult.
The attack is an improved and more lethal version of WannaCry, said Matthieu Suiche, a security researcher who helped contain the spread of the WannaCry ransomware when he created a kill switch that stopped the attacks.
In just the last seven days, Mr. Suiche noted, WannaCry had tried to hit an additional 80,000 organizations but was prevented from executing attack code because of the kill switch. Petya does not have a kill switch.
Petya also encrypts and locks entire hard drives, whereas the earlier ransomware attacks locked only individual files, said Chris Hinkley, a researcher at the security firm Armor.
The hackers behind Petya demanded $300 worth of the cybercurrency Bitcoin to unlock victims machines. By Tuesday afternoon, online records showed that 30 victims had paid the ransom, although it was not clear whether they had regained access to their files. Other victims may be out of luck, after Posteo, the German email service provider, shut down the hackers email account.
In Ukraine, people turned up at post offices, A.T.M.s and airports to find blank computer screens, or signs about closures. At Kievs central post office, a few bewildered customers milled about, holding parcels and letters, looking at a sign that said, Closed for technical reasons.
The hackers compromised Ukrainian accounting software mandated to be used in various industries in the country, including government agencies and banks, according to researchers at Cisco Talos, the security division of the computer networking company. That allowed them to unleash their ransomware when the software, which is also used in other countries, was updated.
The ransomware spread for five days across Ukraine, and around the world, before activating Tuesday evening.
If I had to guess, I would think this was done to send a political message, said Craig Williams, the senior technical researcher at Talos.
One Kiev resident, Tetiana Vasylieva, was forced to borrow money from a relative after failing to withdraw money at four automated teller machines. At one A.T.M. in Kiev belonging to the Ukrainian branch of the Austrian bank Raiffeisen, a message on the screen said the machine was not functioning.
Ukraines Infrastructure Ministry, the postal service, the national railway company, and one of the countrys largest communications companies, Ukrtelecom, had been affected, Volodymyr Omelyan, the countrys infrastructure minister, said in a Facebook post.
Officials for the metro system in Kiev said card payments could not be accepted. The national power grid company Kievenergo had to switch off all of its computers, but the situation was under control, according to the Interfax-Ukraine news agency. Metro Group, a German company that runs wholesale food stores, said its operations in Ukraine had been affected.
At the Chernobyl plant, the computers affected by the attack collected data on radiation levels and were not connected to industrial systems at the site, where, although all reactors have been decommissioned, huge volumes of radioactive waste remain. Operators said radiation monitoring was being done manually.
Cybersecurity researchers questioned whether collecting ransom was the true objective of the attack.
Its entirely possible that this attack could have been a smoke screen, said Justin Harvey, the managing director of global incident response at Accenture Security. If you are an evildoer and you wanted to cause mayhem, why wouldnt you try to first mask it as something else?
An earlier version of this article referred incorrectly to the occupation of Justin Harvey. He is the managing director of global incident response at Accenture Security, not the chief security officer for the Fidelis cybersecurity company.
Reporting was contributed by Liz Alderman, Andrew E. Kramer, Iuliia Mendel, Ivan Nechepurenko and Isabella Kwai.
A version of this article appears in print on June 28, 2017, on Page A1 of the New York edition with the headline: A Cyberattack Hits Ukraine, Then Spreads.
Go here to see the original:
Cyberattack Hits Ukraine Then Spreads Internationally - The ...
- Trump Says He May Give Tomahawks to Ukraine. Is He Bluffing? - The New York Times - October 15th, 2025 [October 15th, 2025]
- Ukraine war briefing: Poland minister shows Shahed drone and warns of deep Russian threat - The Guardian - October 15th, 2025 [October 15th, 2025]
- Ukraine-Russia war latest: Russia will be a major threat to NATO after Ukraine war, says Finland - The Independent - October 15th, 2025 [October 15th, 2025]
- Ukraine live: Trump warns Putin must end war as its not making Russia look good - The Independent - October 15th, 2025 [October 15th, 2025]
- What Are Tomahawk Missiles, and Why Might Trump Give Them to Ukraine? - The New York Times - October 15th, 2025 [October 15th, 2025]
- Analysis: After Gaza, Ukraine is next on Trumps list. But peace with Putin may prove even more elusive - CNN - October 15th, 2025 [October 15th, 2025]
- Why Putin and Russia May Be Running Out of Time in Ukraine - New York Magazine - October 15th, 2025 [October 15th, 2025]
- We need to give Ukraine the means to fight for peace | Column - Tampa Bay Times - October 15th, 2025 [October 15th, 2025]
- Nordic and Baltic Nations to Pledge US Arms Financing to Ukraine - Bloomberg.com - October 15th, 2025 [October 15th, 2025]
- US Presses NATO Allies to Boost Ukraine Aid by Buying American Weapons Through PURL Fund - UNITED24 Media - October 15th, 2025 [October 15th, 2025]
- Russia Revives Propaganda Used Before Invasions of Ukraine and Georgia, Targeting Baltics Next - UNITED24 Media - October 15th, 2025 [October 15th, 2025]
- Ukraine live: Trump says weve got to get Russia done after Tomahawk threat - The Independent - October 15th, 2025 [October 15th, 2025]
- Putins top ally warns if Trump gives missiles to Ukraine it could lead to nuclear war - The Independent - October 15th, 2025 [October 15th, 2025]
- Ukraine tells residents to leave dozens of villages near city of Kupiansk - CBC - October 15th, 2025 [October 15th, 2025]
- NATO's newest members offer to buy more US arms for Ukraine as Western backing declines - WHEC.com - October 15th, 2025 [October 15th, 2025]
- Finland to provide new aid package to Ukraine and join PURL initiative - Ukrinform - October 15th, 2025 [October 15th, 2025]
- Ukraine has relied on trains during the war. Russia is creating new technology to target them - The Independent - October 15th, 2025 [October 15th, 2025]
- 'Surprising' drop in military aid to Ukraine in recent months, report says - The Kyiv Independent - October 15th, 2025 [October 15th, 2025]
- Russia launched 3 more massive strikes on Ukraine's gas facilities over last week, Naftogaz says - The Kyiv Independent - October 15th, 2025 [October 15th, 2025]
- US expects NATO countries to invest more into arms initiative for Ukraine, Hegseth says - Al Arabiya English - October 15th, 2025 [October 15th, 2025]
- Russian strikes knock out power in parts of Ukraine - Al Arabiya English - October 15th, 2025 [October 15th, 2025]
- US defense manufacturer reveals new Tomahawk launcher just what Ukraine would need to hit Russia - The Kyiv Independent - October 15th, 2025 [October 15th, 2025]
- Can Fiber-Optic Drones Be Stopped? How Ukraine Faces the Unjammable Threat - UNITED24 Media - October 15th, 2025 [October 15th, 2025]
- IMF cuts Russias 2025 growth forecast to 0.6%, leaves Ukraine's unchanged at 2% - IntelliNews - October 15th, 2025 [October 15th, 2025]
- NATO's newest members offer to buy more US arms for Ukraine as Western backing declines - The Independent - October 15th, 2025 [October 15th, 2025]
- Ukraine and France Coordinated Positions Ahead of the European Council Meeting to Be Held Next Week - - - October 15th, 2025 [October 15th, 2025]
- Trump speaks with cabinet on Gaza conflict, Russia and Ukraine - WSAZ - October 13th, 2025 [October 13th, 2025]
- Trump speaks with cabinet on Gaza conflict, Russia and Ukraine - WAFB - October 13th, 2025 [October 13th, 2025]
- Ukraine and Russias intensifying energy war brings gas shortages and economic pain - CNN - October 13th, 2025 [October 13th, 2025]
- Kremlin warns the West over 'dramatic' escalation moment in Ukraine war - Reuters - October 13th, 2025 [October 13th, 2025]
- Ukraine war briefing: Moscow voices extreme concern at Trump threat to send Tomahawk missiles to Kyiv - The Guardian - October 13th, 2025 [October 13th, 2025]
- Trump may speak with Putin about sending Tomahawks to Ukraine in effort to end war - Politico - October 13th, 2025 [October 13th, 2025]
- Trump says he may tell Putin to settle war or he'll give Ukraine Tomahawks - Axios - October 13th, 2025 [October 13th, 2025]
- Balkans Breakthrough for Ukraine: Bring Serbia into NATO & the Kosovo Model into the Donbas - The SAIS Review of International Affairs - October 13th, 2025 [October 13th, 2025]
- Trump Says He May Warn Putin US to Mull Tomahawks for Ukraine - Bloomberg.com - October 13th, 2025 [October 13th, 2025]
- Trump says he may tell Putin he may send Tomahawks to Ukraine if war not settled - Reuters - October 13th, 2025 [October 13th, 2025]
- Trump speaks with cabinet on Gaza conflict, Russia and Ukraine - WLBT - October 13th, 2025 [October 13th, 2025]
- Russia's Big Warning Amid Buzz US May Give Tomahawk Missiles To Ukraine - NDTV - October 13th, 2025 [October 13th, 2025]
- Trump speaks with cabinet on Gaza conflict, Russia and Ukraine - fox10tv.com - October 13th, 2025 [October 13th, 2025]
- Pope hails glimmers of hope for peace in Holy Land and prays for Ukraine - Vatican News - October 13th, 2025 [October 13th, 2025]
- Trump says he will send Tomahawk missiles to Ukraine if war with Russia not settled - TRT World - October 13th, 2025 [October 13th, 2025]
- US will send Ukraine Tomahawks if war unresolved - AzerNews - October 13th, 2025 [October 13th, 2025]
- Trump threatens to provide Tomahawks to Ukraine if Putin continues attacks - Washington Examiner - October 13th, 2025 [October 13th, 2025]
- Trump says he may send Tomahawk missiles to Ukraine - Latest news from Azerbaijan - October 13th, 2025 [October 13th, 2025]
- Trump mulls arming Ukraine with Tomahawk missiles: What makes them lethal? - Business Standard - October 13th, 2025 [October 13th, 2025]
- Trump says he will urge Putin to end the war or face the US sending Tomahawks to Ukraine - The Kyiv Independent - October 13th, 2025 [October 13th, 2025]
- Washington Is Helping Ukraine Hit Russia Where It Hurts MostIts Oil Economy - UNITED24 Media - October 13th, 2025 [October 13th, 2025]
- Melania Trump discusses efforts for 'safe reunification of children' in Ukraine - NBC News - October 11th, 2025 [October 11th, 2025]
- Melania Trump: Eight children 'displaced' by war in Ukraine have been reunited with families - Sky News - October 11th, 2025 [October 11th, 2025]
- Ukraine Restores Power To Thousands After Mass Outages Caused By Russian Strikes - Radio Free Europe/Radio Liberty - October 11th, 2025 [October 11th, 2025]
- Skyranger 35 to be supplied to Ukraine - Rheinmetall - October 11th, 2025 [October 11th, 2025]
- UK ready to use frozen Russian assets to fund Ukraine war effort - BBC - October 11th, 2025 [October 11th, 2025]
- On the Battlegrounds in Gaza and Ukraine with H.R. McMaster - Foundation for Defense of Democracies - October 11th, 2025 [October 11th, 2025]
- The new AI arms race changing the war in Ukraine - BBC - October 11th, 2025 [October 11th, 2025]
- Melania Trump reveals talks with Putin over kidnapped Ukraine children - The Independent - October 11th, 2025 [October 11th, 2025]
- Zelenskyy says he will nominate Trump for Nobel peace prize if he secures Ukraine ceasefire as it happened - The Guardian - October 11th, 2025 [October 11th, 2025]
- Ukraine war live: Zelensky will nominate Trump for Peace Prize if US sends Tomahawks - The Independent - October 11th, 2025 [October 11th, 2025]
- Power in Ukraine restored after massive blackout - TVP World - October 11th, 2025 [October 11th, 2025]
- Power returns after Kyiv plunged into darkness by massive Russian attack on Ukraine energy sector as it happened - The Guardian - October 11th, 2025 [October 11th, 2025]
- Power restored to 800,000 in Kyiv after major Russian strikes on Ukraine's energy grid - Yahoo News Canada - October 11th, 2025 [October 11th, 2025]
- Power restored to 800,000 in Kyiv after major Russian strikes on Ukraine's energy grid - The Lufkin Daily News - October 11th, 2025 [October 11th, 2025]
- Poland offers help as Ukraine reels from Russian attacks on energy infrastructure - Reuters - October 11th, 2025 [October 11th, 2025]
- Russian army loses another 1,060 soldiers in war against Ukraine in one day - Ukrinform - October 11th, 2025 [October 11th, 2025]
- Power restored to 800,000 in Kyiv after major Russian strikes on Ukraine's energy grid - Ottumwa Courier - October 11th, 2025 [October 11th, 2025]
- Ukraine war briefing: Analysts flag Kremlin scare campaign against use of Tomahawks - The Guardian - October 9th, 2025 [October 9th, 2025]
- How Ukraine Turned the Tables on Russia - The Atlantic - October 9th, 2025 [October 9th, 2025]
- Russia escalates warning as Trump considers sale of Tomahawks to Ukraine - The Washington Post - October 9th, 2025 [October 9th, 2025]
- News: Five NATO Allies support medical rehabilitation in Ukraine, 07-Oct.-2025 - NATO - Homepage - October 9th, 2025 [October 9th, 2025]
- Beyond FPVs: Learning the Lessons of the Ukraine WarAll of Them - Modern War Institute - - October 9th, 2025 [October 9th, 2025]
- Russia says prospects for Ukraine peace deal now faded as its war rages on - Al Jazeera - October 9th, 2025 [October 9th, 2025]
- Renowned Architect Gunned Down in St. Petersburg in Suspected Murder by Ukraine War Veteran - The Moscow Times - October 9th, 2025 [October 9th, 2025]
- Ukraine war latest: Kyiv denies involvement in case of Ukrainian detained in Poland over Nord Stream sabotage - The Kyiv Independent - October 9th, 2025 [October 9th, 2025]
- Opinion | What if a Russian victory in Ukraine were only the beginning? - The Washington Post - October 9th, 2025 [October 9th, 2025]
- Russia says impetus for peace in Ukraine after Putin-Trump summit has been exhausted - Reuters - October 9th, 2025 [October 9th, 2025]
- Putin says Russia has captured nearly 5,000 square km in Ukraine this year - Reuters - October 9th, 2025 [October 9th, 2025]
- Ukraine says a massive Russian overnight missile and drone barrage was packed with 100,000 foreign-made parts - Business Insider - October 9th, 2025 [October 9th, 2025]
- Rattled Russia threatens US, Ukraine over Tomahawk missiles: We will find ways to hurt those who cause us trouble - New York Post - October 9th, 2025 [October 9th, 2025]
- Russian regions are massively boosting military sign-up bonuses to lure more people to fight in Ukraine - CNN - October 9th, 2025 [October 9th, 2025]
- Zelenskiy says Ukraine inflicts frontline losses on Russian troops in Donetsk region - Yahoo - October 9th, 2025 [October 9th, 2025]
- A Snapback Solution for Ukraine: How to Craft Security Guarantees That Kyivand MoscowWill Find Credible - Foreign Affairs - October 9th, 2025 [October 9th, 2025]