Jun 27, 2017

Massive ransomware attack hits Europe


A massive cyberattack appears to have hit Europe, touching a number of countries, companies and public domains.

  • WPP, one of the world's largest advertising agencies confirmed on Twitter that its IT system has been affected from a possible cyberattack. Employees at Ogilvy and other WPP agencies were sent home.
  • AP reports that Ukraine's prime minister Volodymyr Groysman said the cyberattack is 'unprecedented' but that 'vital systems' haven't been affected, but Ukrainian banks and an electricity firm have been attacked. A Ukrainian official wrote on his official Facebook page that a Ukrainan airport's IT systems had also been compromised.
  • Russia's state-controlled oil company (and the world's largest publicly listed oil company by production), PAO Rosneft, said it was under a "massive hacker attack" but said its oil production hadn't been affected, per WSJ,
  • The WSJ also reports that an attack brought down computer systems across Denmark's shipping giant Maersk, which runs the world's largest container operator.
  • A large percentage of infected machines appear to be Windows 7 and 10 with a majority running 64-bit OS, according to David Kennerley at Webroot.

Daniel Smith, security researcher at Radware, tells Axios the attack is a global ransomware campaign, meaning the attackers are asking victims to forward money to be relieved. "This outbreak is leveraging the ransomware variant PETRWRAP/PETYA and spreading via the EternalBlue exploit, similar to how WannaCry spread," said Smith. "The ransom requested is $300 BTC upon infection. There is only one BTC address associated with this campaign."

What is "Petya"? A strain of attack first reported in March that reboots victims' computers, encrypts their hard drive's master file (instead of individual files) and renders their entire master hard drive inoperable. The Petya component includes many features that enable to malware to remain viable on infected systems, and the EternalBlue component enables it to proliferate through organizations that don't have the correct patches or antivirus software.

"This is a great example of two malware components coming together to generate more pernicious and resilient malware," said Phil Richards, chief information officer at Ivanti.

Timing: The attack comes just over a month after the massive WannaCry ransomware attack, conducted by a North Korean hacking group, that spread to 300,000 breaches across 150 countries. Last October, a DDOS (distributed denial of service) cyberattack shut down a huge portion of the internet. Many organizations spent countless hours trying to patch the vulnerability to the WannaCry attack and were not necessarily paying attention to other vulnerabilities in their devices, Kennerley said.

Who is responsible? Monzy Merza, head of cyber research for Splunk — a San Francisco software company that detects cyber-attacks and insider threats — speculates it might be Ukraine's neighboring countries or hackers nearby since geospatial proximity makes attacking easier. He also notes that the attackers were likely using Ukraine as a "testing ground" for future attacks.

Why it matters: Merza says people are becoming increasingly aware of these types of cyber attacks because they are starting to directly affect people outside of the cyber realm.

This story is being updated.

Go deeper