Showing posts with label WANNACRY. Show all posts
Showing posts with label WANNACRY. Show all posts

Monday, 25 September 2017

By concealing identities, cryptocurrencies fuel cybercrime

hacking

When hackers hold their victims’ data for ransom, as happened in the WannaCry and NotPetya ransomware attacks that spread across the globe in mid-2017, a key to the criminals’ success is getting away with the money. That often means they use cryptocurrencies like bitcoin to collect payment, hoping to remain hidden behind a digital mask.

The WannaCry hackers went a step farther, though. They converted their bitcoins into Monero, another e-currency designed to offer even stronger privacy.

At the Initiative for Cryptocurrencies and Contracts, we have explored the ways cryptocurrency systems protect users’ anonymity. Anonymity in cryptocurrencies is fueling crime by enabling criminals to evade identification by law enforcement. We believe that this problem will get worse as cryptocurrencies evolve stronger privacy protections and become more flexibly programmable. We also believe there’s no simple solution.

Masking criminal identities

All cryptocurrency systems work in roughly the same way. Groups of computers receive transaction information directly from users who want to send each other money. The computers order and permanently record these transactions in a public ledger so that anyone can read them. The public ledger also makes it possible to keep track of how much currency individual users own. Developers tweak the code in different cryptocurrency systems to add additional features, like fast transaction processing or improved anonymity.
READ MORE

Friday, 30 June 2017

India presses Microsoft for Windows discount in wake of cyber attacks

India presses Microsoft for Windows discount in wake of cyber attacks

India is pressing Microsoft Corp to offer a sharply discounted one-time deal to the more than 50 million Windows users in the country so that they can upgrade to the latest Windows 10 operating system in the wake of ransomware attacks.

Microsoft officials in India have "in principle agreed" to the request, Gulshan Rai, India's cyber security coordinator, told Reuters over the phone on Friday.

A spokeswoman for Microsoft in India declined to comment on the matter. Officials at the company's headquarters in the United States and regional headquarters in Asia also declined to comment.

If Microsoft agreed to such a discount, it could open up the global software giant to similar requests from around the world. Rai said the government was in talks with Microsoft management in India. It is not immediately clear whether any other countries were seeking similar deals.

Rai said India began talks with Microsoft after the WannaCry ransomware attack last month, noting that both WannaCry and this week's attack, dubbed by some cyber experts "NotPetya", exploited vulnerabilities in older iterations of the Windows OS.

"The quantum of the price cut, we expect some detail on in a couple of days," Rai said, adding the Indian government expected the company to offer the software at "throw-away prices."

"It will be a one-time upgrade offer to Windows 10 and it will be a discounted price for the entire country," said Rai, who was hand-picked by Indian Prime Minister Narendra Modi to be the country's first cyber security chief.

Rai declined to be more specific, but said he was confident that it would be "less than a quarter of the current price."

Rai, who has over two decades of experience in different IT areas including cyber security, said his team began coordinating with government agencies and regulators to push for OS upgrades soon after the WannaCry attack began on May 12.
READ MORE

Wednesday, 28 June 2017

Cyberattack hits Ukraine then spreads internationally

cyber attack

Computer systems from Ukraine to the United States were struck on Tuesday in an international cyberattack that was similar to a recent assault that crippled tens of thousands of machines worldwide.

In Kiev, the capital of Ukraine, A.T.M.s stopped working. About 80 miles away, workers were forced to manually monitor radiation at the old Chernobyl nuclear plant when their computers failed. And tech managers at companies around the world — from Maersk, the Danish shipping conglomerate, to Merck, the drug giant in the United States — were scrambling to respond. Even an Australian factory for the chocolate giant Cadbury was affected.

It was unclear who was behind this cyberattack, and the extent of its impact was still hard to gauge Tuesday. It started as an attack on Ukrainian government and business computer systems — an assault that appeared to have been intended to hit the day before a holiday marking the adoption in 1996 of Ukraine’s first Constitution after its break from the Soviet Union. The attack spread from there, causing collateral damage around the world.

The outbreak was the latest and perhaps the most sophisticated in a series of attacks making use of dozens of hacking tools that were stolen from the National Security Agency and leaked online in April by a group called the Shadow Brokers.

Like the WannaCry attacks in May, the latest global hacking took control of computers and demanded digital ransom from their owners to regain access. The new attack used the same National Security Agency hacking tool, Eternal Blue, that was used in the WannaCry episode, as well as two other methods to promote its spread, according to researchers at the computer security company Symantec.

The National Security Agency has not acknowledged its tools were used in WannaCry or other attacks. But computer security specialists are demanding that the agency help the rest of the world defend against the weapons it created.
READ MORE

Monday, 5 June 2017

Japan arrests 14-year-old for creating ransomware similar to WannaCry

Arrest via Shutterstock

Japanese authorities on Monday arrested a 14-year-old boy for creating a ransomware virus similar to WannaCry which was responsible for global cyberattacks last month.

The boy, a student at a secondary school in Osaka prefecture, is accused of creating the ransomware — a malware, or malicious software programme that limits or prevents users from accessing the computer or files unless they pay a ransom — through free encryption software, Efe news reported.

The student, who admitted to the allegations, then uploaded it to a foreign website and taught users of the platform to download and use it, according to sources quoted by the Kyodo news agency.

This ransomware, which has been downloaded 100 times, allowed the user to infect the victim's computer and asked for virtual currency as ransom, although the economic toll has not yet been confirmed, added the same sources.

The young boy, who supposedly learned by himself how to create this type of programme, revealed to the investigating authorities that he only wanted to become famous, according to state television channel NHK.

His arrest comes after WannaCry's ransomware hit at least 150 countries and health centres in the UK, large companies in France and Spain, railways networks in Germany, public institutions in Russia and universities in China.

Some 600 Japanese companies, including Hitachi and Nissan, were affected by this cyberattack.

Japanese IT security company Trend Micro has detected more than 65,000 ransomware attacks over the past year in Japan, a figure 10 times higher than that of the previous year.
READ MORE

Saturday, 20 May 2017

Victims call hackers' bluff as ransomware deadline nears

Victims call hackers' bluff as ransomware deadline nears

With the clock ticking on whether a global hacking attack would wipe out his data, Bolton Jiang had no intention of paying a 21st-century ransom.

Since a week ago, when the malware first struck, Mr. Jiang has been busily fixing and replacing computers at the electronics company where he works in Shanghai. Paying is a bother, he said, and there was no guarantee he would get his data back.

“Even if you do pay, you won’t necessarily be able to open the files that are hit,” he said. “There is no solution to it.”

Tens of thousands of computer users around the world faced the same dilemma on Friday, their last chance to pay the anonymous hackers behind the ransomware attack known as WannaCry. The malicious software exposed the widespread vulnerability of computers and offered a peek at how a new type of crime could be committed on a global scale.

As part of the hacking, attackers demanded that individuals pay a fee to regain control of their machines, or face losing their data.

The latest strain of ransomware was particularly virulent, experts warned, because it had been based on software stolen from the National Security Agency. Law enforcement agencies in the United States and elsewhere have been hunting for the culprits, with attention focused on hackers linked to North Korea.

Despite a week of widespread disruption, the total ransom paid so far looks relatively modest. An online tracking system showed that the amount sent in the electronic currency Bitcoin to accounts listed by the attackers had begun to plateau on Wednesday, and had reached about $90,000 on Friday afternoon in Europe. Early estimates of what the virus could ultimately earn had ranged into the tens of millions or even hundreds of millions of dollars. Victims have seven days to pay from when their computers were originally infected, so the deadline will vary from case to case.

A number of people and companies have struck a defiant tone. The Japanese conglomerate Hitachi, which had been identified in the news media as a victim, declined to confirm those reports on Friday but said that it had no intention of paying a ransom and that it aimed to be fully secure against future attacks by Monday.
READ MORE

Monday, 15 May 2017

Renault-Nissan resumes work in nearly all plants after ransomware attack

Renault-Nissan, Nissan, cyber attack,

Renault-Nissan said on Monday that output had returned to normal at nearly all its plants, after a global cyber attack caused widespread disruption including stoppages at several of the auto alliance's sites.

Renault and its Japanese partner are the only major car manufacturers so far to have reported production problems resulting from Friday's WannaCry ransomware worm attack that spread to more than 150 countries.

Nissan said its huge factory in Sunderland, northeast England was operating normally, after Friday's initial outbreak disrupted the final production shift before the weekend.

However, manufacturing remained suspended at the Douai plant in northern France, where Renault builds pricier models including its Talisman sedan and Espace crossover, the company said.

The cyber attack halted or reduced the output of at least five Renault sites over the weekend. Besides Douai, they included a van plant in Sandouville, France; a small-car plant in Slovenia; the no-frills Dacia plant in Pitesti, Romania; and a factory shared with Nissan in Chennai, India.

"All Renault Group sites are operational with the exception of Douai, which reopens tomorrow," a spokesman said. Lost production will be made up, he added, and the financial impact has yet to be calculated.

Renault-Nissan's main rivals appeared to escape any disruption. PSA Group, Fiat Chrysler, Volkswagen, Daimler, Toyota and Honda all said their plants were unaffected.

They declined to comment on their cybersecurity policies. "If we give any information on our systems we would be sending a message to potential hackers," a PSA spokesman said.

The attack damaged some high-profile targets, including Britain's health service. But experts say the concentration of infections in emerging markets, with relatively low numbers in Europe and the United States, reflects the way they mainly affected older Windows computer systems.

Paul Pratley of London-based MWR Infosecurity said WannaCry had in many cases hit budget-strapped organisations or older business units where it no longer made economic sense to upgrade hardware or software aggressively.

READ MORE