会员登录 - 用户注册 - 设为首页 - 加入收藏 - 网站地图 A new ransomware tapped an NSA exploit to wreak some of its havoc!

A new ransomware tapped an NSA exploit to wreak some of its havoc

时间:2024-09-23 02:18:48 来源:摩登家庭人人影视网 作者:关于我们 阅读:452次

New week, new ransomware.

A new form of ransomware surfaced in Russia, Ukraine and elsewhere this week. Known as Bad Rabbit, it's employed a leaked NSA exploit to do some of its damage.

SEE ALSO:Paying for antivirus software is mostly BS

Ransomware works by freezing up a computer in an attempt to force the user to pay a fee if they want their machine to be normal again.

The trick for hackers, of course, is how to get the malicious agent onto machines in the first place.

Mashable Games

Bad Rabbit does this in a few steps. Here's how the cybersecurity firm Symantec described it in a post analyzing the ransomware:

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

"The initial infection method is through drive-by downloads on compromised websites. The malware is disguised as a fake update to Adobe Flash Player. The download originates from a domain named 1dnscontrol[dot]com, although visitors may have been redirected there from another compromised website."

After the malware's been installed, according to cybersecurity firm Cisco Talos, "there is an SMB component used for lateral movement and further infection."

SMB refers to Server Message Block, which is a means by which networked Windows machines share information. Bad Rabbit attacks SMB in several ways, according to Symantec, looking to spread to other vulnerable Windows machines in the same network as the computer on which it was first installed. One of the ways is through an SMB exploit known as EternalRomance, according to Talos and Symantec.

This takes us back to April, when a group of hackers known as the Shadow Brokers dumped a trove of NSA exploits on the internet for anyone to use them, assuming they have the knowledge required. Those exploits pertained to computers running Windows, putting millions of Windows users at risk of ransomware broadsides. Microsoft had actually released patches to ameliorate this and other exploits in March, but folks have to update their computers in order for those patches to take effect, and people looking to use this ransomware surely know that many folks simply never hit update (if you're running Windows and reading this, make sure to patch up your system if you haven't already).

"Ransomware is the threat of choice for both its monetary gain as well as destructive nature"

"The distribution of BadRabbit was massive," a threat intelligence expert at the cybersecurity firm Group-IBwrote on the company's website, though he noted that the distribution resulted in "much fewer victims" than another recent ransomware attack. The "primary" victims of the attack included "several Ukrainian strategic enterprises" including Odessa International Airport and the metro in Kiev, as well as "federal mass media" in Russia.

Wrapping up its Bad Rabbit analysis, Talos concluded that the world can expect more fast-spreading attacks that strike quickly and are designed "to inflict maximum damage."

"Ransomware is the threat of choice for both its monetary gain as well as destructive nature," they wrote. "As long as there is money to be made or destruction to be had these threats are going to continue."


Featured Video For You
Step inside the secretive class that turns people into hackers

(责任编辑:资讯)

相关内容
  • 21 College and University Museums
  • 筑牢金融安全防线 构建和谐金融环境
  • 探索郁南无核黄皮百亿产业发展方案,培优扶强行动走进郁南黄皮产区
  • 实施强村公司培育计划,壮大村集体经济
  • The Techies Who Lunch
  • 灞变笢鍚勫競2014鏈€浣庡伐璧勬爣鍑咜闈掑矝鏈€浣?350鍏僟涓浗灞变笢缃慱闈掑矝
  • 青岛商家开炒她经济 三八妇女节促销提前
  • 前三月电商投资额占去年50% 传统零售背道而驰
推荐内容
  • 21 Unexpected Wonders in Colorado’s Vibrant Cities and Small Towns
  • 3月北京CPI涨2.1% 分析称 物价不具备高企条件
  • 莆田民生银行司机:申请辞职一个多月 公司扣薪不放人
  • 新品种亮相!广东省农作物现代种业产业园晚稻现场观摩会召开
  • Spaceship tech slashes energy usage of existing AC systems
  • 人民币告别不跌神话 海淘族一箱奶粉多花70元