Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Tuesday’s massive ransomware outbreak was, in fact, something much worse
ArsTechnica ^ | 6/29/2017 | DAN GOODIN

Posted on 06/28/2017 9:51:49 PM PDT by TigerLikesRooster

Tuesday’s massive ransomware outbreak was, in fact, something much worse

Payload delivered in mass attack destroys data, with no hope of recovery.

DAN GOODIN - 6/29/2017, 5:30 AM

Tuesday's massive outbreak of malware that shut down computers around the world has been almost universally blamed on ransomware, which by definition seeks to make money by unlocking data held hostage only if victims pay a hefty fee. Now, some researchers are drawing an even bleaker assessment—that the malware was a wiper with the objective of permanently destroying data.

Initially, researchers said the malware was a new version of the Petya ransomware that first struck in early 2016. Later, researchers said it was a new, never-before-seen ransomware package that mimicked some of Petya's behaviors. With more time to analyze the malware, researchers on Wednesday are highlighting some curious behavior for a piece of malware that was nearly perfect in almost all other respects: its code is so aggressive that it's impossible for victims to recover their data.

In other words, the researchers said, the payload delivered in Tuesday's outbreak wasn't ransomware at all. Instead, its true objective was to permanently wipe as many hard drives as possible on infected networks, in much the way the Shamoon disk wiper left a wake of destruction in Saudi Arabia. Some researchers have said Shamoon is likely the work of developers sponsored by an as-yet unidentified country. Researchers analyzing Tuesday's malware—alternatively dubbed PetyaWrap, NotPetya, and ExPetr—are speculating the ransom note left behind in Tuesday's attack was, in fact, a hoax intended to capitalize on media interest sparked by last month's massive WCry outbreak.

(Excerpt) Read more at arstechnica.com ...


TOPICS: Chit/Chat; Computers/Internet
KEYWORDS: petya; ransomware; ukraine
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-73 next last

1 posted on 06/28/2017 9:51:49 PM PDT by TigerLikesRooster
[ Post Reply | Private Reply | View Replies]

To: TigerLikesRooster

Another CIA tool let loose.


2 posted on 06/28/2017 9:53:38 PM PDT by jospehm20
[ Post Reply | Private Reply | To 1 | View Replies]

To: jospehm20

Important data should always be backed up and kept offline.


3 posted on 06/28/2017 9:56:34 PM PDT by CondorFlight (I)
[ Post Reply | Private Reply | To 2 | View Replies]

To: TigerLikesRooster
A code segment altered for destroying data:


4 posted on 06/28/2017 9:56:49 PM PDT by TigerLikesRooster (dead parakeet + lost fishing gear = freep all day)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TigerLikesRooster

Could be Russia. Or the US Deep State destroying incriminating evidence of its own crimes, under the cover of worldwide cyber chaos.


5 posted on 06/28/2017 9:56:50 PM PDT by rfp1234 (DinosorosExtinction)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jospehm20

“Another CIA tool let loose.”

yep.


6 posted on 06/28/2017 9:57:57 PM PDT by catnipman ( Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: CondorFlight

“Important data should always be backed up and kept offline.”

yep.


7 posted on 06/28/2017 9:58:16 PM PDT by catnipman ( Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: jospehm20
Obama’s Black Hats at work.
8 posted on 06/28/2017 9:58:45 PM PDT by Chgogal (I will NOT submit, therefore, Jihadists hate me.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: CondorFlight

There is no “offline”, once you’ve gone to the cloud. So all eyes are on the cloud, I would presume.


9 posted on 06/28/2017 10:00:43 PM PDT by dr_lew (I)
[ Post Reply | Private Reply | To 3 | View Replies]

To: rfp1234

Could be a Rockefeller Reptilian who infiltrated the KGB, was assigned to worming his way into the Vatican, where he was assigned to the Bilderburger Illuminati liason office, too.


10 posted on 06/28/2017 10:01:28 PM PDT by Rashputin (Jesus Christ doesn't evacuate His troops, He leads them to victory !!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: TigerLikesRooster

So, if it destroys the master boot record, use a utility to copy your disks master boot record to file so you can restore it later.


11 posted on 06/28/2017 10:02:45 PM PDT by eastexsteve
[ Post Reply | Private Reply | To 1 | View Replies]

To: Rashputin

Good suggestion for the future plot of “The Godfather Part IV”.


12 posted on 06/28/2017 10:03:50 PM PDT by rfp1234 (DinosorosExtinction)
[ Post Reply | Private Reply | To 10 | View Replies]

To: CondorFlight

Yep. I back mine up to an external every day.


13 posted on 06/28/2017 10:09:06 PM PDT by jospehm20
[ Post Reply | Private Reply | To 3 | View Replies]

To: rfp1234
Someone either used this thing as a way to hide their destruction of data they didn't want revealed or had a way to make a buck from it by either not being infected when others were or by intimidating someone who was refusing to pay kickbacks. Given the current state of affairs in Ukraine, I suspect the later, someone being intimidated for not paying up.

As for the Godfather IV, that'll be mostly how some guy who buys into the gaming and hospitality industry becomes President then realizes that the mob is quietly helping him fight the globalists who have nearly destroyed all the solid business it took nearly a hundred years for the mob to build.

Once he knows, does coordinate with them or simply pretend he doesn't know and let things play out without his actively trying to help them in return for them helping him.

14 posted on 06/28/2017 10:32:08 PM PDT by Rashputin (Jesus Christ doesn't evacuate His troops, He leads them to victory !!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: TigerLikesRooster

Interesting. Thanks for posting.


15 posted on 06/28/2017 10:34:32 PM PDT by PGalt
[ Post Reply | Private Reply | To 1 | View Replies]

To: catnipman

That isn’t even necessarily safe anymore.

https://wikileaks.org/vault7/releases/#Brutal Kangaroo


16 posted on 06/28/2017 10:36:59 PM PDT by 31R1O
[ Post Reply | Private Reply | To 7 | View Replies]

To: TigerLikesRooster


FYI: turn OFF JavaScript, the most evil entity known to computing.

NEVER open email attachments. The info can always be conveyed another way.

Turn OFF HTML when downloading/reading email. This not only disables scripts, it provides privacy by not "phoning home" through embedded images.

NEVER install any application unless you are willing to bet your cyber life/security/privacy and everything else on its source. Installing an application gives the keys of your kingdom to that application. You've been warned.
17 posted on 06/28/2017 10:43:04 PM PDT by 867V309 (Lock Her Up)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_lew

Which is part of why I deactivated all cloud functions on my machines. I suppose there may be an empty space associated with this iPad but nothing is stored on a machine I don’t own.


18 posted on 06/28/2017 10:51:08 PM PDT by Rurudyne (Standup Philosopher)
[ Post Reply | Private Reply | To 9 | View Replies]

To: catnipman

With multiple terabyte free standing hard drives $150 +/- on Amazon, there is no reason not to follow your advice. Get two, swap out and dupe all drives every week, and you can never miss one than a week’s data.


19 posted on 06/28/2017 11:02:42 PM PDT by Strac6 ("We sleep safe in our beds only because rough men stand ready to visit violence on the enemy.")
[ Post Reply | Private Reply | To 7 | View Replies]

To: CondorFlight

Amazon
WD 4TB Orange USB 3.0 My Passport Portable External Hard Drive (WDBYFT0040BOR-WESN)
4.5 out of 5 stars 2,038 customer reviews
| 645 answered questions
List Price: $129.99
Price: $119.00 & FREE Shipping.

FOUR TB FOR $129, Incredible!


20 posted on 06/28/2017 11:04:46 PM PDT by Strac6 ("We sleep safe in our beds only because rough men stand ready to visit violence on the enemy.")
[ Post Reply | Private Reply | To 3 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-73 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson