RANSOMEWARE HIT COMPUTER SYSTEMS

Stephanie Perrin stephanie.perrin at MAIL.UTORONTO.CA
Sun May 14 12:44:29 EEST 2017


Good article in the NYT on this

https://www.nytimes.com/2017/05/13/opinion/the-world-is-getting-hacked-why-dont-we-do-more-to-stop-it.

Stephanie Perrin

On 2017-05-13 08:22, Niel Harper wrote:
> Hello Wisdom,
> I want to play the devil's advocate here for a minute.
> Ransomware has been a major problem since the mid-2000s. There was an 
> over 150% increase in new ransomware variants in the first half of 
> 2016 alone. Moreover, cybercriminals are now operating 
> Ransomware-as-a-Service (RaaS) with lower buy-in costs that allow less 
> tech-savvy perpetrators to distribute ransomware. News reports would 
> seem to suggest that yesterday's attack was outside the norm, when it 
> really wasn't.
> While providing information on this particular attack is all well and 
> good, shouldn't we be talking about why governments should not be 
> building up their cyber attack capabilities, and why things like 
> stockpiling zero day vulnerabilities is a really bad idea and 
> compromises the security of the Internet (also eroding online trust)?
> Additionally, shouldn't the discourse include guidelines about 
> protecting individuals and organizations from malware attack (again 
> not criticizing the efficacy and importance of incident response)?
> Sadly enough, hospitals are usually low hanging fruit for ransomware 
> attacks. Their data sets are critical to patient care and management, 
> and they usually don’t have the IT resources to support critical 
> process areas like vulnerability management, patch management, 
> business continuity management, etc. They also generally don’t have 
> robust backup solutions and/or real-time replication to disaster 
> recovery sites which increases the overall availability of mission 
> critical data for recovery. And from a risk management perspective, 
> they don’t possess the depth of human resources to employ a ‘three 
> lines of defense’ approach to managing organizational risk. A robust 
> data backup and recovery solution usually goes a long way in protect 
> oneself from ransomware attacks. My preferred approach for 
> organizations is usually a disk-to-disk-to-tape backup solution 
> combined with offsite replication if possible. The backup tapes are 
> encrypted and stored off site. For individuals, backing up critical 
> data is also very important. But end users need to also regularly 
> update their endpoint security, be wary of phishing and other 
> suspicious emails, and also be mindful the rootkits can be downloaded 
> from legitimate websites that have been compromised.
> Regards,
> Niel
>
> On Sat, May 13, 2017 at 6:10 AM, Wisdom Donkor <wisdom.dk at gmail.com 
> <mailto:wisdom.dk at gmail.com>> wrote:
>
>     Dear Colleagues,
>
>     Thought of sharing this information.
>
>     Yesterday, May 12, at about 5:00 pm GMT, a massive ransomware hit
>     computer systems of hundreds of private companies and public
>     organizations across the world which is believed to have the
>     highest infection rate of all time.
>     The Ransomware in question has been identified as a variant of
>     ransomware known as WannaCry (also known as 'Wana Decrypt0r,'
>     'WannaCryptor' or 'WCRY').
>
>     Like other dangerous ransomware variants, WannaCry also blocks
>     access to
>     a computer or its files and demands money to unlock it.
>
>     Once infected with the WannaCry ransomware, victims are asked to
>     pay up
>     to $300 in order to remove the infection from their PCs; otherwise,
>     their PCs render unusable, and their files remain locked.
>
>     WannaCry attackers use a Windows exploit detected and tested by
>     the NSA
>     called EternalBlue, which was stolen and released by the Shadow
>     Brokers
>     hacking group over a month ago.
>
>     Microsoft released a patch for the vulnerability in March (MS17-010),
>     but many users and organizations who did not patch their systems
>     are open to attacks.
>
>     The exploit has the capability to penetrate into machines running
>     unpatched version of Windows by exploiting flaws in Microsoft
>     Windows SMB Server. This is why the WannaCry ransomware is
>     spreading at an astonishing pace.
>     Once a single computer in your organization is hit by the WannaCry
>     ransomware, the worm looks for other vulnerable computers and infects
>     them as well.
>
>     In just a few hours, the ransomware targeted over 45,000 computers
>     in 74
>     countries, including United States, Russia, Germany, Turkey,
>     Italy, Philippines and Vietnam, and that the number was still growing.
>
>     A screenshot of detailing nations attacked are attached in this email.
>
>     The ransomeware's actual mode by which it initiates and spreads
>     itself on networks has not been discovered but like other
>     ransomware variant, malicious links and emails are most likely the
>     culprit.
>
>     CERT-GH recommends users and system admins:
>
>     1. Take all windows OS systems off the internet and off the network.
>     2. Create a backup of all files needed.
>     3. Store backup in an airgapped location.
>     4. Download windows update(KB4019472) in a sandbox environment.
>     5. Install the update without connecting to a network/internet.
>     6. After the update, the system can be connected to the internet.
>
>     Kind Regards
>
>
>     CERT-GHANA
>
>
>     -- 
>     *WISDOM DONKOR (S/N Eng.)*
>     E-government and Open Government Data Platforms Specialist*
>     *
>     ICANN Fellow / Member, UN IGF MAG Member, ISOC Member,
>     Freedom Online Coalition (FOC) Member, Diplo Foundation Member,
>     OGP Open Data WG Member, GODAN Memember, ITAG Member
>     Email: wisdom.dk at gmail.com <mailto:wisdom.dk at gmail.com>
>     Skype: wisdom_dk
>     facebook: facebook at wisdom_dk
>     Website: www.data.gov.gh <http://www.data.gov.gh/>
>     www.isoc.gh <http://www.isoc.gh/> / www.itag.org.gh
>     <http://www.itag.org.gh/>
>
>
>
>
> -- 
> *Niel Harper*
> Barbados: +(246) 424 3809
> London: +44 207 193 9826
> Mobile: +(246) 243 3818
> Email: niel.harper at ieee.org <mailto:niel.harper at ieee.org>
> Website: http://nielharper.com <http://nielharper.com/>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170514/ad7aa1af/attachment.htm>


More information about the Ncsg-discuss mailing list