RANSOMEWARE HIT COMPUTER SYSTEMS
Stephanie Perrin
stephanie.perrin at MAIL.UTORONTO.CA
Sun May 14 12:44:29 EEST 2017
Good article in the NYT on this
https://www.nytimes.com/2017/05/13/opinion/the-world-is-getting-hacked-why-dont-we-do-more-to-stop-it.
Stephanie Perrin
On 2017-05-13 08:22, Niel Harper wrote:
> Hello Wisdom,
> I want to play the devil's advocate here for a minute.
> Ransomware has been a major problem since the mid-2000s. There was an
> over 150% increase in new ransomware variants in the first half of
> 2016 alone. Moreover, cybercriminals are now operating
> Ransomware-as-a-Service (RaaS) with lower buy-in costs that allow less
> tech-savvy perpetrators to distribute ransomware. News reports would
> seem to suggest that yesterday's attack was outside the norm, when it
> really wasn't.
> While providing information on this particular attack is all well and
> good, shouldn't we be talking about why governments should not be
> building up their cyber attack capabilities, and why things like
> stockpiling zero day vulnerabilities is a really bad idea and
> compromises the security of the Internet (also eroding online trust)?
> Additionally, shouldn't the discourse include guidelines about
> protecting individuals and organizations from malware attack (again
> not criticizing the efficacy and importance of incident response)?
> Sadly enough, hospitals are usually low hanging fruit for ransomware
> attacks. Their data sets are critical to patient care and management,
> and they usually don’t have the IT resources to support critical
> process areas like vulnerability management, patch management,
> business continuity management, etc. They also generally don’t have
> robust backup solutions and/or real-time replication to disaster
> recovery sites which increases the overall availability of mission
> critical data for recovery. And from a risk management perspective,
> they don’t possess the depth of human resources to employ a ‘three
> lines of defense’ approach to managing organizational risk. A robust
> data backup and recovery solution usually goes a long way in protect
> oneself from ransomware attacks. My preferred approach for
> organizations is usually a disk-to-disk-to-tape backup solution
> combined with offsite replication if possible. The backup tapes are
> encrypted and stored off site. For individuals, backing up critical
> data is also very important. But end users need to also regularly
> update their endpoint security, be wary of phishing and other
> suspicious emails, and also be mindful the rootkits can be downloaded
> from legitimate websites that have been compromised.
> Regards,
> Niel
>
> On Sat, May 13, 2017 at 6:10 AM, Wisdom Donkor <wisdom.dk at gmail.com
> <mailto:wisdom.dk at gmail.com>> wrote:
>
> Dear Colleagues,
>
> Thought of sharing this information.
>
> Yesterday, May 12, at about 5:00 pm GMT, a massive ransomware hit
> computer systems of hundreds of private companies and public
> organizations across the world which is believed to have the
> highest infection rate of all time.
> The Ransomware in question has been identified as a variant of
> ransomware known as WannaCry (also known as 'Wana Decrypt0r,'
> 'WannaCryptor' or 'WCRY').
>
> Like other dangerous ransomware variants, WannaCry also blocks
> access to
> a computer or its files and demands money to unlock it.
>
> Once infected with the WannaCry ransomware, victims are asked to
> pay up
> to $300 in order to remove the infection from their PCs; otherwise,
> their PCs render unusable, and their files remain locked.
>
> WannaCry attackers use a Windows exploit detected and tested by
> the NSA
> called EternalBlue, which was stolen and released by the Shadow
> Brokers
> hacking group over a month ago.
>
> Microsoft released a patch for the vulnerability in March (MS17-010),
> but many users and organizations who did not patch their systems
> are open to attacks.
>
> The exploit has the capability to penetrate into machines running
> unpatched version of Windows by exploiting flaws in Microsoft
> Windows SMB Server. This is why the WannaCry ransomware is
> spreading at an astonishing pace.
> Once a single computer in your organization is hit by the WannaCry
> ransomware, the worm looks for other vulnerable computers and infects
> them as well.
>
> In just a few hours, the ransomware targeted over 45,000 computers
> in 74
> countries, including United States, Russia, Germany, Turkey,
> Italy, Philippines and Vietnam, and that the number was still growing.
>
> A screenshot of detailing nations attacked are attached in this email.
>
> The ransomeware's actual mode by which it initiates and spreads
> itself on networks has not been discovered but like other
> ransomware variant, malicious links and emails are most likely the
> culprit.
>
> CERT-GH recommends users and system admins:
>
> 1. Take all windows OS systems off the internet and off the network.
> 2. Create a backup of all files needed.
> 3. Store backup in an airgapped location.
> 4. Download windows update(KB4019472) in a sandbox environment.
> 5. Install the update without connecting to a network/internet.
> 6. After the update, the system can be connected to the internet.
>
> Kind Regards
>
>
> CERT-GHANA
>
>
> --
> *WISDOM DONKOR (S/N Eng.)*
> E-government and Open Government Data Platforms Specialist*
> *
> ICANN Fellow / Member, UN IGF MAG Member, ISOC Member,
> Freedom Online Coalition (FOC) Member, Diplo Foundation Member,
> OGP Open Data WG Member, GODAN Memember, ITAG Member
> Email: wisdom.dk at gmail.com <mailto:wisdom.dk at gmail.com>
> Skype: wisdom_dk
> facebook: facebook at wisdom_dk
> Website: www.data.gov.gh <http://www.data.gov.gh/>
> www.isoc.gh <http://www.isoc.gh/> / www.itag.org.gh
> <http://www.itag.org.gh/>
>
>
>
>
> --
> *Niel Harper*
> Barbados: +(246) 424 3809
> London: +44 207 193 9826
> Mobile: +(246) 243 3818
> Email: niel.harper at ieee.org <mailto:niel.harper at ieee.org>
> Website: http://nielharper.com <http://nielharper.com/>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170514/ad7aa1af/attachment.htm>
More information about the Ncsg-discuss
mailing list