Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…
Another Ransomware Outbreak Is Going Global
191–200 of 435 posts
Re: Another Ransomware Outbreak Is Going Global
#192Earlier quoted context omitted.
That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.
@willlstrafach, Nothing you have said convinces me the commentator you are replying to is wrong. Especially since an NSL would prevent ANYONE who detected anything from speaking about it. Updates that tweak code to introduce vulnerabilities, is not something thats science fiction.
Forced malicious updates would indeed be a reasonable concern if this was somehow actually the case. It is not, though, and I am not sure how that would even work. Are you saying that when it is detected, the government would somehow become aware of the detection and threaten the finder with an NSL before they could tell anyone?
Re: Another Ransomware Outbreak Is Going Global
#193The Netherlands and various other countries have created laws where either their version of the NSA and/or police can hoard 0days to be used for hacking. This massive outbreak is so widespread that at this stage it appears that it either was a very recent 0day or something which only recently was fixed by a patch. Instead of having loads of countries hoarding security problems I highly encourage a focus on security i…
It is basically WannaCry without the kill switch. It is using the same exploits (EternalBlue). Not some recent zero-day, but sloppy patching.
Re: Another Ransomware Outbreak Is Going Global
#194FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)
Interesting. If I was Posteo I don't think I would've been so quick to ban the email, this will potentially cause a lot of harm. What about all the people that need their data back? They have no way to get it now. Plus many people are still going to post the money only to get no response from the email.
Re: Another Ransomware Outbreak Is Going Global
#195>A cyberattack is affecting the Beaver and Sewickley hospitals and all other care facilities in the Heritage Valley Health System on Tuesday.
http://amp.wtae.com/article/cybersecurity-incident-heritage-...
Re: Another Ransomware Outbreak Is Going Global
#196This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.
"Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised." March 14 of what year ? I would say 2000 but I am open to discussion ...
Re: Another Ransomware Outbreak Is Going Global
#197FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)
Interesting. If I was Posteo I don't think I would've been so quick to ban the email, this will potentially cause a lot of harm. What about all the people that need their data back? They have no way to get it now. Plus many people are still going to post the money only to get no response from the email.
It will cause a major headache for those who pay and will hopefully make people learn to distrust ransomware, in turn making it less lucrative.
On the other hand, that requires a fair number of "acceptable casualties" so to speak.
I personally think both sides of this are valid and don't know what the best option really is. It will be interesting to watch how things evolve at least.
Re: Another Ransomware Outbreak Is Going Global
#198Earlier quoted context omitted.
How do they plan on contacting the employees en masse if the computer is off?
Probably via their smart phones
Smart (-ass?) employees will also turn off their smartphones...
Re: Another Ransomware Outbreak Is Going Global
#199FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)
It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money. All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.
The best way to end ransomware is to get serious about security. In many cases, being attacked by a ransomware, is paying a low price compared to if it was a targeted attack.
edit: Also, I imagine it gets easier after you wrote one i.e. many ransomewares come from the same author. So he could gain a reputation by signing messages saying that yes, this is our ransomware, we always unlock after receiving the payment.
Re: Another Ransomware Outbreak Is Going Global
#200i said this before and it was met with mostly hostility, but im still wondering... bitcoin has enabled ransomware, so its a boon to crooks. what has it done for non-crooks? i dont mean conceptually (no fed! decentralized! etc. etc.), i mean since its come into being, what has it done for you personally? for me: i bought a vpn subscription, anonymously. probably not able to do that as easily without btc. but, i would…
However crooks are always going to be among the early adopters, so I my guess i my answer would be that it has limited value, right now.