Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

71–80 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#71
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.

It's compromised by Microsoft, who would willingly (and would be required to) cooperate with the NSA upon request.

Re: Another Ransomware Outbreak Is Going Global

#72
post #68

My friend's work laptop is a victim of this same attack... all the way here in the Philippines. There was a company wide email blast to disconnect all workstations from the internet at once. Fascinating development

A literal case of 'in case of cyberattack break glass'

https://i.imgur.com/fHhkdxX.jpg

Re: Another Ransomware Outbreak Is Going Global

#73
post #65
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to securi…

The previous one WanaCry, was based on a vulnerability that was patched on later OSes. Microsoft went back and retroactively added patches for unmaintained operating systems (like XP).

It was based off an SMB exploit released in a ShadowBroker's dump; an unreleased exploit thought to have been used by the NSA.

Re: Another Ransomware Outbreak Is Going Global

#76
post #31
post #20

A friend sent me the bitcoin address, they've already collected 2600$. [EDIT] Now 3230$ Source: https://blockchain.info/address/1Mz7153HMuxXTuR2R1t78mGSdzaA...

it seems like a trivially avoidable mistake to use a single wallet for all collections, but maybe i shouldn't be giving them ideas...

Why do you think it a mistake?

Re: Another Ransomware Outbreak Is Going Global

#77
post #31

Earlier quoted context omitted.

it seems like a trivially avoidable mistake to use a single wallet for all collections, but maybe i shouldn't be giving them ideas...

how do you konw it's only one wallet

Every infection is showing the same address.

Re: Another Ransomware Outbreak Is Going Global

#78
(Sorry for the repost but I feel the pain of sysadmins so it might be useful to some people as everything melts down around them this evening)...

Hey, FWIW we had to do some response for ransomware cases recently.

There was a lack of decent stuff out there for how IT teams should deal with it. So we contributed to putting together this quick checklist:

https://github.com/0xswap/guides/blob/master/ransomware-tria...

Would be great if more people wanted to add to it.

Re: Another Ransomware Outbreak Is Going Global

#79
post #75

Can someone provide a simple (but not overly so) explanation of how the current generation of ransomware operate i.e., A) spread and B) lock up the computer? Does it always require human intervention for A. ? Thank you.

Depends on The ransomware.

Usually if it says "0-Day" assume that it can be exploited without human intervention a-la stuxnet

Re: Another Ransomware Outbreak Is Going Global

#80
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.

Distrusting Windows was the wisest thing you did since you climbed off your horse. [1]

No, seriously. How is it paranoia to think the NSA was/is surveilling your Windows installation if we already have proof that they have the means [2] and motivation [3] to do it at scale?

[1] http://www.quotes.net/show-quote/34121

[2] https://en.wikipedia.org/wiki/EternalBlue

[3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)

Post reply on HN