New week,Watch Operation Condor Online new ransomware.
A new form of ransomware surfaced in Russia, Ukraine and elsewhere this week. Known as Bad Rabbit, it's employed a leaked NSA exploit to do some of its damage.
SEE ALSO: Paying for antivirus software is mostly BSRansomware works by freezing up a computer in an attempt to force the user to pay a fee if they want their machine to be normal again.
The trick for hackers, of course, is how to get the malicious agent onto machines in the first place.
Bad Rabbit does this in a few steps. Here's how the cybersecurity firm Symantec described it in a post analyzing the ransomware:
"The initial infection method is through drive-by downloads on compromised websites. The malware is disguised as a fake update to Adobe Flash Player. The download originates from a domain named 1dnscontrol[dot]com, although visitors may have been redirected there from another compromised website."
After the malware's been installed, according to cybersecurity firm Cisco Talos, "there is an SMB component used for lateral movement and further infection."
SMB refers to Server Message Block, which is a means by which networked Windows machines share information. Bad Rabbit attacks SMB in several ways, according to Symantec, looking to spread to other vulnerable Windows machines in the same network as the computer on which it was first installed. One of the ways is through an SMB exploit known as EternalRomance, according to Talos and Symantec.
This takes us back to April, when a group of hackers known as the Shadow Brokers dumped a trove of NSA exploits on the internet for anyone to use them, assuming they have the knowledge required. Those exploits pertained to computers running Windows, putting millions of Windows users at risk of ransomware broadsides. Microsoft had actually released patches to ameliorate this and other exploits in March, but folks have to update their computers in order for those patches to take effect, and people looking to use this ransomware surely know that many folks simply never hit update (if you're running Windows and reading this, make sure to patch up your system if you haven't already).
"Ransomware is the threat of choice for both its monetary gain as well as destructive nature"
"The distribution of BadRabbit was massive," a threat intelligence expert at the cybersecurity firm Group-IBwrote on the company's website, though he noted that the distribution resulted in "much fewer victims" than another recent ransomware attack. The "primary" victims of the attack included "several Ukrainian strategic enterprises" including Odessa International Airport and the metro in Kiev, as well as "federal mass media" in Russia.
Wrapping up its Bad Rabbit analysis, Talos concluded that the world can expect more fast-spreading attacks that strike quickly and are designed "to inflict maximum damage."
"Ransomware is the threat of choice for both its monetary gain as well as destructive nature," they wrote. "As long as there is money to be made or destruction to be had these threats are going to continue."
Topics Cybersecurity
Previous:Andrew Yang’s War on Normal People
Eerie photos from the aftermath of the Hillary Clinton party that wasn'tThis website makes the impending Trump presidency all too realAustralia's newspapers aren't holding back on hot Trump takesStunning 360Muslim women are scared to wear the hijab in public after Trump winPeople are blacking out their Twitter profiles to protest a Trump presidencyAirlines already have deals for depressed Americans7 video game escapes you desperately need todayIndians sign up for mobile wallets after most cash rendered uselessJ.K. Rowling keeps her cool during election, calmly destroys Twitter trollsWatch Conor McGregor meet an Irish NYPD officer and feel all of the feels25 positive tweets for people who are traumatized by the U.S. electionChicago anthem 'Go Cubs Go' cracks the Billboard chartsThe entire US election was basically one giant Photoshop battleMashReads Podcast: 'The Underground Railroad' is a must7 video game escapes you desperately need todayDespondent parents wonder how to explain the Trump's win to their kidsThis is how the world leaders reacted to Trump's electionDude who used drone to deliver sausage explains how (and why)Irish couple live tweets journey to receive legal abortion in England Notes on Unreadable Books Samuel Beckett on One of His Favorite Paintings Is This a Photo of the Brontë Sisters? Probably Not. Swimming with Oliver Sacks The World’s First Multicolor Solving Agatha Christie’s Mysteries with Data We Are All Sensitive People: A Marvin Gaye Story Having Trouble Sleeping? Read the Ultimate Insomnia Cure. Did Herman Melville’s Mother Make Him Watch Her Sleep? Beautiful Image, or, Adolescence at the Spa California Street: Learning to Surf in the Sixties Only Five Days Left to #ReadEverywhere Loved the Ocean, Lived in the Desert, and Other News by Dan Piepenbring Staff Picks: Amy Gerstler, Barton Swaim, Matthew Gavin Frank Think Like a Mountain—Aldo Leopold’s Path to Conservationism Next Tuesday: James Salter’s Memorial Service “Coke,” a Poem by Scott Cohen When You Marry Someone Who Has the Same Last Name How Rebracketing Gives Us New Words A Letter from H. L. Mencken
2.5514s , 10128.875 kb
Copyright © 2025 Powered by 【Watch Operation Condor Online】,Miracle Information Network