Ransomware is being used as bait in data destruction attacks targeting Ukraine
International security researchers have issued a warning about a new type of data erasure malware that is currently being deployed in destructive attacks against Ukraine's network infrastructure. In many cases, the attacks are accompanied by a GoLang-based ransomware.
The Symantec security team said today that it has found a malicious wiper malware program called HermeticWiper that is being deployed in infection campaigns targeting agencies and organizations related to the Ukrainian government. This is basically a type of malicious code designed to erase data in a radical way. After successful infection, HermeticWiper will immediately destroy data on the system, making it unrecoverable and causing local failure.
Symantec also revealed another interesting piece of information, which is that it appears that ransomware has been used as a bait or as a distraction from malicious and potentially dangerous wiper malware attacks. more severe damage. This suggests some similarities to previous WhisperGate attacks that also targeted Ukraine, where wiper malware was disguised as ransomware.
The decoy ransomware also comes with ransom notices on compromised systems, along with political messages. The ransom note instructs victims to contact two email addresses ([email protected] and [email protected]) to recover encrypted data.
The hacked targets included financial contractors and government organizations from not only Ukraine but also Latvia and Lithuania.
Although the cyberattack was primarily recorded on February 24, cybersecurity firm ESET noted that the HermeticWiper malware has code compiled from December 28, 2021. This suggests that this could be a pre-planned cyber attack. Up to now, thousands of devices operating in Ukraine's cyberspace have been found to be infected with the above malware.
Notably, Symantec also found evidence that attackers gained access to victims' networks long before that, by exploiting Microsoft Exchange vulnerabilities in early November. 2021 and install the web shell before deploying the malware.
The wiper malware uses the EaseUS Partition Manager driver to corrupt the files of the compromised device before rebooting the system. In particular, the data eraser will also wipe the device's Master Boot Record, making all infected devices unbootable.
Along with the malware infection attacks, Ukraine's network infrastructure is also suffering from a series of DDoS attacks targeting a number of key government agencies and banks.
You should read it
- 10 typical malware types
- How does malware get into smartphones?
- Fileless malware - Achilles heel of traditional antivirus software
- 5 tips to help detect signs of malware
- The malware detection is extremely dangerous, unable to destroy even if the operating system is reinstalled and the hard drive is replaced
- Google 'purged' 24 applications downloaded nearly 500,000 times containing malicious malware
- Chrome 17 blocks malware that helps users
- How many types of malware do you know and how to prevent them?
May be interested
- Detection of a new ransomware strain targeting the Windows search enginea ransomware attack begins when the victim receives an executable file containing malicious code via email.
- Ransomware can attack the CPU, not just the operating system: How to prevent it?ransomware is a serious problem in its current state and is only going to get worse. any security programs and measures will be rendered useless when ransomware attacks the cpu.
- 5 gangs that create the world's most dangerous ransomwareransomware attacks are growing exponentially in size and demand for ransom - changing the way we operate online. knowing who is behind the attacks and the purpose of the attacks is important to taking down.
- VnDirect case 'collapsed': How dangerous is ransomware?ransomware is the type of software that causes the most financial damage to agencies and businesses through attacks and data encryption. basically, it is very difficult to decrypt encrypted data.
- Warning: Quantum Ransomware is being rapidly deployed in lightning attacksransomware (ransomware) is probably not a new concept for most computer users. however, quantum ransomware is a term not everyone has heard of.
- Strange ransomware detection only attacks the richother ransomware often spread to all victims if possible, but the new ransomware is different, it selectively infects.
- How to use Acronis Ransomware Protection against ransomwareacronis ransomware protection is an anti-ransomware software on your computer that protects your computer against malicious attacks and data backup features.
- Warning: These 3 dangerous ransomware could explode all over the world, 1800 large enterprises were 'shot'.the netherlands national cyber security center (ncsc) has issued an emergency report, warning of three ransomware strains that are storming around the world, and will likely explode in the near future.
- What is Fargo Ransomware? How to avoid?ransomware is a major threat to the digital world, made even more so by cybercriminals coming up with various strategies. one way to solve the problem is to learn how these attacks work.
- PureLocker - a very 'weird' ransomware strain that can encrypt serverspurelocker: new ransomware strain with an unusual attack mechanism