Site icon WinCert

Eastern Europe under new “BadRabbit” cyber-attack

<p>After Petya&comma; the ransomware cyber-attack that happened earlier this year&comma; Russia&comma; Ukraine and other Eastern European countries have been under another attack&comma; most likely&comma; from the same source&period; This one is called BadRabbit and is focused on many corporate networks&comma; Kiev metro computer systems&comma; Odessa International Airport and many others&comma; for society vital&comma; computer systems&period;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2017&sol;09&sol;computer&lowbar;attacker&period;jpg"><img class&equals;"alignnone size-full wp-image-2275" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2017&sol;09&sol;computer&lowbar;attacker&period;jpg" alt&equals;"ccleaner" width&equals;"640" height&equals;"423" &sol;><&sol;a><&sol;p>&NewLine;<h5>Cybersecurity researchers say that it is obvious that this attack has been planned for quite some time&comma; probably since the first cyber-attack which happened earlier this summer&comma; since both have so much in common&period;<&sol;h5>&NewLine;<p>For example&comma; they both used the Windows Management Instrumentation Command-line&comma; a scripting interface for managing devices and applications in a network so that they could spread more efficiently along with Mimikatz&comma; a tool for harvesting passwords and other data from computers&period; And now they have been popping up in various systems&comma; displaying a ransom message&period;<&sol;p>&NewLine;<p>It is very easy for an inexperienced eye to catch this virus since it has been spreading through a drive-by download&period; To put it simply&comma; a JavaScript is injected into an HTML body of a website or a &period;js file&period;<&sol;p>&NewLine;<p>With the message saying that the Flash Player needs to be updated&comma; the virus installs itself together with the downloaded update&period; It is&comma; however&comma; possible that this is only one method used to spread the virus&period;<&sol;p>&NewLine;<p>As in other similar attacks&comma; the random amount just increases as time goes by&period; It is still unclear who is behind these attacks&period;<&sol;p>&NewLine;<p>There is undeniable evidence that links these cyber terrorists with Russia but it is not yet certain&period; What matters most is the prevention of this new virus to cause more harm than it already has&comma; as was the scenario with the virus that was released earlier in the summer that took down many government agencies and businesses&period;<&sol;p>&NewLine;

Exit mobile version