June 2017 Petya Ransomware Virus Hits Ukraine

  • Thread starter Thread starter jedishrfu
  • Start date Start date
  • Tags Tags
    2017 Virus
Join the discussion
Registration is free. Start your own thread to ask a follow-up.
4 replies · 2K views
Messages
15,819
Reaction score
10,706
This new virus used multiple means of attack to infect machines on a network. The initial attack came from a legitimate software updater program:

Microsoft on Tuesday confirmed some initial infections in the Petya ransomware attacks occurred via Ukraine-based tax accounting software firm M.E.Doc, which develops MEDoc.

The finding solves part of the mystery surrounding yesterday's huge ransomware outbreakthat hit industry giants like shipping firm Maersk, but took a particularly heavily toll on organizations in the Ukraine, including banks, energy companies and even Kiev's main airport.

Security researchers speculated a corrupted MEDoc updater was the initial infection vector. However, Microsoft now says it has solid evidence that at least some infections were due to a software supply-chain attack that started with a legitimate MEDoc updater process.
...

http://www.zdnet.com/article/micros...tacks-were-spread-by-hacked-software-updater/
 
  • Like
Likes   Reactions: Asymptotic, QuantumQuest and Greg Bernhardt
Physics news on Phys.org
jedishrfu said:
People are speechless in the face of this viral onslaught.
I just shake my head that there are still systems out there that either don't get patched, or don't run host firewalls to block the spread of this stuff. Microsoft started blocking this kind of attack out of the box with Windows XP SP2 in 2004.
 
  • Like
Likes   Reactions: QuantumQuest and OCR
stoomart said:
I just shake my head that there are still systems out there that either don't get patched, or don't run host firewalls to block the spread of this stuff. Microsoft started blocking this kind of attack out of the box with Windows XP SP2 in 2004.
I'm confused. Wikipedia article says:
The EternalBlue exploit had been previously identified, and Microsoft issued patches in March 2017 to shut down the exploit for the latest versions of Windows Vista, Windows 7, Windows 8.1, Windows 10, Windows Server 2008, Windows Server 2012, and Windows Server 2016
Doesn't this imply that their OSs did not block this kin of attack until March of this year?
 
Bandersnatch said:
I'm confused. Wikipedia article says:

Doesn't this imply that their OSs did not block this kin of attack until March of this year?
March is when the patch was released, but running the default Windows firewall prevents a system from being compromised over the network, whether it's patched or not. You have to disable or misconfigure the firewall for the malware to spread around your network.
 
  • Like
Likes   Reactions: Bandersnatch