{"id":158327,"date":"2017-06-29T04:53:00","date_gmt":"2017-06-29T09:53:00","guid":{"rendered":"https:\/\/www.ntegrait.com\/a-new-strain-of-ransomware-is-even-more-virulent\/"},"modified":"2017-06-29T04:53:00","modified_gmt":"2017-06-29T09:53:00","slug":"a-new-strain-of-ransomware-is-even-more-virulent","status":"publish","type":"post","link":"https:\/\/ntegrait.com\/a-new-strain-of-ransomware-is-even-more-virulent\/","title":{"rendered":"A New Strain of Ransomware is Even More Virulent"},"content":{"rendered":"
This is a simple breakdown of the new ransomware attacks spreading globally. The attack is quite different to anything that has been spread in the past. The intention may not even be money. \u00a0<\/strong><\/p>\n <\/p>\n Recently, a new and viral malware has been spreading throughout Europe. News organizations such as the Washington Post and The New York Times have been talking about it quite a lot. However, no one seems to have much information about it.<\/p>\n The stories began on the morning of June 27, 2017. While its method of infection has not been discovered, it is known that this malware in behaving like a worm. That means when one node is infected, it tries to spread to other nodes. When the virus infects a computer, it shows a \u201cChkdisk\u201d screen that is meant to entice the user not to power off. This attack has been touted to be even worse than the Wannacry attack.<\/p>\n Kaspersky Discovered in First.<\/strong><\/p>\n Kaspersky actually discovered this Ransomware a while back. Since then, they have noted that it has been spreading for weeks. The reason why it has become such a big issue in recent days is that it has started to affect huge organizations, especially government organizations.<\/p>\n What is Known About it.<\/strong><\/p>\n Some researchers have christened it PetyaWrap. It uses a potent mix of techniques to enter a network and from there spread to all computers in that network. As with other attacks from ransomware such as WCry, it made use of EternalBlue. This advanced exploit was developed by the NSA to snoop on unwitting users of the Windows OS.<\/p>\n The new attack used a new exploit called the EternalRomance, which was developed by the NSA. Microsoft developed a patch for the vulnerabilities. However, many computers remain quite vulnerable. People with basic technical skills now have a powerful method to deliver any kind of digital warhead that they wish to install in a computer. It is especially so for those who had not installed the updates from Microsoft.<\/p>\n However, EternalRomance was not the only exploit that it used. The recent attack showed that it was a major improvement over past attacks. The new attack also used Mimikatz, which is a tool used to extract passwords from computers on a network. With that ability, they could use PSExec, which is a legitimate component of Windows.<\/p>\n That means even computers that had updated their OS and were immune to EternalRomance and EternalBlue could be hacked. Some of the Ransomware is also using a vulnerability of Ukrainian software called MeDoc. The result is that MeDoc is being used to send updates to the end users.<\/p>\n