Arab Times

New computer virus spreads from Ukraine to disrupt world business

Port terminals operation by Maersk disrupted

-

FRANKFURT/MOSCOW/KIEV, June 28, (Agencies): A cyber attack wreaked havoc around the globe on Wednesday, crippling thousands of computers, disrupting operations at ports from Mumbai to Los Angeles and halting production at a chocolate factory in Australia.

The virus is believed to have first taken hold on Tuesday in Ukraine where it silently infected computers after users downloaded a popular tax accounting package or visited a local news site, national police and internatio­nal cyber experts said.

The malicious code locked machines and demanded victims post a ransom worth $300 in bitcoins or lose their data entirely, similar to the extortion tactic used in the global WannaCry ransomware attack in May.

More than 30 victims paid up but security experts are questionin­g whether extortion was the goal, given the relatively small sum demanded, or whether the hackers were driven by destructiv­e motives rather than financial gain.

Ransoms

Hackers asked victims to notify them by email when ransoms had been paid but German email provider Posteo quickly shut down the address, a German government cyber security official said.

Ukraine, the epicentre of the cyber strike, has repeatedly accused Russia of orchestrat­ing attacks on its computer systems and critical power infrastruc­ture since its powerful neighbour annexed the Black Sea peninsula of Crimea in 2014.

The Kremlin, which has consistent­ly rejected the accusation­s, said on Wednesday it had no informatio­n about the origin of the global cyber attack, which also struck Russian companies such as oil giant Rosneft and a steelmaker.

“No one can effectivel­y combat cyber threats on their own, and, unfortunat­ely, unfounded blanket accusation­s will not solve this problem,” said Kremlin spokesman Dmitry Peskov.

ESET, a Slovakian company that sells products to shield computers from viruses, said 80 percent of the infections detected among its global customer base were in Ukraine, with Italy second hardest hit with about 10 percent.

The aim of the latest attack appeared to be disruption rather than ransom, said Brian Lord, former deputy director of intelligen­ce and cyber operations at Britain’s GCHQ and now managing director at private security firm PGI Cyber.

“My sense is this starts to look like a state operating through a proxy ... as a kind of experiment to see what happens,” Lord told Reuters on Wednesday.

While the malware seemed to be a variant of past campaigns, derived from code known as Eternal Blue believed to have been developed by the US National Security Agency (NSA), experts said it was not as virulent as May’s WannaCry attack.

Security researcher­s said Tuesday’s virus could leap from computer to computer once unleashed within an organisati­on but, unlike WannaCry, it could not randomly trawl the internet for its next victims, limiting its scope to infect.

Bushiness that installed Microsoft’s latest security patches from earlier this year and turned off Windows file-sharing features appeared to be largely unaffected.

There was speculatio­n, however, among some experts that once the new virus had infected one computer it could spread to other machines on the same network, even if those devices had received a security update.

After WannaCry, government­s, security firms and industrial groups advised businesses and consumers to make sure all their computers were updated with Microsoft security patches.

Austria’s government-backed Computer Emergency Response Team (CERT) said “a small number” of internatio­nal firms appeared to be affected, with tens of thousands of computers taken down.

Security firms including Microsoft, Cisco’s Talos and Symantec said they had confirmed some of the initial infections occurred when malware was transmitte­d to users of a Ukrainian tax software programme called MEDoc.

The supplier of the software, M.E.Doc denied in a post on Facebook that its software was to blame, though Microsoft reiterated its suspicions afterwards.

Active

“Microsoft now has evidence that a few active infections of the ransomware initially started from the legitimate MEDoc updater process,” it said in a technical blog post.

Russian security firm Kaspersky said a Ukrainian news site for the city of Bakhumut was also hacked and used to distribute the ransomware to visitors, encrypting data on their machines.

A number of the internatio­nal firms hit have operations in Ukraine, and the virus is believed to have spread within global corporate networks after gaining traction within the country.

Shipping giant A.P. MollerMaer­sk, which handles one in seven containers shipped worldwide, has a logistics unit in Ukraine.

Other large firms affected, such as French constructi­on materials company Saint Gobain and Mondelez Internatio­nal Inc, which owns chocolate brand Cadbury, also have operations in the country.

Maersk was one of the first global firms to be taken down by the cyber attack and its operations at major ports such as Mumbai in India, Rotterdam in the Netherland­s and Los Angeles on the US west coast were disrupted.

The company said on Wednesday it was unable to process new orders and its 76 terminals around the world were becoming increasing­ly congested.

Other companies to succumb included BNP Paribas Real Estate , a part of the French bank that provides property and investment management services.

“The internatio­nal cyber attack hit our non-bank subsidiary, Real Estate. The necessary measures have been taken to rapidly contain the attack,” the bank said on Wednesday.

Production at the Cadbury factory on the Australian island state of Tasmania ground to a halt late on Tuesday after computer systems went down.

Russia’s Rosneft, one of the world’s biggest crude producers by volume, said on Tuesday its systems had suffered “serious consequenc­es” but oil production had not been affected because it switched to backup systems.

 ??  ?? A computer screen cyberattac­k warning notice reportedly holding computer files to ransom, as part of a massive internatio­nal cyberattac­k, at an office in Kiev, Ukraine on June 27. A new and highly virulent outbreak of malicious data-scrambling software...
A computer screen cyberattac­k warning notice reportedly holding computer files to ransom, as part of a massive internatio­nal cyberattac­k, at an office in Kiev, Ukraine on June 27. A new and highly virulent outbreak of malicious data-scrambling software...
 ??  ?? Passengers use mobile phones in an undergroun­d in Kiev, Ukraine on June 28. The cyberattac­k ransomware that has paralysed computers across the world hit Ukraine hardest Tuesday, with victims including top-level government offices, energy companies,...
Passengers use mobile phones in an undergroun­d in Kiev, Ukraine on June 28. The cyberattac­k ransomware that has paralysed computers across the world hit Ukraine hardest Tuesday, with victims including top-level government offices, energy companies,...

Newspapers in English

Newspapers from Kuwait