Sun Sentinel Broward Edition

New cyber attack on themove from Europe to United States

- By Raphael Satter and Frank Bajak Associated Press

‘Ransomware’ locks up a computer with all-but-unbreakabl­e encryption, then demands a ransom for its release.

PARIS — A new and highly virulent outbreak of data-scrambling software caused disruption across theworld Tuesday. Following a similar attack in May, the fresh assault paralyzed some hospitals, government offices and major multinatio­nal corporatio­ns in a dramatic demonstrat­ion of how easily malicious programs can bring daily life to a halt.

Ukraine and other parts of Europe were hit particular­ly hard by the new strain of ransomware— malicious software that locks up computer files with all-but unbreakabl­e encryption and then demands a ransom for its release.

As the malware began to spread across the United States, it affected companies such as the drugmaker Merck and Mondelez Internatio­nal, the owner of food brands such as Oreo and Nabisco. But its pace appeared to slow as the day wore on.

The origins of the malware remain unclear.

Researcher­s picking the program apart found evidence its creators had borrowed from leaked National Security Agency code, raising the possibilit­y that the digital havoc had spread using U.S. taxpayerfu­nded tools.

“The virus is spreading all over Europe and I’m afraid it can harm the whole world,” said Victor Zhora, chief executive of Info safe IT in Kiev, where reports of the malicious software first emerged Tuesday.

In the U.S, a hospital in western Pennsylvan­ia said itwas dealing with a “widespread” cyberattac­k, but it did not immediatel­y release further details.

Security experts said Tuesday’s global cyberattac­k shares something in common with last month’s outbreak of ransomware, dubbed Wanna Cry: Both spread using digital lock picks originally created by the NSA and later published to the web by a still-mysterious group known as the Shadow brokers.

Security vendors including Bitdefende­r and Kaspersky said the NSA exploit, known as EternalBlu­e, is allowing malware to spread rapidly by itself across internal computer networks at companies and other large organizati­ons.

Microsoft issued a security fix in March, but Chris Wysopal, chief technology officer at the security firm Veracode, warned that would only be effective if 100 percent of computers on a company’s network were patched, saying that if one computer were infected, the malware could use a backup mechanism to spread to patched computers aswell.

Bogdan Botezatu, an analyst with Bitdefende­r, compared such selfspread­ing software, often called “worms,” to a contagious disease.

“It’s like somebody sneezing into a train full of people,” Botezatu said. “You just have to exist there and you’re vulnerable.”

Aside from its method of propagatio­n, the malware was different from WannaCry.

Botezatu said the new program appeared to be nearly identical to GoldenEye, itself a variant of a known family of hostagetak­ing programs known as “Petya.”

The motives of those behind the malware remain unknown.

Emails sent toan address posted to the bottom of ransom demands went unreturned. That might be because the email provider hosting that address, Berlin-based Posteo, pulled the plug on the account before the infection became widely known.

In an email, a Posteo representa­tive said it had blocked the email address “immediatel­y” after learning that it was associated with ransomware. The company added that it was in contact with German authoritie­s “to make sure thatwe react properly.”

The blocked address may make it difficult for hackers to capitalize on the digital havoc, but it may also complicate victims’ attempts to retrieve their data.

Without the hackers’ decryption key — or the discovery of someweakne­ss in the malware’s code — the encrypted data may stay scrambled for a long time yet.

 ?? ERDEM SAHIN/EPA ?? An engineer checks a may of a cyberattac­k threat Tuesday in Turkey. The attack may be tied to leaked NSA code.
ERDEM SAHIN/EPA An engineer checks a may of a cyberattac­k threat Tuesday in Turkey. The attack may be tied to leaked NSA code.

Newspapers in English

Newspapers from United States