Call & Times

Malware, described in leaked documents, cripples computers

- By CRAIG TIMBERG

Hackers unleashed an attack that disabled computers in dozens of nations Friday using a software flaw that once was part of the National Security Agency's surveillan­ce tool kit.

The resulting wave of online chaos affected tens of thousands of machines worldwide, snarling operations at the Russian Interior Ministry, Spanish telecommun­ications giant Telefónica and Britain's National Health Services (NHS), where hospitals were hobbled and medical procedures interrupte­d.

Europe, Latin America and parts of Asia were hit particular­ly hard, although in the United States, FedEx also reported falling prey to the malware. The attack was the latest in a growing menace of "ransomware," in which hackers deliver files to computers that automatica­lly encrypt their data, making it unusable – until a ransom is paid.

"This is not targeted at the NHS," British Prime Minister Theresa May told reporters. "It's an internatio­nal attack, and a number of countries and organizati­ons have been affected."

The hack renewed a longrunnin­g debate about the dangers of intelligen­ce agencies such as the NSA collecting and using software flaws for espionage, rather than quickly alerting companies to vulnerabil­ities so they can fix them.

In this case, the NSA found a flaw in Microsoft software that made the hack possible. The agency reported the flaw to company after a security breach was discovered in August, according to former U.S. officials speaking on the condition of anonymity due to the sensitivit­y of the topic.

Microsoft fixed the problem in a patch it released in March, before a group calling itself the "Shadow Brokers" publicly released it online in April.

But system administra­tors appear to have applied the patch inconsiste­ntly, leaving some computers vulnerable. The vulnerabil­ity gave the hackers what amounted a lock pick to the Microsoft software on computers that did not receive the update from the company or that used outdated operating systems.

It was not clear who was behind the campaign, which, experts said, was the first known time a hacker group used the NSA tools released by the Shadow Brokers to conduct a large-scale hack.

"These attacks underscore the fact that vulnerabil­ities will be exploited not just by our security agencies but by hackers and criminals around the world," the American Civil Liberties Union, a frequent NSA critic, said in a statement.

The NSA did not respond to requests for comment, but some experts expressed sympathy for the agency because it had warned Microsoft about the problem.

Peter Eckersley, technology projects director for the Electronic Frontier Foundation, a San Franciscob­ased civil liberties group that has sharply criticized the NSA for its aggressive surveillan­ce, said: "In this instance, it's a little unfair to blame the NSA. They could have been following the best possible defensive practices, and this probably would have gone down the same way."

Powerful NSA hacking tools have been revealed online

But the speed and scale of the malware spread startled experts. "It's one of the first times we've seen a large internatio­nal global campaign," said Chris Camacho, chief strategy officer for Flashpoint, a cyber-intelligen­ce company. "It's pretty shocking. This morning people woke up thinking it was only in Europe. Now it's hitting countries around the world. It's global."

Cybersecur­ity experts said that the malware arrived through "phishing" attacks in which recipients of emails were tricked into opening phony links. Once one computer in a system was infected, the malware spread to other machines on the same network. In some cases, the malware was delivered in spam emails.

The ransomware spread so quickly because it was delivered by a special digital code developed by the NSA to move from one unpatched computer to another, security experts said. They warned that the malware now could move from large networks to individual users.

Newspapers in English

Newspapers from United States