Maersk IT systems infected with ransomware
twitter.com
twitter.com
I heard later a rumour that the reason the AV didn't pick it up was it was a 0-day (stuxnet derived before that was known) and it was literally targeting the SCADA systems on boats.. but that's also the plot of Hackers, so take that with a pinch of salt.
Anyway being the build/devops/tooling person on a project i burned 40 dvd's with eclipse and ubuntu and handed to them to the devs and they booted into Ubuntu and kept developing.
All was going fine until i got a telling off from the Corporate IT security team complaining that our unauthorised Ubuntu machines weren't running AV and so could be introducing viruses into the network.
Total facepalm.
Here it is... http://www.imdb.com/title/tt0750242/
An guess what the computer is called: I.R.A.C.
New Petrwrap/Petya ransomware has a fake Microsoft digital signature appended. Copied from Sysinternals Utils.
I was sitting next to someone who wanted didn't close his laptop immediately when notified, 1 minute later it was too late. Most of my colleagues went home, even if their laptop was not infected (also over de VPN) they are no allowed to start the machine. Some departments ask people to stay home tomorrow too. Those with MacBooks continue working. And externals.
In Rotterdam APM Terminals has shutdown.
The signature doesn't validate, and was simply copied from a published Microsoft application (something from sysinternals). You can do this at home right now by visiting Microsoft.com, downloading any signed application, and copying the signature verbatim onto your application.
>Russia, Ukraine, Spain, France - confirmed reports about #Petya ransomware outbreak. Good morning, America.
https://twitter.com/codelancer/status/879688596852101120
>Petrwrap/Petya ransomware variant with contact wowsmith123456@posteo.net spreading worldwide, large number of countries affected.
https://twitter.com/craiu/status/879689411419668480
Sample: https://twitter.com/benkow_/status/879692704724250628
Articles:
http://www.independent.co.uk/news/world/europe/ukraine-cyber...
https://motherboard.vice.com/en_us/article/qv4gx5/a-ransomwa...
https://github.com/0xswap/guides/blob/master/ransomware-tria...
Would be great if more people wanted to add to it.
One morning a colleague notices that a particular Windows share used by every EE in the multi-national company now contains encrypted files and generic request for ransom.
Highlight of the e-mail thread that followed: "<Name of another coworker whose account was used to encrypt files>, virus again?"
It almost looks like the virus has been slumbering in systems and today woke up.
'Petya sees you when you're sleeping
Petya knows when you're awake
Don't click the link in that email or IR gets no break'
the first link is:
https://blog.malwarebytes.com/threat-analysis/2016/04/petya-...
https://twitter.com/martijn_grooten/status/87970508635999846...
It's also unclear whether Maersk is hit by Petya variant everybody talks about.
A delay of a day is probably already enough to cause congestion in ports with further delays down the road.
We have the security posture of a wet sock.
The market is (weakly) starting to improve, though.
Last time (WannaCry) after the usual initial "you should update" choir, it seemingly came out that after all it was not as vulnerable as initially thought:
https://blog.kryptoslogic.com/malware/2017/05/29/two-weeks-l...
At least the computers running XP did not contribute to spread the malware in that case.