Microsoft said late Saturday that dozens of computer systems at an unspecified number of Ukrainian government agencies have been infected with destructive malware disguised as ransomware, a disclosure suggesting an attention-grabbing defacement attack on official websites was a diversion. The extent of the damage was not immediately clear.
The attack comes as the threat of a Russian invasion of Ukraine looms and diplomatic talks to resolve the tense stand-off appear stalled.
Microsoft said in a short blog post that amounted to the clanging of an industry alarm that it first detected the malware on Thursday. That would coincide with the attack that simultaneously took some 70 government websites temporarily offline.
The disclosure followed a Reuters report earlier in the day quoting a top Ukrainian security official as saying the defacement was indeed cover for a malicious attack.
Separately, a top private sector cybersecurity executive in Kyiv told The Associated Press how the attack succeeded: The intruders penetrated the government networks through a shared software supplier in a so-called supply-chain attack in the fashion of the 2000 SolarWinds Russian cyberespionage campaign targeting the U.S. government.
Recommended
Microsoft said in a different, technical post that the affected systems "span multiple government, non-profit, and information technology organizations.” It said it did not know how many more organizations in Ukraine or elsewhere might be affected but said it expected to learn of more infections.
"The malware is disguised as ransomware but, if activated by the attacker, would render the infected computer system inoperable," Microsoft said. In short, it lacks a ransom recovery mechanism.
Microsoft said the malware "executes when an associated device is powered down," a typical initial reaction to a ransomware attack.
Microsoft said it was not yet able to assess the intent of the destructive activity or associate the attack with any known threat actors. The Ukrainian security official, Serhiy Demedyuk, was quoted by Reuter s as saying the attackers used malware similar to that used by Russian intelligence. He is deputy secretary of the National Security and Defense Council.
A preliminary investigation led Ukraine’s Security Service, the SBU, to blame the web defacement on "hacker groups linked to Russia’s intelligence services.” Moscow has repeatedly denied involvement in cyberattacks against Ukraine.
Tensions with Russia have been running high in recent weeks after Moscow amassed an estimated 100,000 troops near Ukraine's border. Experts say they expect any invasion would have a cyber component, which is integral to modern "hybrid" warfare.
Demedyuk told Reuters in written comments that the defacement “was just a cover for more destructive actions that were taking place behind the scenes and the consequences of which we will feel in the near future." The story did not elaborate and Demedyuk could not immediately be reached for comment.
Oleh Derevianko, a leading private sector expert and founder of the ISSP cybersecurity firm, told the AP he did not know how serious the damage was. He said also unknown is what else the attackers might have achieved after breaking into KitSoft, the developer exploited to sow the malware.
In 2017, Russia targeted Ukraine with one of the most damaging cyberattacks on record with the NotPetya virus, causing more than $10 billion in damage globally. That virus, also disguised as ransomware, was a so-called "wiper" that erased entire networks.
Ukraine has suffered the unfortunate fate of being the world’s proving ground for cyberconflict. Russia state-backed hackers nearly thwarted its 2014 national elections and briefly crippling parts of its power grid during the winters of 2015 and 2016.
In Friday’s mass web defacement, a message left by the attackers claimed they had destroyed data and placed it online, which Ukrainian authorities said had not happened.
Recommended
The message told Ukrainians to "be afraid and expect the worst."
Ukrainian cybersecurity professionals have been fortifying the defenses of critical infrastructure since 2017, with more than $40 million in U.S. assistance. They are particularly concerned about Russian attacks on the power grid, rail network and central bank.
- Risk of Malware Attack on Android Devices 100 Times Higher Than iPhone
- Hackers employ new malware attacking gov't entities
- New strain of ransomware cripples networks
- Over 60 countries hit by huge cyberextortion attack
- Dozens of countries hit by huge cyberextortion attack
- Global cyber attacks shut down thousands of computers
- Phl except gov't 'relatively safe' from cyber attacks
- Microsoft adds new protection for ransomware amid global cyber attack
- [BIG QUESTION] Who Is Really Behind The Great Sony Hack Attack?
- NKorea link emerges in global cyber attacks
- Microsoft blames Russia-linked hackers for recent email hack attacks on Windows
- Microsoft joins list of companies recently hacked
- Experts, Microsoft push for global NGO to expose hackers
- Pro-Russia police help foil Ukraine crackdown in east
- Global cyberattack seems intent on havoc, not extortion
- Cybersecurity is a $81.7 billion market — and startups are raking in the dough
- Cyberattack cost Maersk as much as $300M
- A key American defense has failed, and now Russia fears no reprisal for hacking the US
- Google asks to publish more US gov't information
- Ransomware hits ‘hundreds of thousands’ of China PCs
![]() | ![]() | Anime Comic Cartoon Attack On Titan Ipod Touch 5th Case5.0★ / check it now at Amazon | Anime Comic Cartoon Attack On Titan Ipod Touch 4th Case5.0★ / check it now at Amazon | Shingeki No Kyojin Attack on Titan Collectible Anime Pocket Black Watch4.7★ / check it now at Amazon | ![]() | ![]() | 7 Weapons Shingeki No Kyojin Attack on Titan Pocket Watch#34.6★ / check it now at Amazon | BestFyou® Anime Watch Wrist Watch with Cool Led Attack on Titan5.0★ / check it now at Amazon | ![]() | ![]() | Sky Buddy Anime Attack on Titan Wing of Freedom Cut-out Analog Watch with Money Box Design Packing Box4.0★ / check it now at Amazon | ![]() | ![]() | Shingeki no Kyojin Attack on Titan Cosplay Scouting Legion Watch New in Box3.8★ / check it now at Amazon | ![]() | Shingeki no Kyojin Attack on Titan Scouting Legion LED Touch Screen Watch5.0★ / check it now at Amazon | Shingeki no Kyojin Attack on Titan Scouting Legion Cosplay Costume Anime Watch Led Watch Black #B CoSmile4.0★ / check it now at Amazon | Attack on titan led wrist watch White #A3.0★ / check it now at Amazon | ![]() | Attack on Titan Scouting Legion Iphone 4 Case Iphone 4s Case3.8★ / check it now at Amazon | ![]() | ![]() | ![]() | Verizon Rapid Car Charger for Samsung Galaxy S4 and Note2 - OEM Micro USB (Works for the S4 on all wireless networks)3.7★ / check it now at Amazon | ![]() | Shingeki No Kyojin Attack On Titan Mikasa Ackerman 06 Anime Gaming Mouse Pad4.2★ / check it now at Amazon | ![]() | ![]() | ![]() | Onelee(TM) - Attack On Titan Manga Anime Comic iPhone 6 Case & Cover - iPhone 6 Case5.0★ / check it now at Amazon | ![]() | ![]() | ![]() | Shingeki no Kyojin Attack on Titan Manga Anime Comic Apple iPhone ipod touch4 TPU Soft Black or White case (Black)1.0★ / check it now at Amazon | ![]() | ![]() | ![]() | Samsung Galaxy S6 (Not Edge) Attack on Titan Manga Mikasa Ackerman Case Cover (#12 Black)5.0★ / check it now at Amazon | ![]() | ![]() | Attack on Titan Anime 3.5mm Headphones3.5★ / check it now at Amazon | Fanstown attack on titan iphone5/5s case scratch proof TPU cell phone case check it now at Amazon | ![]() | ![]() | Fincibo (TM) Microsoft Lumia 640 Snap On Protector Cover Case - Purple check it now at Amazon | ![]() | ![]() | ![]() | ![]() |
Microsoft discloses malware attack on Ukraine govt networks have 1773 words, post on www.independent.co.uk at January 16, 2022. This is cached page on USA Breaking News. If you want remove this page, please contact us.