HomeSecurityPetya/Notpetya. The ransomware “mutated” into a wiper (?)

Petya/Notpetya. The ransomware “mutated” into a wiper (?)

Ransomware or Wiper: The recent Petya/Notpetya malware attack that hit dozens of countries around the world this week seems to be taking an interesting turn. Security experts are increasingly coming to the conclusion that NotPetya is not a conventional ransomware. Rather, they say, it is a sabotage tool.

Ransomware

Companies and organizations affected by the cyberattack, in Ukraine, Russia, the US, as well as other countries in Europe, Asia and Australia, would never be able to recover their data.

WannaCry, while devastating, was a flawed tool created by amateurs. Petya, according to experts, is not an amateur tool but a powerful ransomware that can infect any version of Windows. (Including Windows 10).

On the other hand:

Several researchers and security companies, including Kaspersky, believe that the malware that invaded computers was simply disguised as ransomware.

The malware took advantage of the "noise" that WannaCry managed to create , which acted as "bait" for the media.

And while its developers tried to make it look like ransomware, researchers point out that it is actually a “wiper,” since it erases sections that a disk needs to run.

So, based on the claims of security researchers, even if the required liters are paid, the victims' disk cannot be recovered.

This is because NotPetya generates a random infection ID for each computer. A ransomware that does not use a C&C server, like NotPetya, uses the infection ID to store information about each infected computer, along with the decryption key.

Because NotPetya generates random data for this identifier, the decryption process is impossible, says Kaspersky.

“What does this mean? First of all, this is the worst news for victims – even if they pay the ransom they will not get their data back. Second, this reinforces the theory that the attack is not driven by financial motives, but destructive ones,” Ivanov adds.

[su_note note_color=”#e8eed6″ text_color=”#494134″ radius=”1″]How Petya/NotPetya works and spreads. How can we protect ourselves.[/su_note]

Ransomware, Wiper or something else?

Kaspersky says that over 60 percent of the attacks took place in Ukraine. Russia is second on the list with 30 percent. And these are just the initial findings of the company's ongoing research.

Initial analyses are slowly being refuted and the story seems to be taking a completely different turn. More and more researchers believe that this is a generalized cyberattack, possibly with political criteria. However, they point out that NotPetya is not ransomware, but a malicious software that wipes systems, destroying files.

MalwareTech, however, seems to disagree with this approach, claiming that the software only destroys the first 25 sections of the disk.

As the researchers rightly state:

"These disk sectors are necessary, but they are also empty in standard Windows installations. It's a little hard to believe that cybercriminals didn't know this."

MalwareTech researchers agree, however, that the hackers were not motivated by financial gain.

Ransomware Who is behind the attack?

And while researchers continue their analysis, the questions that now arise are “Who did it?” and “Why?”

We don't have an answer to that at the moment. But Ukrainian government security companies and agencies believe that what happened was a government-sponsored attack. This particular attack was intended to cause damage to Ukrainian institutions.

When asked if he believes Russia is behind all this, the head of Ukraine's Center for Cyber ​​Protection replied:

"It's hard to imagine anyone else who would want to do this.".

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS