HomeSecurityRansomware that hit Ukraine is being used as bait

Ransomware that hit Ukraine is being used as bait

The new data-wiping ransomware that affected Ukrainian networks on Wednesday, shortly before Russia's invasion of the country, was accompanied, in some cases, by a GoLang.

ransomware

See also: Ransomware: Victims pay but hackers come back for more

“ In many attacks that Symantec has investigated to date, ransomware was also deployed against affected organizations. As with data-wiping, scheduled tasks were used to deploy the ransomware ,” Symantec revealed

“It seems likely that the ransomware was used as a decoy or distraction from the data-wiping attacks. It bears some similarities to the previous WhisperGate attacks against Ukraine, where the data-wiping was disguised as ransomware.“

The ransomware bait also displayed a ransom note on compromised systems, with a political message that said, “The only thing we learn from the new elections is that we learned nothing from the old ones!”

The ransom note instructs victims to contact two email addresses, vote2024forjb@protonmail.com and stephanie.jones2024@protonmail.com, to get their files back.

See also: Ukraine: Ministry of Defense, Army and banks receive DDoS attacks

The data-wiping, dubbed HermeticWiper by SentinelOne 's principal threat researcher , Juan Andres Guerrero-Saade , carried out attacks on Ukrainian organizations and also ended up on systems outside Ukraine's borders.

Ukraine

Targets hit by data-wiping attacks also included financial and government contractors from Ukraine, Latvia and Lithuania, said Vikram Thakur, Technical Director at Symantec Threat Intelligence.

While the cyberattacks occurred yesterday, cybersecurity firm ESET noted that the HermeticWiper malware had a collection date of December 28, 2021, suggesting that the attacks were planned.

Symantec found evidence that attackers were gaining access to victims' networks much earlier, exploiting vulnerabilities in Microsoft Exchange as early as November 2021 and installing web shells before deploying the malware.

See also: More and more DDoS attacks demanding ransom

The malware uses EaseUS Partition Manager to destroy files on compromised devices before the computer reboots. As security researcher Silas Cutler, the data-wiping discards the device's Master Boot Record, rendering all infected devices unbootable.

This month's DDoS and malware attacks follow a press release from the Security Service of Ukraine (SSU) saying the country is the target of a "massive wave of hybrid warfare."

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS