It was only a matter of time, as we've said before. WannaCry was just the beginning. All that was needed was a malicious element with sufficient skill and a larger budget to reuse the exploits in a much more aggressive campaign. That campaign is already upon us. Multiple sources indicate that the attack began in Ukraine, and despite its emphasis on infecting local networks, it spread quickly. Pharmaceutical companies, transport companies, legal firms, banks, food producers, and even the monitoring systems in Chernobyl were hit.
The Global Impact
The specialist media are still processing information, and we expect several updates in the coming hours, but we already have a robust base to know what happened. A new global ransomware campaign disrupted operations in more than 80 companies. Some of the names that circulated include pharmaceutical Merck, Mondelez International (Cadbury, Toblerone, Milka, Oreo, etc.), shipping giant Maersk, and several operators in Russia and Ukraine, including oil company Rosneft, steelmaker Evraz, state energy distributor Ukrenergo, and Boryspil International Airport. It has not yet been fully confirmed, but preliminary forensic analysis suggests it is a variant of the Petya ransomware. Like WannaCry, this build of Petya (also identified as PetyaWrap, GoldenEye, and Nyetya) uses the EternalBlue exploit; however, Kaspersky says it applies a second NSA-leaked exploit, EternalRomance.
Propagation and Ransom Demand
The primary method of propagation has not yet been identified, but the available evidence points to a Ukrainian accounting program called MeDoc, whose update system was hacked. Kaspersky and the Cisco Talos Group have not reached that point, although in the official post by researcher MalwareTech (the same one who discovered the WannaCry kill switch) we can find several references. Basically, the attackers want a payment of $300 in Bitcoins, and once made, victims need to send the "installation key" to an email address. That email uses the domain of a German provider, Posteo, who has already confirmed its blocking. That means affected users have no way to receive the decryption key and restore their files, so we must repeat the same recommendation as always: Do not pay.
Technical Differences from WannaCry
While there are plenty of reasons to compare this campaign with WannaCry, the technical differences are considerable. WannaCry concentrated its power on a small number of terminals and quickly got out of control, while this Petya variant attacked a large number of computers, then proceeded to infect internal networks (it barely needs one vulnerable terminal). It also has the ability to steal local credentials with the help of Mimikatz, and deepen its presence using PSExec, an official Microsoft tool. Once the infection has finished, the ransomware can wait between 10 and 60 minutes to restart the computer. Most sources agree that this campaign is much more refined. There is no magic kill switch to disable it, and it seems more focused on causing damage than on collecting (it only got $6,000). Images of the ransomware have been seen in ATMs, but CNN made the most disturbing report, reporting that the automatic radiation monitoring system at the Chernobyl nuclear plant was hit. Authorities will continue monitoring manually until further notice.
How to Protect Yourself
For now, the only way to avoid the ransomware is to interrupt the encryption process. If your computer restarts spontaneously and displays a message indicating that the file system is being repaired (very similar to the classic CHKDSK), turn it off completely. We will keep you informed.
MalwareTech