Russian hackers are targeting Ukraine (again)

27 May, 2018, 06:24 | Author: Regina Silva
  • Russian hackers are targeting Ukraine (again)

It's persistent, modular, and delivered in several stages. This will redirect attempts by stage one of the malware to reinfect the device to an FBI-controlled server, which will capture the Internet Protocol (IP) address of infected devices, pursuant to legal process.

The malware also includes an auto-destruct feature that renders the malware and software on infected devices inoperable.

Researchers say that the VPNFilter-enabled botnet is capable of doing significant harm, including permanently disabling the hacked devices through a method known as "bricking", which could cause thousands of companies to immediately lose internet connection and therefore likely lose business.

The Stage Two VPNFilter malware module does not survive device reboots but relies on the Stage One module to re-download it when the user reboots (and inadvertantly cleans) his device.

"Sniffers included with VPNFilter collect login credentials and possibly supervisory control and data acquisition traffic". Stage 2 covers file collection, command execution, data exfiltration, and device management.

The FBI and Department of Homeland Security said in December 2016 that the Sofacy Group was connected to Russian intelligence services and government officials.

From a global standpoint we saw this malware pretty much distributed evenly across the planet.

Coming back to now infected routers, the devices belong to major companies, including TP-Link, NETGEAR, Linksys, and MikroTik.

Still, based on information provided by Cisco, the sinkholding doesn't automatically stop VPNFilter in its tracks.

"VPNFilter is an expansive, robust, highly capable, and unsafe threat that targets devices that are challenging to defend".

Traces of opioids found in mussels in Seattle bay
When humans ingest opioids like oxycodone , they ultimately end up excreting traces of the drugs into the toilet. It's just one of hundreds of pharmaceuticals that native mussels have absorbed from the waters of Puget Sound.


Boris Johnson takes call from prankster posing as Armenia PM
After congratulating the caller at the start of the call, Mr Johnson talks of developing UK-Armenia trade and investment links. A recording of the phone call, which happened last week, was. "Obviously this should not have happened", said a spokeswoman.


Tearful Salah forced off early in Champions League final
Madrid are going for their third consecutive Champions League title, an unprecedented achievement in the Champions League era. In the United States (US), the game can be watched live and on-demand with fuboTV (7-day free trial ).


Cisco said when it revealed VPNFilter that more than 500,000 devices in 54 countries-with a particular focus on Ukraine-had been compromised by the botnet.

The United States Justice Department shortly after announced seizing a domain used in the botnet campaign.

The VPNFilter malware responsible for the attack is particularly concerning as it contains code to steal website credentials and make the infected router unusable.

"While this isn't definitive by any means, we have also observed VPNFilter, a potentially destructive malware, actively infecting Ukrainian hosts at an alarming rate, utilizing a command and control infrastructure dedicated to that country", Talos wrote in a blog post on Wednesday. "Weighing these factors together, we felt it was best to publish our findings so far prior to completing our research".

The Cyber Threat Alliance, which Cisco is a member of, has briefed companies about the destructive malware, calling VPNFilter a "serious threat".

The U.S. government said late on Wednesday that it would seek to wrestle hundreds of thousands of infected routers and storage devices from the control of hackers who security researchers warned were planning to use the "botnet" to attack Ukraine. This challenge is augmented by the fact that most of the affected devices have publicly known vulnerabilities which are not convenient for the average user to patch.

This malware strain is incredibly complex when compared to other IoT malware, and comes with support for boot persistence (the second IoT/router malware to do so), scanning for SCADA components, and a firmware wiper/destructive function to incapacitate affected devices.

Just to be safe, Talos is recommending that owners and administrators of home or small office routers reset the devices and restore to factory default in order to clear potential malware.

But despite not having boot persistence, the Stage Two module is also the most risky, as it contains a self-destruct function that overwrites a critical portion of the device's firmware, and reboots the device.

Recommended:

  • Real Madrid captures 3rd straight Champions League title

    Real Madrid captures 3rd straight Champions League title

    Egypt play their first warm-up game ahead of the World Cup against Colombia on June 1 before facing Belgium on June 6. Told that it sounded like he was saying goodbye, Ronaldo said: "In the coming days you will have my answer".
    Qualcomm Introduces The Snapdragon 710 SoC

    Qualcomm Introduces The Snapdragon 710 SoC

    The Snapdragon 710 made its debut today, and Qualcomm touts that it'll bring high-end mobile features to mid-range products. The processor also offers new Wi-Fi features, Bluetooth 5 , Qualcomm Broadcast Audio, and Qualcomm TrueWireless Stereo Plus.
    PBS puts Roma instead of Real Madrid as Champions League finalist

    PBS puts Roma instead of Real Madrid as Champions League finalist

    After receiving treatment on the field, he came on for about a minute before going back to the ground and asking to be subbed off. Liverpool had nine shots with Salah on the pitch in Kiev and none in the remainder of the first half after he was subbed off.
  • Ramos Criticises UEFA For Staging 2018 UCL Final In Kiev

    It added: "We can't apologise to our customers enough about the situation they find themselves in". I go to practically all Liverpool games and I haven't missed a home game in almost four years".
    Hugh Grant Marries Anna Eberstein In London

    Hugh Grant Marries Anna Eberstein In London

    A wedding announcement for Eberstein and Grant was recently circulated in newspapers, the BBC reportedearlier this month. Hey, if the perennial bachelor is going to get married, at least he's going to sport some interesting jewerly.
    Modern Birds Impacted By Asteroid That Wiped Out Dinosaurs

    Modern Birds Impacted By Asteroid That Wiped Out Dinosaurs

    They also revealed that birds surviving the end of the Cretaceous period had long sturdy legs made for living on the ground. No trees meant no homes for flying birds, so they all died while their non-flying cousins survived on the ground.
  • Body of Missing Wichita Boy Believed to be Found

    Body of Missing Wichita Boy Believed to be Found

    Glass was found not guilty in May in an unrelated case accusing her of child endangerment involving her 1-year-old daughter. After doing a couple loads of laundry, watering plants, and cleaning her daughter's bottle, Glass made the children lunch.
    NASA Camera Melted During a SpaceX Rocket Launch, Photos Survived

    NASA Camera Melted During a SpaceX Rocket Launch, Photos Survived

    One of Ingalls's cameras, a Canon 5D worth several thousands of dollars, was burned to a crisp as a result of the Falcon launch. Still, much of the body looks like it's maybe (hopefully?) salvageable, depending on just how long it spent in the fire.
    Seized fentanyl sufficient to kill 26M folks, Nebraska police say

    Seized fentanyl sufficient to kill 26M folks, Nebraska police say

    According to the DEA's website, fentanyl is "30-50 times more potent than heroin and 50-100 times more potent than morphine". On Thursday Governor Ricketts celebrated four state troopers who made a Nebraska record drug bust earlier this year.
  • Utah Main Jailed in Venezuela Will Return to US

    Utah Main Jailed in Venezuela Will Return to US

    Mia Love , R-Utah, also lobbied on behalf of Holt and decried his poor treatment in prison. Holt's family says "we are grateful to all who participated in this miracle".
    Real Madrid topples Liverpool to win Champions League final

    Real Madrid topples Liverpool to win Champions League final

    The national station will be screening the final of the Champions League tonight between Real Madrid and Liverpool. Salah's absence in the second half will significantly diminish Liverpool's attacking threat.
    Warriors’ sloppiness catching up to them against physical Rockets

    Warriors’ sloppiness catching up to them against physical Rockets

    This is the same core of stars that has gone 16-1 at Oracle Arena during the playoffs since the start of last year's postseason. Game 6 is Saturday night in Oakland; a Game 7, if necessary, would be Monday night back in Houston .


Popular

Fulham defeat Aston Villa in Championship play-off final to reach Premier League
The task is quite simple for the two sides competing at Wembley Stadium on Saturday; win and you're back in the Premier League . Between them, they gladly hoovered up danger and it was only Grealish, the dancing Villa playmaker who Fulham failed to mute.

Utah hostage Josh Holt released from Venezuelan prison
In their statement, the Holt family said, "We thank you for your collaboration during this time of anguish. There has not been any official confirmation or comment from President Nicolás Maduro's government.

North and South Korean leaders hold surprise United States summit discussions
The POTUS cancelled the highly-anticipated meeting on Thursday after blaming " tremendous anger and open hostility " by Pyongyang. Pictures showed them shaking hands and embracing on the North Korean side of the Demilitarised Zone separating the two nations.

Liverpool, Real Madrid set to clash in Champions League title game
They were unsettled and imprecise with their passes and it allowed Liverpool to have the better of play in the first 15 minutes. She expressed her surprise with Salah's performance this season saying, "I think Mo Salah has impressed me the most".

Tottenham demand Man United star as part of deal for Toby Alderweireld
The Ukrainian club wanted £50m for Fred and were keen to get United involved in a bidding war to drive up the price even higher. Fred is quoted as saying by Metro: "There have been some advanced talks since January, when I nearly went to Man City.

Super-sub Bale earns Real third straight UCL crown
Salah's exit gave Real an immediate lift because they had been nervous and edgy up until that point in the game. Those injuries temporarily took the sting out of the game after an enthralling start, with Liverpool on top.

Russia Downplays Dutch-Led Investigation Into the Downing of MH17
We hold the Russian state and its leaders as ultimately responsible for the deaths of our family members. Of the 298 people of more than 30 nationalities killed, 196 were Dutch, 42 Malaysian and 27 Australian.

FBI, Justice Department Leaders Meet Over Trump Informant Allegations
Some of them were also upset with Obama for not making more of what the government knew about Russian campaign meddling in 2016. The president demanded the Justice Department investigate the accusations and turn over any relevant documents to Congress.

Utah man jailed in a Venezuela for two years to be released
She worked feverishly to bring attention to her son's incarceration, hosting rallies, fundraisers and doing media interviews. There has not been any official confirmation or comment from President Nicolás Maduro's government.

Trump praises IN teacher for 'action' IN school shooting
Steve Vedder, who lives across the street from Seaman, said the teacher moved into the Noblesville home in November. Indiana Governor Eric Holcomb, flying back from Europe, said in a statement that he was monitoring the situation.