Biodun Iginla, BBC News

Biodun Iginla, BBC News
Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Tuesday, May 28, 2019

BREAKING: Baltimore says it will not pay ransom after cyberattack


Baltimore city hall was targeted in a cyberattack
Baltimore city hall was targeted in a cyberattack Baltimore city hall was targeted in a cyberattack GETTY IMAGES NORTH AMERICA/AFP/File
ADVERTISING
Washington 
The US city of Baltimore, a victim this month of a cyberattack that paralyzed part of its computer network, will not pay a ransom to undo the damage, Mayor Bernard Young said Tuesday.
Hackers reportedly had demanded $100,000 in bitcoin, but Young told a news conference "I'm not considering" paying it.
ADVERTISING
"As a matter of fact, we are going to work with other cities, encouraging them not to pay either," he said.
Baltimore was the latest big US city, after Atlanta, Georgia and San Antonio, Texas, to be hit with a ransomware attack.
Smaller cities like Greenville, North Carolina and Allentown, Pennsylvania also have been targeted.
The Baltimore attack targeted the Microsoft Windows operating system, blocking city hall's computer system, online sales and real estate sales.
They used a malware known as "EternalBlue," developed by the Maryland-headquartered National Security Agency, The New York Times reported Saturday.
Leaked from the NSA, the hacking tool was posted on the internet in April 2017 by "Shadow Brokers," a hacking group that first surfaced in mid-2016.
- 'Smart virus' -
"This was a smart virus," said Young. "Anytime NSA do something they do it well, I just hope that they had the key so we can all get out of this."
Since the attack was discovered on May 7, the mayor's IT team has worked to restore the network with the help of state, federal and private sector experts, Young said.
"We're making progress on some of the programming piece. We are not there yet," he said, adding he could not say how long it would take.
He said since NSA was the origin of the malware, the city is seeking federal financial assistance to cover the cost of repairs.
But some experts say other malware known as "Robin Hood" was used in the attack, not "EternalBlue."
Robert Graham, of the cyber security firm Errata Security, said Microsoft provided its clients with a patch for "EternalBlue" in 2017.
"Going two years without a patch is gross malfeasance that's hard to lay at the NSA's feet," Graham said in a blog post.

Friday, May 25, 2018

BREAKING: FBI says Russians hacked hundreds of thousands of routers

May 25, 2018  23H:32  GMT/UTC/ZULU TIME
The FBI warned on Friday that Russian computer hackers had compromised hundreds of thousands of home and office routers and could collect user information or shut down network traffic.
FILE PHOTO: A man types on a computer keyboard in front of the displayed cyber code in this illustration picture taken on March 1, 2017. REUTERS/Kacper Pempel/Illustration
The U.S. law enforcement agency urged the owners of many brands of routers to turn them off and on again and download updates from the manufacturer to protect themselves.
The warning followed a court order Wednesday that allowed the FBI to seize a website that the hackers planned to use to give instructions to the routers. Though that cut off malicious communications, it still left the routers infected, and Friday’s warning was aimed at cleaning up those machines.
Infections were detected in more than 50 countries, though the primary target for further actions was probably Ukraine, the site of many recent infections and a longtime cyberwarfare battleground.
In obtaining the court order, the Justice Department said the hackers involved were in a group called Sofacy that answered to the Russian government.
Sofacy, also known as APT28 and Fancy Bear, has been blamed for many of the most dramatic Russian hacks, including that of the Democratic National Committee during the 2016 U.S. presidential campaign.
Earlier, Cisco Systems Inc (CSCO.O) said the hacking campaign targeted devices from Belkin International’s Linksys, MikroTik, Netgear Inc (NTGR.O), TP-Link and QNAP.
An FBI official told us at Reuters that the kinds of devices known to be affected by the hack were purchased by users at electronic stores or online.
However, the FBI was not ruling out the possibility that routers provided to customers by internet service companies could also be affected, the official added.
Cisco shared the technical details of its investigation with the U.S. and Ukrainian governments. Western experts say Russia has conducted a series of attacks against companies in Ukraine for more than a year amid armed hostilities between the two countries, causing hundreds of millions of dollars in damages and at least one electricity blackout.
CSCO.ONASDAQ
+0.03(+0.07%)
CSCO.O
  • CSCO.O
  • NTGR.O
The Kremlin on Thursday denied the Ukrainian government’s accusation that Russia was planning a cyber attack on Ukrainian state bodies and private companies ahead of the Champions League soccer final in Kiev on Saturday.
“The size and scope of the infrastructure by VPNFilter malware is significant,” the FBI said, adding that it is capable of rendering peoples’ routers “inoperable.”
It said the malware is hard to detect, due to encryption and other tactics.
The FBI urged people to reboot their devices to temporarily disrupt the malware and help identify infected devices.
People should also consider disabling remote-management settings, changing passwords and upgrading to the latest firmware.

Monday, February 12, 2018

Hackers hijack government websites to mine crypto-cash--analysis


Security breachImage copyrightGETTY IMAGES
by Tamara Kachelmeier and Biodun Iginla, BBC News Technology Analysts, San Francsisco
The Information Commissioner's Office (ICO) took down its website after a warning that hackers were taking control of visitors' computers to mine cryptocurrency.
Security researcher Scott Helme said more than 4,000 websites, including many government ones, were affected.
He said the affected code had now been disabled and visitors were no longer at risk.
The ICO said: "We are aware of the issue and are working to resolve it."
Mr Helme said he was alerted by a friend who had received a malware warning when he visited the ICO website.

Bitcoin rival

He traced the problem to a website plug-in called Browsealoud, used to help blind and partially sighted people access the web.
Texthelp, the company which makes the plug-in, confirmed that the product was affected for four hours by malicious code designed to generate cryptocurrency.
The cryptocurrency involved was Monero - a rival to Bitcoin that is designed to make transactions in it "untraceable" back to the senders and recipients involved.
The plug-in had been tampered with to add a program, Coinhive, which "mines" for Monero by running processor-intensive calculations on visitors' computers.
Once the plug-in was infected, it affected thousands of other websites in addition to the ICO's, which used it.
Presentational grey line

Analysis

Mining hardwareImage copyrightVICHAI
Image captionGenerating crypto-currencies involves lots of computer hardware
By Rory Cellan-Jones, BBC technology correspondent
The surge in value of Bitcoin and other cryptocurrencies hasn't escaped the attention of hackers looking to make a quick buck.
Mining, the process where new digital coins are created by solving complex mathematical problems, uses increasing amounts of computer processing power and that means big electricity bills.
All the better then if you can get other people's computers to do the job. The hackers do this by inserting software into websites which then means that, unbeknown to them, visitors' computers are put to work mining cryptocurrencies.
It seems that the Information Commissioner's site along with others run by the government were infected by crypto-mining code injected into some accessibility software they all use.
This kind of attack is becoming increasingly common and while it appears not to cause data loss or damage to systems, it does mean computers can run much more slowly.
Presentational grey line

'Serious breach'

Mr Helme said: "It's a very lucrative proposal. They infect one website and it infects close to 5,000.
"This was a very serious breach. They could have extracted personal data, stolen information or installed malware. It was only limited by the hackers' imaginations."
As well as the ICO website, the hacked script was found running on the site of the Student Loans Company, Barnsley Hospital and other websites in the UK and worldwide.
Martin McKay, chief technical officer of TextHelp, said: "In light of other recent cyber-attacks all over the world, we have been preparing for such an incident for the last year and our data security action plan was actioned straight away."
The company is commissioning a security review by an independent consultancy following the attack, he said.
Because the malware only runs while someone is actively visiting an infected site, there is no further risk to users' computers, Mr Helme added.
A National Cyber Security Centre spokesman said: "NCSC technical experts are examining data involving incidents of malware being used to illegally mine cryptocurrency.
"The affected service has been taken offline, largely mitigating the issue. Government websites continue to operate securely.
"At this stage there is nothing to suggest that members of the public are at risk."

Related Topics

More on this story

Related Internet links

The BBC is not responsible for the content of external Internet sites