Leaked NSA tools were once again used in a global ransomware attack
Full article564 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A tool leaked by The Shadow Brokers was found to be used in the 'BadRabbit' attack.
Another global ransomware outbreak was powered with a leaked, fully operational NSA hacking tool that had been released by The Shadow Brokers, according to researchers with cybersecurity firms Cisco Talos, IB Group and Symantec.
The latest international ransomware incident occurred on Tuesday and primarily affected computers in Ukraine and Russia. Analysts studying malware samples connected to this event, dubbed “BadRabbit,” found Thursday that the carefully prepared attack contained an exploit known as “EternalRomance.”
Some researchers say the BadRabbit operation had been planned for months, dating back perhaps to as far as Feb. 2017, according to FireEye, or July 2017, based on digital evidence found by Kaspersky Lab.
EternalRomance is effective against older Microsoft operating systems, including Windows XP and Server 2003. It is used to remotely install a malicious payload onto a computer. The tool is just one component of a larger hacking framework, which in the BadRabbit case included techniques unassociated with any intelligence agency.
The findings are significant because they show, once again, the lasting impact and negative consequences of when government-sponsored cyber weapons land in the wrong hands. Even though EternalRomance is more than 4 years old and can only affected outdated systems, the exploit continues to be effective against a large number of computers and organizations.
BadRabbit is the third consecutive ransomware outbreak believed to have been launched with NSA tools attached. The first two, respectively known as WannaCry and NotPetya, affected far more computers in a greater number of nations. Researchers say WannaCry was the work of North Korean hackers while NotPetya is connect to a group known as “Telebot,” according to Czech cybersecurity firm ESET, which is associated with Russia.
Preliminary analysis suggests there may be some connection between BadRabbit and this Telebots group, according to ESET, IB Group and Kaspersky Lab.
CyberScoop previously confirmed, citing former U.S. intelligence officials, that the exploits shared by the group were in fact used by the NSA in the past. The counterintelligence investigation into The Shadow Brokers is ongoing.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/eternal-romance-bad-rabbit-nsa-ransomware/