Massive supply chain cyberattack on the horizon in Ukraine, according to police
Full article571 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The attack may come through another booby-trapped software update, according to a cryptic press release published Thursday by the Secret Service of Ukraine.
Ukrainian government authorities are warning of a “large-scale” cyberattack against local government agencies and private companies through the deployment of another booby-trapped software update, according to a cryptic press release published Thursday by the Secret Service of Ukraine (SBU).
“SBU notifies about preparing of a new wave of large-scale attack against the state institutions and private companies,” the release notes. “The SBU experts received data that the attack can be conducted with the use of software updating, including public applied software. The mechanism of its realization will be similar to cyber-attack of June 2017.”
The use of the word “realization” in the SBU’s statement has led some security researchers to believe the government is likely preparing, once again, for a destructive-style attack.
The SBU did not respond to a request for comment.
The ambiguous warning comes four months after a Russian hacking group, dubbed “Telebots” or “Sandworm Group” by security researchers, broke into a popular Ukrainian accounting software maker to infect the company’s update servers with destructive ransomware. For several weeks afterwards, whenever a user attempted to upgrade their software they would also download hidden, malicious computer code.
On June 27, millions of hidden logic bombs exploded, causing a rapid outbreak of “NotPetya” ransomware.
Products made by this Ukrainian accounting software firm, known as M.E.Doc, continue to be used by the country’s public and private sector. In the June 27 incident, multinational corporations with business ties to Ukraine, who had similarly installed the software, were caught up in the blast and lost millions of dollars due to disrupted business operations. Those corporations included American organizations.
The M.E.Doc incident is far from the only case of a group targeting a supply chain weakness to penetrate valuable organizations. For example, hackers were similarly able to corrupt the update mechanism behind a popular file cleaning tool named CCleaner to dispense custom backdoor implants into targeted technology firms.
The attackers in this case, according to some security researchers, may have come from hackers connected to the Chinese government.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ukraine-cyberattack-impending-petya-wannacry/