Yesterday saw another global Ransomware attack hit the headlines. Named NotPetya, within the security community, due to this sophisticated malware masquerading as an existing Ransomware variant (Petya) from 2016. Behaving like most Ransomware attacks and initially considered a new strain of WannaCry, by those hasty for headlines, due to the combination of previously used (and patched) exploits within its payload.
Financial reward is not the primary goal associated with this attack. In reality, this was a destructive malware attack, launched in Ukraine via multiple attack vectors (a compromised software update and the low cost Phishing emails) with sophisticated deniability i.e. behaving like Ransomware. We know that the cryptocurrency Bitcoin demand for $300 and the single wallet and email payment mechanism was much less sophisticated than the typical ‘ransomware as a service’ created and distributed by organised cyber-crimes groups.
Like most destructive attacks over the last few years, the soft target is the Master Boot Record (MBR), a small file vital for booting your Windows operating system. The NotPetya payload exploits the MBR to encrypt the Master File Table after 1hr on the host machine. This process is disguised as a CHKDISK routine, only up to this point (prior to the reboot) are your files are recoverable! During the 1hr time bomb this malware will move laterally across your network via legacy network protocol taking advantage of an old exploit, unless patched. It can also spread via a Windows administration function PsExec to default admin$ shares, even on patched machines, stealing local admin credentials.
Things to consider; it’s highly likely that further combinations of destructive malware notwithstanding ransomware variants will utilise this modus operandi in the future.
- Create a file call perc in the C:\Windows folder and make it read only
- Protect your Mast Boot Record (MBR) with an Open Source MBR filter from Cisco Security
- Sure you are not infected, look for two rundll32.exe files running on your machine
- Consider preventing your machines from rebooting following a system crash
- Apply the Windows patch released on the 14th March (this will not help those machines already compromised)
- Prevent this type of malware from communicating on your network, block inbound traffic on SMB (ports 139, 445).
- Consider disabling PowerShell
- Review the need for local privileges admin accounts for peer-to-peer infection vectors
Best practice guidance:
- Review your backup strategy, back up your data and key platforms regularly. If you become a ransomware victim, restore your files from a backup instead of paying the ransom
- Test your backup process. Practice recovery of backups and enterprise data centric platforms, which are at high risk to you
- Install patches and updates immediately, subject to your patch testing processes. Many victims of ransomware are using outdated or unprotected operating systems
- Install strong anti-virus and anti-malware software and keep it updated with the latest virus and malware definitions
- Educate your staff about Cyber hygiene and Phishing awareness, they will be the gateway for a future cyber-attack on your business
- Take care when clicking links in emails
- Exercise extreme caution when opening any email attachment. Think before you click!
- Take an extra moment to check unexpected emails you receive — even from trusted sources.
Richard Beck is Director of Cyber at QA. He works with customers to build effective and successful learning solutions tailored for business needs, helping to solve business problems. Richard has designed and architected numerous enterprise and nationwide cyber programmes for QA customers. Responsible for the QA cyber portfolio, products, proposition and cyber partner community. He has over 15 years' experience in senior Information Security roles.
Prior to QA, Richard was Head of Information Security for an organisation who underpin 20% of the UK's Critical National Infrastructure. Richard also held Security and Technical Management posts in Defence, Financial Services and HMG. He holds a number of leading cyber professional certifications, including CISSP, CISM, CISA.
Richard sits on a number of industry boards and security advisory panels, and previously chaired the Communication Industry Personnel Security Information Exchange (CPNI). He is the work stream lead for Cyber Skills & Diversity on the techUK Cyber Management Committee, in addition Richard is also supporting a work stream for the UK Cyber Security Council Formation project. Richard is a regular contributor for cyber insights and industry collaboration including speaker engagements.
He is also a STEM Ambassador working to engage and enthuse young people in the area of cyber security. Providing a unique perspective on the world of cyber security to teachers and encourage young people to consider a career in cyber security.
More articles by Richard
CISOs should prioritise the “human firewall” during Covid-19
Cyber Pulse: Edition 141 | 11 January 2021
Cyber Pulse: Edition 140 | 4 January 2021
Cyber Pulse: Edition 139 | 18 December 2020
Cyber Pulse: Edition 138 | 8 December 2020
Cyber Pulse: Edition 137 | 13 November 2020
Cyber Pulse: Edition 136 | 5 November 2020
Cloud Native Security – Accelerate Left or Get Left Behind
Cyber Pulse: Edition 135 | 27 October 2020
Cyber Pulse: Edition 134 | 21 October 2020