Hackers are picky about their victims. They’ll target just about any group or organization, including the 2018 Olympics.
Cisco’s Talos Group recently identified a new strain of malware they’ve dubbed “Olympic Destroyer” which is wreaking havoc in Pyeong Chang’s computer networks and causing downtime to internal WiFi and television systems. This has impacted the games’ opening ceremonies, and stands an excellent chance of further disrupting the rest of the festivities.
Because the threat was only recently discovered, the Talos team’s initial assessment and report was spotty and short on details, but the group recently amended their initial findings. The results aren’t pretty, and the malware is seen as being both more dangerous and more advanced than originally thought.
The big three findings in the team’s amended report are as follows:
It’s Polymorphic – As the malware spreads, it collects new credentials from each machine it infects, adding these to its binary on the fly. Members of the Talos team had this to say about the behavior: “I have not seen a malware sample modify itself to include harvested creds before and I’ve been doing this stuff longer than I should admit. Polymorphic malware isn’t a new idea by itself, but I’ve never seen any examples of malware modifying itself to include harvested credentials.”
It Spreads Via The EternalRomance Exploit – This bit of information comes to us from the Windows Defender team. The mechanism by which Olympic Destroyer spreads is industrial grade, utilizing an exploit from the NSA leaked by the Shadow Brokers last year.
Finally, It Wipes Data – This is perhaps the most significant of the three updates to the Talos report. The malware has a data wiping mechanism built into it that it utilizes at every opportunity in an attempt to delete files on network shares. Since it only seems to target shared files, it’s not deleting items key to OS functionality. Even so, these shared files are important, and this is what’s causing operational disruptions.
More details will no doubt become available as the various teams researching Olympic Destroyer get a better understanding of what they’re looking at. The bottom line is, it’s a pretty advanced threat and will likely inspire copycats in the months ahead.
Google is poised to make an important change to its Chrome browser beginning in July 2018.
Image theft is one of the biggest problems on the internet. If you’re a photographer, you’ve almost certainly lost money because people find your work online and make a copy of it rather than paying for the right to use it.
There are big changes coming to MS Office which you need to be aware of, given how widely used “Office” is in most companies.
The latest Brand Finance Global 500 report out and contains some surprises this year.
Menlo Security just released their third annual “State of the Web” report and it’s not pretty. The headline finding is that 42% of the top 100,000 sites as ranked by Alexa are more dangerous than you think.
That smartwatch you’re wearing might save your life. Literally.
Microsoft is getting tough on so-called “registry cleaners”, and it’s about time. The company recently announced a planned change to Windows Defender (the anti-malware program that comes standard with every Windows installation). The change will see to the deletion of an increasing number of these registry cleaners. It’s a great move, and the company deserves credit for it, but there’s a catch. This type of software has been around for decades. So the move, as welcome as it is, comes very late in the game.
Sophos has released the results of their annual “State of Endpoint Security Today”, and it doesn’t paint a pretty picture. A full 54% of companies surveyed reported having been hit by a ransomware attack in 2017. Another 31% reported that they expect to be on the receiving end of such an attack in the near future.