Ukraine suffered more data-wiping malware than anywhere, ever

Destruction of Ukraine

Celestino Arce/Getty Images

Amidst the tragic toll of Russia’s brutal and devastating invasion of Ukraine, the impact of the Kremlin’s long-running campaign of devastating cyberattacks against neighboring countries has often, understandably, been treated as an afterthought. But after a year of war, it is becoming clear that the cyberwar Ukraine has endured over the past year is in some ways the most active digital conflict in history. Never before on the planet have so many samples of data destruction code been targeted in his one year.

Before the one-year anniversary of the Russian invasion, cybersecurity researchers at Slovak cybersecurity firm ESET, network security firm Fortinet, and Google-owned incident response firm Mandiant predicted that by 2022, the number of “wiper” specimens in Ukraine would be much higher. independently discovered that many were found in More malware than any other year in Russia’s long-running cyberwar targeting Ukraine. This does not necessarily mean that Ukraine has suffered more from Russian cyberattacks than in years past. In 2017, a Russian military intelligence hacker known as Sandworm released his NotPetya worm, which is highly destructive. But the growing amount of destructive code suggests a new kind of cyber warfare with Russia’s physical invasion of Ukraine, and the pace and diversity of cyberattacks is unprecedented. .

Anton Cherepanov, Senior Malware Researcher at ESET, said:

Researchers say they are seeing Russian state-sponsored hackers launch an unprecedented type of data-destructive malware into Ukraine in the form of the Cambrian Explosion of wipers. They found samples of Wiper his malware that target not only Windows machines, but also Linux devices and less common operating systems such as Solaris and FreeBSD. From destroying partition tables used to clean up databases, to repurposing Microsoft’s SDelete command-line tool, to overwriting large amounts of files with junk data, they corrupted the code of the victim’s machine. I’ve seen samples written in different programming languages, using different techniques to .

Fortinet counted a total of 16 different wiper malware “families” in Ukraine over the past 12 months. This was him only one or two in the last few years, even in the height of cyber warfare, before Russia made a full-scale invasion. Derek Manky, Head of Fortinet’s Threat Intelligence Team, said: “This is another single-digit explosion.” That diversity, according to the researchers, reflects the sheer number of malware developers Russia has allocated to target Ukraine, or, in particular, as Ukraine strengthens its cybersecurity defenses. , could be a sign of Russia’s efforts to build new variants that can stay ahead of Ukrainian detection tools. .

Fortinet also found that the increased number of wiper malware samples hitting Ukraine may actually be causing a more global spread problem. With these malware samples appearing on the malware repository VirusTotal or even the open source code repository Github, Fortinet’s network security tools have detected other hackers reusing these wipers against targets in 25 countries around the world. said he did. “Once that payload is developed, anyone can pick it up and use it,” he says.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *