News

After WannaCry comes Petya. What do we know so far?

Posted: Wednesday, June 28, 2017

Author: Hannah Collier

With major institutions still reeling from last month’s WannaCry attack, a new ransomware threat known as Petya was reportedly spreading across the world last night affecting users in France, Russia, Spain, Ukraine and the United States.

So are these persistent, high-profile, global attacks our new reality? Utilize has previously offered advice on how best to protect your organisation against the threat posed by ransomware in blogs that include Utilize takes proactive measures to combat ransomware in 2017. This advice still stands but, for the time being, what specifically do we know – and what do we not yet know – about Petya?

What we know

  • Petya appears to be spreading via email with the subject “CV” or “Resume”. The message will contain a malicious Dropbox link pointing to an executable virus which, when run, delivers the payload.
  • According to the New York Times this morning, several private companies have confirmed they were affected by the attack, including US pharmaceutical giant Merck, Danish shipping company AP Moller-Maersk, the British advertising firm WPP, the French multinational Saint-Gobain and the Russian steel, mining and oil companies Evraz and Rosneft.
  • Infected systems appear to be displaying a red screen with the message: You became a victim of the PETYA RANSOMWARE. The harddisks of your computer have been encrypted with an [sic] military grade encryption algorithm. There is no way to restore your data without a special key. You can purchase this key on the darknet page shown in step 2.

What we don’t know

  • We do not yet know who is behind the attack. Several variations have been identified online but cybercriminals have so far succeeded in masking their identities.
  • How much bigger this attack will get. Cybersecurity researchers have confirmed that, like WannaCry, the ransomware infects computers using vulnerabilities in the central nerve of a computer, called a kernel, making it difficult for anti-virus products to detect.

Sonicwall customers already have a level of protection

SonicWall Capture Labs confirmed yesterday that they had started tracking a high number of Petya ransomware attacks against SonicWall customers. In a blog they confirmed the following:

“Petya as a malware payload is not new. In fact, we reported in the 2017 Annual SonicWall Threat Report that it was second only to Locky in the number of infections we noted last year. The good news for SonicWall customers that are using our security services is that we have had signatures for certain variants of Petya since March 2016. Then, in April 2017 Capture Labs analyzed and released protection for the Eternal Blue exploit that Shadow Brokers leaked from the NSA.

Read the full blog by SonicWall here: Locky, Then WannaCry, Now Petya. Is This The New Normal in Cyber Security?

If you have any questions or wish to review you’re your own IT security, please don’t hesitate to get in touch with a member of our team by calling 0333 006 9060.

Our web site uses cookies, including Google Analytics cookies, to better understand how you use our site. Read our Cookie Policy for more information including Google Options. By using our web site you accept our use of cookies as detailed in our Cookie Policy.