BadRabbit: blackmailer software spreading in Russia and Ukraine

A new Ransomware named BadRabbit has hit Ukrainian companies and several Russian media. The first cases of infection are allegedly also in Germany.

BadRabbit: blackmailer software spreading in Russia and Ukraine

There is a new Ransomware in Russia and Ukraine. As IT security company Kaspersky has shared, about 200 targets are affected by Blackmailer software BadRabbit in se two countries as well as in or European countries, including Germany and Turkey.

BadRabbitwar showed up on Tuesday. The software infects computers by visiting manipulated websites, disguises itself as an alleged installation file for Adobe Flash and locks data and access for users, who are n asked to pay money to get back access. The ransom is 0.05 bitcoin, current price is about 230 euros. Affected persons are directed to a page called BadRabbit in Tor network, hence name.

Accordingly, information system at Odessa airport was affected on Tuesday afternoon, but flights were scheduled. Also affected were electronic systems of Metro in capital Kiev and computers of Ukrainian Ministry of Infrastructure. The domestic intelligence SBU shared that situation was under control. However, ministry's website was still unavailable on Wednesday morning.

Malware What is Ransomware?

malware is a generic term that identifies software that is harmful. Ransomware is a type of malware that primarily takes over computers and prevents users from entering data until y pay for it. The name is derived from English ransom, which means "ransom" .

How is computer infected?

Most of time, Ransomware computer through links or attachments in harmful emails, also known as Phishing. Once users click on malicious link or attachment, malicious software will be accessed on computer.

What happens n?

The software takes data quasi as a hostage by encrypting it. For encryption , it uses a key that only attacker knows. If user does not pay ransom, files are often lost forever.

Attackers often give very precise instructions on how user can pay money. Many of hackers first demand between 300 and 500 dollars in Bitcointo decrypt files again. Over time, amount can rise. Prosecutors advise against paying.

How can you protect yourself?

There is no perfect solution. However, risk of being affected can be reduced: users should regularly back up ir data and install Sicherheitsupdates as soon as y are published. In addition, you should pay attention to bad emailsthat are often disguised as mails from companies or people who often have e-mail contacts. It is important not to click on any links or attachments. (Source: AP)

In addition, almost all services of Russian news agency Interfax were paralysed by malware. Only partially could agency resume its work on Wednesday, said deputy director General Alexei Gorshkov. The independent Russian news portal Fontanka from St. Petersburg was also affected and journalist, attack had to do with critical reports about Russia's deployment in Syrian civil war. In turn, authorities in Russia and Ukraine rejected this.

"With all due respect for large media corporations, but y are not critical infrastructure," said Telecommunications minister Nikolai Nikiforov. The cybercrime department at Ukrainian police teilteebenfalls that it is not a "targeted attack".

The US Homeland Security Ministry meanwhile issued a warning to BadRabbiraus and called on users not to respond to requests for money, since even n return of data was not secured.

Date Of Update: 26 October 2017, 12:04
NEXT NEWS