Why Africans should be worried about PETYA 0 878

  • The malicious software has been identified as a modified version of a previously known ransomware, called Petya or Petrwrap, that has been substantially altered.
  • Due to its unique characteristics, it has been dubbed as NotPetya and ExPetya, which is currently detected by ESET as Win32/Diskcoder.C Trojan.
  • NotPetya can be termed as a worm, which can self-replicate across multiple networks. Petya uses two primary methods to spread across networks. Execution across network shares and SMB exploits
  • The current global ransomware trend utilises the EternalBlue Exploit in order to take advantage of the vast use of the Windows Operating System.
  • More than 80% of enterprise servers and endpoints in the African Digital Economy run on the Windows Operating System.
africans-worried-petya

It all begins with the MS17-010 Exploit

The EternalBlue Exploit, otherwise known as MS17-010, developed by the NSA and pilfered by the Shadow Brokers continues to open opportunities for malicious malware authors as fresh ransomware attacks continue to ravage Europe while spreading through the globe at an alarming pace.

Notably, it has become evident that in the realm of cybersecurity, the adage of once bitten, twice shy, seldom applies as unpatched computer systems have been utilised for a second time by cybercriminals to achieve exponential infection rates, reminiscent of the WannaCry nightmare that the globe experienced only two months ago.

NotPetya

The malicious software has been identified as a modified version of a previously known ransomware, called Petya or Petrwrap, that has been substantially altered, prompting a debate among researchers over whether it is new malware.

Due to its unique characteristics, it has been dubbed as NotPetya and ExPetya, which is currently detected by ESET as Win32/Diskcoder.C Trojan. If it successfully infects the MBR (Master Boot Record), it will encrypt the whole drive itself. Otherwise, it encrypts all files, like Mischa.

How does NotPetya replicate?

In many ways, NotPetya can be termed as a worm, which can self-replicate across multiple networks. Petya uses two primary methods to spread across networks. These include:

  • Execution across network shares: It attempts to spread to the target computers by copying itself to [COMPUTER NAME]\\admin$ using the acquired credentials. It is then executed remotely using either PsExec or the Windows Management Instrumentation Command-line (WMIC) tool. Both are legitimate tools.
  • SMB exploits: It attempts to spread using variations of the EternalBlue and EternalRomance exploits.

Crucially, NotPetya seeks to gain administrator access on a machine and then leverages that power to commandeer other computers on the network: it takes advantage of the fact that far too many organizations employ flat networks in which an administrator on one endpoint can control other machines, or sniff domain admin credentials present in memory, until total control over the Windows network is achieved. It achieves primary access through using phishing techniques to trick administrators into running the malware with high privileges.

What institutions have been adversely affected?

africans-worried-petya

The most severe damage is being reported by Ukrainian businesses, with systems compromised at Ukraine’s central bank, state telecom, municipal metro, and Kiev’s Boryspil Airport. Systems were also compromised at Ukraine’s Ukrenego electricity supplier, although a spokesperson said the power supply was unaffected by the attack. The attack has even affected operations at the Chernobyl nuclear power plant, which has switched to manual radiation monitoring as a result of the attack.

Infections have also been reported in more isolated devices like point-of-sale terminals and ATMs. The virus has also spread internationally. The Danish shipping company Maersk has also reported systems down across multiple sites, including the company’s Russian logistics arm Damco.

The virus also reached servers for the Russian oil company Rosneft, although it’s unclear how much damage was incurred. There have also been several recorded cases in the United States, including the pharmaceutical company Merck, a Pittsburgh-area hospital, and the US offices of law firm DLA Piper.

The attacks have been indiscriminate across every vulnerable vertical as institution after institution falls short against the unique threat posed by NotPetya.

Why Africans should be concerned about the current global ransomware trend

The current global ransomware trend, of utilising the EternalBlue Exploit in order to take advantage of the vast use of the Windows Operating System should send chills down the spines of any executive worth his salt in the African Digital Market for the following reasons.

Firstly, more than 80% of enterprise servers and endpoints in the African Digital Economy run on the Windows Operating System, thus exposing majority of our organisations to the next-generational strains of ransomware being designed by savvy malware authors. Moreover, a significant percentage of these Windows systems are run on legacy platforms such as XP and Windows Vista which exponentially increase the probability that these systems are probably unpatched.

Secondly, there is an astounding number of citizens who are unaware of the cybersecurity risks present within their daily lives. Kenya, serves as a key example to the plight of the African digital economy. With an 85.3% internet penetration rate, Kenya boasts a wealth of 37.7m netizens, actively contributing to their digital ecosystem.

Moreover, due to the proliferation of mobile banking, internet banking continues to rise within the region. However, contrary to logical perception, about 90% of Kenya’s netizens remain unaware of the increased cyber risks within their digital market. This poses a unique and advanced risk as ransomware’s primary source of entry is through A

In conclusion, new strains of ransomware seem to tactically replicate across networks utilising unpatched Windows systems and untrained company personnel through phishing e-mails to wreak havoc across targeted networks. The African Digital Economy is especially vulnerable to these risks as they exploit our unique weaknesses.

Our recommendations:

  1. Invest in new-school cybersecurity awareness training.
  2. Deploy reputable endpoint protection.
  3. Strengthen your business continuity capabilities.
  4. Evaluate and Patch Installed Software.
  5. Monitor access rights.
Previous ArticleNext Article

Safer Internet Day 2019 0 205

Working together with your children for a better online experience

Beginning in 2004, Safer Internet Day has grown to become one of the landmark events in the online safety calendar. And this year’s theme, ‘Together for a better internet’, encapsulates a lot of the discussion we are seeing around online safety and cybersecurity. The topic is too complex a minefield for any of us to bear sole responsibility and, like all good things in life, we need to work together to bring about the best possible future.

What does it mean to work together where online safety is concerned? It could be an IT security company working closely with a consultation of parents to develop products, or parents and teachers working to ensure the online education of our young people. But what about children themselves? We put a lot of onus on finding the right solutions and products to protect our kids online, but one day those kids will grow up and live without online parental control. We should think about the best way to prepare them; ‘together for a better internet’ should mean working with our children to educate, inform and protect them, so they can stand the best possible change of making the right decisions for themselves.

That’s not to say that software doesn’t play a crucial role, and ESET would encourage all parents to take care over choosing the right parental control software on the family computer. When you are doing this though, we advise you do it together with your kids. Talk them through the programmes you’re installing and select your privacy settings together, discussing why you are doing it and the kinds of threats you’re protecting the family against. As part of this conversation you can talk to your children about what they’re doing online, who they’re talking to and what kinds of things they need to be careful about in day to day online. Many kids see control settings on the internet as a block to them having fun; what they need is someone to explain their function and reasoning. By having this discussion, you’re giving your kids an element of control and responsibility over their online activities which, when paired alongside the rules and software we all need to protect ourselves, should produce better results when it comes to their internet education.

The internet is such an integral part of our lives that the earlier you start talking to kids, involving them and teaching them about their online worlds, the better the results. Creating an open dialogue will always be more effective than just putting your foot down.

Set an example; whatever you expect your kids to do, make sure you are also doing. The online world represents dangers for all of us and we can all benefit from a few more precautions. If you’re asking your kids to cover their webcam when they’re not using it, then make sure you also do it. If you’re restricting their screen time, then think about setting yourself some boundaries as well. With the damaging effects of too many screens on our health and wellbeing, it’s unlikely to have any negative repercussions.

ESET’s software, such as its ESET Parental Control, places a large emphasis on parents and children working together. It helps them to navigate online, manage what apps and websites they use, and decide – together – what’s good for them. One of the key features is age-based filters which helps to manage which apps children can and cannot access, allowing parents to consider the right restrictions for their children and to not just impose a blanket ban. Other features include setting time limits on when children can play on their devices and creating exceptions that kids can request. Parents can even send their children messages which they must acknowledge before they can continue to use their devices.

It’s elements such as these that allow children to be involved in the monitoring of their safety, and truly help parents to work together with their kids for a better internet and the best possible online world.

 

Play it safe during FIFA 2018 0 891

We do realize that you’ve been caught up in the hurly-burly of the FIFA World Cup, but surely you have a few minutes to spare and peruse our roster of tips to stay safe online not only during the soccer spectacle. While you’re at it, recognize that no single player, no matter how stellar, is enough to put you on a path to success. In fact, being even one player short can be enough to trip you up. What should the pillars of your cybersecurity game plan be, then?

#1 A stitch in time saves nine

Last year went down in history for two serious cyber-incidents – the WannaCryptoroutbreak and the Equifax hack – that served up powerful reminders of the merits of swiftly squashing security bugs. 2017 also saw the highest number of  vulnerabilities reported.

So the number one player in you security team is updates. In your home settings, making sure that automatic updates are enabled for your operating system and software is an easy step to take to keep attackers away.

 

#2 Prune your team

Get rid of that disgruntled bench-warmer who ends up sapping your team’s morale. Software that you hardly ever use can become a liability simply by increasing your attack surface. To further reduce the possible entry points for cybercriminals, you may also want to disable unused services and ports, and ditch programs that have a track record of vulnerabilities.

For your browser, consider blocking ads and removing all but the most necessary of browser add-ons and plugins. While you’re at it, shut down the accounts that you no longer need and use your high-privilege, or admin, account only for administrative tasks.

#3 Practice strong password hygiene

One of the easiest ways to protect your online identities consists in using a long, strong and unique password or better still, passphrase, for each of your online accounts. It may well come in handy if your login credentials leak, for example due to a breach at your service provider – which, in fact, is far too common a scenario. Further, just as you’d never share your teams tactics with your opponents, you should never share your password with anybody.

If you’re like most people and find the need to remember many username/password combinations overwhelming, consider using a password manager, which is intended to store your passwords in a “vault”.

#4 Look before you leap

Even if you have the most complex of passwords or passphrases, be aware of where you input them.

Online, everything is just a click away, and scammers are keenly aware of that. In their pursuit of your personal information, they use social engineering methods to sucker you into clicking a link or opening a malware-laden attachment.

5 questions to ask yourself before clicking on a link are:

  1. Do you trust the sender of the link?
  2. Do you trust the platform?
  3. Do you trust the destination?
  4. Does the link coincide with a major world event like the FIFA worldcup? (Cyber criminals tend to be opportunistic this way)
  5. Is it a shortened link?

#5 Add a factor

When aiming for secure accounts, you need to up your ante by using two-factor authentication, particularly for accounts that contain Personally Identifiable Information (PII) or other important data. The extra factor will require you to take an extra step to prove your identity when you attempt to log in or conduct a transaction. That way, even if your credentials leak or your password proves inadequate, there is another barrier between your account and the attacker.

#6 Use secure connections

When you connect to the internet, an attacker can sometimes place himself between your device and the connection point. To reduce the risk that such a man-in-the-middle attack will intercept your sensitive data while they are in motion, use only web connections secured by HTTPS (particularly for your most valued accounts) and use trusted networks such as your home connection or mobile data when performing the most sensitive of online operations, such as mobile banking. Needless to say, secure Wi-Fi connections should be underpinned by at least WPA2 encryption (or, ideally, WPA3as soon as it becomes available) – even at home – together with a strong and non-default administrator password and up-to-date firmware on your router.

Be very wary of public Wi-Fi hotspots. If you need to use such a connection, avoid sending personal data or use a reputable virtual private network (VPN) service, which keeps your data private via the use of an encrypted “tunnel”. Once you’re done, log out of your account and turn off Wi-Fi.

#7 Hide behind a firewall

A firewall is one of your key defensive players. Indeed, it is often thought of as the very first line of defense. It can typically be a piece of software in your computer, perhaps as part of anti-malware software, or it can be built into your router – or you can actually use both a network- and a host-based firewall. Regardless of its implementation, a firewall acts as a brawny bouncer that, based on predetermined rules, allows or denies traffic from the internet into an internal network or computer system.

#8 Back up

A backup is the kind of player who doesn’t get much time on the pitch, but when he does get the nod, he can “steal the show”. True, we might have spoken ill of bench warmers earlier, but a reliable backup is definitely not the kind of player to spoil your team’s chemistry.

Your system cannot usually be too – or completely – safe from harm. Beyond a cyber-incident, your data could be compromised by something as unpredictable as a storage medium failure. A backup is an example of a measure that is corrective in nature, but that is fully dependent on how hard you “practiced”. Or, as Benjamin Franklin put it, “by failing to prepare, you are preparing to fail”. It will cost you some time and possibly money to create (time and time again) your backups, but when it comes to averting (data) loss, this player may very well save the day for you.

#9 Select security software

Even if you use your common sense and take all kinds of “behavior-centered” precautions, you need another essential addition to your roster. At a time when you’re pitted against attackers who are ever more skilled, organized and persistent, dedicated security software is one of the easiest and most effective ways to protect your digital assets.

A reliable anti-malware solution uses many and various detection techniques and deploys multiple layers of defense that kick in at different stages of the attack process. That way, you’re provided with multiple opportunities to stymie a threat, including the latest threats, as attackers constantly come up with new malicious tools. This underscores the importance of always downloading the latest updates to your anti-malware software, which ideally are released several times a day. Top-quality security software automates this process, so you needn’t worry about installing the updates.

#10 Mobiles are computers, too!

Much of this article’s guidance also applies to smartphones and tablets. Due to their mobility, however, these devices are more prone to being misplaced or stolen. It is also of little help that users tend to view security software as belonging in the realm of laptops and desktops. But mobile devices have evolved to become powerful handheld computers and attackers have been shifting their focus to them.

There’s a number of measures you can take to reduce risks associated with mobile devices. They include relying on a secure authentication method to unlock your device’s screen, backing up the device, downloading system and app updates as soon as they’re available (preferably automatically, if possible), installing only reputable apps and only from legitimate stores, and making sure to use device encryption if it’s not turned on by default.

A dedicated mobile security solution will also go a long way towards enhancing your protection from mobile threats. This includes a scenario whereby your device goes missing, so you are then able to use the suite’s anti-theft and remote-wipe functionalities.

#11 Be aware

The final team member is, in fact, you – the keeper. Stay vigilant and cyber-aware and educate yourself on safe online habits. Don’t ever say, “it won’t/can’t happen to me”, because everyone is a potential target and victim. Recognize that one click is enough to inflict major damage on yourself and others, and that breaking good security practices for the sake of convenience may come back to bite you worse than Luis Suárez did in 2014. After all, how secure we are is largely dependent on how we use the technology.

So there you have it. You may want to enjoy the soccer now.