Petya Ransomware a 'Ruse' to Hide Cyber-Attack Culprit, Claim Researchers

Advertisement
By Ellen Nakashima, The Washington Post | Updated: 3 July 2017 09:39 IST
Highlights
  • Petya malware is doubted to be more than just a money-making ransomware
  • Petya ransomware attack hit major global companies on Tuesday
  • Mumbai's JNPT post also reported to be compromised by the attack

The cyber-attack that crippled computer systems in Ukraine and other countries this week employed a ruse - the appearance of being ransomware - that seems designed to deflect attention from the attacker's true identity, security researchers said.

And many companies initially fell for it.

The first reports out of cyber-security firms on Monday, when news of the attack hit, was that a new variant of WannaCry, a virus that encrypted data and demanded a ransom to restore it, was on the loose.

Advertisement

In fact, a number of researchers said this week, the malware - which researchers are calling NotPetya - does not encrypt data, but wipes its victims' computers. If the data is not backed up, it's lost, they said.

Advertisement

"It definitely wasn't ransomware and wasn't financially motivated," said Jake Williams, founder of Rendition Infosec, a cyber-security firm, which has analysed the virus. "The goal was to cause disruption in computer networks."

Moreover, the email address to make a payment to retrieve data is no longer accessible, said Matt Suiche, a hacker and founder of Comae Technologies, a cyber-security firm.

Advertisement

He said in a blog post this week that the ransomware feint was likely a way to make people think "some mysterious hacker group" was behind the attack rather than a nation state.

"The fact of pretending to be a ransomware while being in fact a nation state attack . . . is in our opinion a very subtle way for the attacker to control the narrative of the attack," Suiche said.

Advertisement

Security researchers cautioned that it is too early to know for sure who is behind it. But some say that the targeting and distribution method of the malware point to Russia.

More than half the victimized computers were in Ukraine, including banks, energy firms and an airport.

Russia, which has annexed Crimea and has backed separatists in eastern Ukraine, has carried out an aggressive campaign of cyber-attacks and harassment there.

In December, Russian government hackers disrupted the power grid in Kiev and a year earlier they knocked out power in western Ukraine.

In this case, to get into victims' computers, attackers infected a financial software program in Ukraine, called MEDoc, that delivers software updates to businesses through the Internet.

That's called a "watering hole" attack, which targets users who navigate to the site for updates or to browse. It is also a tactic that Russian government hackers have used in the past to compromise industrial control system networks, Williams noted.

MEDoc is one of only two software options Ukrainian businesses have to pay their taxes, noted Lesley Carhart, an information security expert.

"This was a clever choice" for several reasons, she noted in a blog post, including that the "distribution base" within the country was "extremely comprehensive" as many companies used the software.

NotPetya did not spread across the open Internet, she said in an email. "Its tactic was to compromise a few computers inside a network" once the hacker got in, say, by delivering the malware through MEDoc. Then it could rapidly spread to other computers in the same network using a variety of other methods.

"While most 'patient zero' computers were in Ukraine . . . the corporate networks those computers [connect to] could potentially span the globe, and infection could also spread to any customers, partners, or vendors with whom they had unrestricted network connections and shared accounts," she said.

That might explain how US pharmaceutical giant Merck, the Danish shipping firm Maerskeven and the Russian oil company Rosneft got infected.

The Rosneft infection might be an unintended consequence - collateral damage, Williams said.

Valentyn Petrov, head of the information security service at Ukraine's National Security and Defense Council, said that the attack's timing, on the eve of Ukraine's Constitution Day, indicated this was a political attack.

"We are in an interesting test phase in which Russia is using modern cyber weapons," Petrov said, "and everyone is interested to see how it is working - and how threats can be countered."

© 2017 The Washington Post

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series 5G Confirmed to Launch in India Soon
  2. OnePlus 15R Goes on Sale in India For the First Time Today: Price, Offers
  3. iQOO Z11 Turbo Design Teased; Specifications Leaked
  4. Oppo Reno 15 Pro Mini Confirmed to Launch in India Alongside These Models
  5. Poco M8 Series India Launch Teased, Poco M8 and M8 Pro Could Debut
  6. Ram Pothineni's Andhra King Taluka Premieres on Netflix This December
  7. Instagram Could Embrace Long-Form Video Content to Compete With TikTok
  8. Samsung's 'Wide Fold' Will Reportedly Rival Apple's Foldable iPhone in 2026
  1. CES 2026: Samsung to Expand Bespoke Appliances With Google Gemini AI
  2. Oppo Reno 15 Pro Mini Confirmed to Launch in India Along With Reno 15, Reno 15 Pro; Flipkart Availability Announced
  3. Instagram Could Embrace Long-Form Video, Premium Content to Compete With TikTok, Says Adam Mosseri
  4. Samsung 'Wide Fold’ Will Reportedly Compete With Apple’s First Foldable iPhone in 2026
  5. Crypto Market Consolidation Continues as Bitcoin Tests Resistance Near $90,000
  6. Xiaomi Watch 5 With EMG Sensor, Xiaomi Buds 6 Confirmed to Launch Alongside Xiaomi 17 Ultra
  7. Samsung Galaxy S26 Series Will Go on Sale a Month After Anticipated Launch, Tipster Claims
  8. Valve Discontinues Production of Steam Deck LCD Model Weeks After Announcing Steam Machine
  9. Google Revises Timeline to Replace Assistant With Gemini on Android Smartphones
  10. OnePlus 15R With 7,400mAh Battery, 50-Megapixel Rear Camera Goes on Sale in India: Price, Offers, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.