Petya Ransomware: Firms Scramble to Recover From Wave of Cyber-Attacks

Advertisement
By Agence France-Presse | Updated: 28 June 2017 17:53 IST
Highlights
  • Another major cyber-attack 'Petya' hit global companies on Tuesday
  • Affected companies are gradually recovering from the damages
  • Microsoft has also addressed the ransomware attack

Thousands of computer users across the globe scrambled to reboot on Wednesday after a wave of ransomware cyber-attacks spread from Ukraine and Russia through Europe to the United States.

The virus, which demanded a payment worth $300 (roughly Rs. 20,000) as it locked up files at companies and government agencies including the Chernobyl nuclear site, appeared similar to the WannaCry ransomware that swept the world last month, hitting more than 200,000 users in more than 150 countries.

But the new attack appeared much smaller in scale, with global cyber-security firm Kaspersky Lab estimating the number of victims at 2,000. There was no immediate indication of who was responsible.

Advertisement

Petya Ransomware: What it Is, Impact on India, How to Protect Your PC, and Everything Else You Need to Know

Some IT specialists identified the newcomer as "Petrwrap", a modified version of ransomware called Petya which circulated last year. But Kaspersky described it as a new form of ransomware.

Advertisement

The government of Ukraine, where the attacks were first reported and appeared most severe, said the attack had been halted, but key organisations were still reporting problems.

Advertisement

"The large-scale cyber-attack on corporate and government networks that happened yesterday on June 27 has been stopped," the government said in a statement.

"The situation is under the complete control of cyber-security experts and they are now working on recovering lost data," it said, adding that all "strategic enterprises" were functioning as normal.

Advertisement

Despite the assurances, employees at the Chernobyl nuclear site were continuing to use hand-held Geiger counters to measure radiation levels after the monitoring system was shut down by the hack.

Online arrivals and departures information for Kiev's main Boryspil airport also remained down, but its director said the hub was otherwise fully operational.

Meanwhile, systems at the major lender Oschadbank still appeared crippled, while a delivery service and energy supplier said they were also facing some difficulties.

Global spread
The attacks started Tuesday at around 2:00pm in Kiev (1100 GMT) and quickly spread to about 80 companies in Ukraine and Russia, said cyber-security company Group IB.

In Russia, major companies including the oil giant Rosneft said they had suffered cyberattacks at roughly the same time.

Later, multinationals in Western Europe and the United States reported that they too had been hit by the virus.

Among the companies reporting problems were global shipping firm Maersk, British advertising giant WPP, French industrial group Saint-Gobain and US pharmaceutical group Merck.

India's government on Wednesday said operations at a terminal at the country's largest container port in Mumbai, run by Maersk, were disrupted.

Windows vulnerability
Security specialists said the cyber-attacks on Tuesday exploited an already patched vulnerability in Windows software and appeared to have focused on Ukraine as a primary target.

The malware that, once in a computer, locked away data from users who were then told to pay, bore resemblances to the recent WannaCry attack. US software titan Microsoft also called the latest virus ransomware.

"Our initial analysis found that the ransomware uses multiple techniques to spread, including one which was addressed by a security update previously provided for all platforms from Windows XP to Windows 10 (MS17-010)," a Microsoft spokesperson told AFP.

After the WannaCry scourge in May, Microsoft urged users to protect machines with the MS17-010 patch.

The flaw - and the means to exploit it - had previously been disclosed in pirated documents about cyberweapons at the US National Security Agency.

So far there was no clear indication of who was behind the attack.

Some experts said it looked likely to be a criminal scam, while Ukraine suggested that its archrival Russia could have been behind the attack.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco Pad M1 Tipped to Come With These Specifications
  2. Vivo X300 Series India Launch Date Announced
  3. Ajay Devgn-Starring De De Pyaar De 2 Could Arrive on OTT Next Year
  4. Redmi Note 15 Series India Launch Timeline Tipped
  5. Pradeep Ranganathan's and Mamitha Baiju Dude Begins Streaming on OTT
  1. Coming-of-Age Web Series CO-ED to Stream on OTT Soon: Know When, Where to Watch Online
  2. Leonardo DiCaprio’s One Battle After Another Now Available for Rent on Prime Video: All You Need to Know
  3. Ajay Devgn's De De Pyaar De 2 OTT Debut Timeline Tipped: All You Need to Know
  4. Pradeep Ranganathan's Dude Now Streaming on OTT: Know All About This Tamil-Language Rom-Com Film
  5. Tim Cook to Reportedly Step Down as Apple CEO in 2026; Successor to Be Announced After January
  6. Vivo X300 Series India Launch Date Announced: Here's What to Expect
  7. Redmi Note 15 Series India Launch Timeline Tipped; Redmi 15C Could Debut This Month
  8. Poco Pad M1 May Come With Snapdragon 7s Gen 4 Chip and 12,000mAh Battery; Price Tipped
  9. BSNL Announces Silver Jubilee Prepaid Recharge Plan With 2.5GB of Daily Data and More Benefits
  10. Blue Origin Joins SpaceX in Orbital Booster Reuse Era With New Glenn’s Successful Launch and Landing
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.