Ransomware Attacks: Ukrainian Police Seize Servers of Software Firm

Advertisement
By Reuters | Updated: 5 July 2017 10:17 IST
Highlights
  • Servers of M.E.Doc seized as part of an investigation into the attack
  • Initial infections were spread via a malicious update issued by M.E.Doc
  • At least 3 M.E.Doc updates had been issued with backdoor vulnerability

Ukrainian police on Tuesday seized the servers of an accounting software firm suspected of spreading a malware virus which crippled computer systems at major companies around the world last week, a senior police official said.

The head of Ukraine's Cyber Police, Serhiy Demedyuk, told Reuters the servers of M.E.Doc - Ukraine's most popular accounting software - had been seized as part of an investigation into the attack.

Though they are still trying to establish who was behind last week's attack, Ukrainian intelligence officials and security firms have said some of the initial infections were spread via a malicious update issued by M.E.Doc, charges the company's owners deny.

Advertisement

The owners were not immediately available for comment on Tuesday.

Advertisement

Premium Service, which says it is an official dealer of M.E.Doc's software, wrote a post on M.E.Doc's Facebook page saying masked men were searching M.E.Doc's offices and that the software firm's servers and services were down.

Ransomware Attacks: Family Firm in Ukraine Says Not Responsible

Premium Service could not be reached for further comment.

Advertisement

Cyber Police spokeswoman Yulia Kvitko said investigative actions were continuing at M.E.Doc's offices, adding that further comment would be made on Wednesday.

The police move came after cyber-security investigators unearthed further evidence on Tuesday that the attack had been planned months in advance by highly-skilled hackers, who they said had inserted a vulnerability into the M.E.Doc progamme.

Advertisement

Ukraine also took steps on Tuesday to extend its state tax deadline by one month to help businesses hit by the malware assault.

Researchers at Slovakian security software firm ESET said they had found a "backdoor" written into some of M.E.Doc's software updates, likely with access to the company's source code, which allowed hackers to enter companies' systems undetected.

"Very stealthy and cunning"
"We identified a very stealthy and cunning backdoor that was injected by attackers into one of M.E.Doc's legitimate modules," ESET senior malware researcher Anton Cherepanov said in a technical note. "It seems very unlikely that attackers could do this without access to M.E.Doc's source code."

"This was a thoroughly well-planned and well-executed operation," he said.

ESET said at least three M.E.Doc updates had been issued with the "backdoor vulnerability", and the first one was sent to clients on April 14, more than two months before the attack.

ESET said the hackers likely had access to M.E.Doc's source code since the beginning of the year, and the detailed preparation before the attack was testament to the advanced nature of their operation.

Ransomware Attacks: Ukraine Points Finger at Russian Security Services

Oleg Derevianko, board chairman at Ukrainian cyber-security firm ISSP, said an update issued by M.E.Doc in April delivered a virus to the company's clients which instructed computers to download 350 megabytes of data from an unknown source on the Internet.

The virus then exported 35 megabytes of company data to the hackers, he told Reuters in an interview at his office in Kiev.

"With this 35 megabytes you can exfiltrate anything - emails from all of the banks, user accounts, passwords, anything."

Little known outside Ukrainian accounting circles, M.E.Doc is used by around 80 percent of companies in Ukraine. The software allows its 400,000 clients to send and collaborate on financial documents between internal departments, as well as file them with the Ukrainian state tax service.

Ukraine's government said on Tuesday it would submit a draft law to parliament for the country's tax deadline to be extended to July 15, and waive fines for companies who missed the previous June 13 cutoff because of the attack.

"We had programme failures in connection to the cyber-attack, which meant that businesses were unable to submit account reports on time," Prime Minister Volodymyr Groysman told a cabinet meeting.

Separately, Ukraine's security service, the SBU, said it had discussed cyber defence with NATO officials and had received equipment from the alliance to better combat future cyber-attacks. Ukraine is not in NATO but is seeking closer ties.

On Saturday Ukrainian intelligence officials accused Russian security services of being behind the attack, and cyber-security researchers linked it to a suspected Russian group who attacked the Ukrainian power grid in December 2016.

A Kremlin spokesman dismissed charges of Russian involvement as "unfounded blanket accusations".

Derevianko said the hacker's activity in April and reported access to M.E.Doc's source code showed Ukraine's computer networks had already been compromised and that the intruders were still operating inside them.

"It definitely tells us about the advanced capabilities of the adversaries," he said. "I don't think any additional evidence is needed to attribute this to a nation-state attack."

© Thomson Reuters 2017

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  2. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  3. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  4. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  5. Realme UI 7.0 Launched With Light Glass Design, AI Features
  6. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  7. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  8. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  9. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  2. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  3. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  4. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  5. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  6. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
  7. iOS 26.2 Beta 1 Rolled Out to Developers With Enhanced Safety Alerts, Reminder Alarms
  8. Samsung Galaxy S26 Ultra Spotted in Leaked Design Renders That Hint at Rounder Corners
  9. Call of Duty: Black Ops 7 PC Specifications, Preloading Times Revealed; Activision Confirms Handheld Support
  10. Silicon Carbide-Based Motor Drive Enables a Smaller, Lighter Electric Aircraft Engine
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.