USEUROPEAFRICAASIA 中文雙語Fran?ais
    World
    Home / World / Americas

    Log in, look out: cyberattack havoc could grow at week's start

    chinadaily.com.cn | Updated: 2017-05-15 10:32

    Log in, look out: cyberattack havoc could grow at week's start

    A projection of cyber code on a hooded man is pictured in this illustration picture taken on May 13, 2017. Capitalizing on spying tools believed to have been developed by the US National Security Agency, hackers staged a cyber assault with a self-spreading malware that has infected tens of thousands of computers in nearly 100 countries. [Photo/Agencies]

    LONDON?- An unprecedented "ransomware" cyberattack that has already hit tens of thousands of victims in 150 countries could wreak greater havoc as more malicious variations appear and people return to their desks Monday and power up computers at the start of the workweek.

    Officials and experts on Sunday urged organizations and companies to update their operating systems immediately to ensure they aren't vulnerable to a second, more powerful version of the software — or to future versions that can't be stopped.

    The cyberattack paralyzed computers that run Britain's hospital network, Germany's national railway and scores of other companies and government agencies worldwide.

    Chinese media reported Sunday that students at several universities were hit, blocking access to their thesis papers and dissertation presentations.

    The attack, already believed to be the biggest online extortion scheme ever recorded, is an "escalating threat" after hitting 200,000 victims across the world since Friday, according to Rob Wainwright, the head of Europol, Europe's policing agency.

    "The numbers are still going up," Wainwright said. "We've seen that the slowdown of the infection rate over Friday night, after a temporary fix around it, has now been overcome by a second variation the criminals have released."

    Researchers discovered at least two variants of the rapidly replicating worm Sunday and one did not include the so-called kill switch that allowed them to interrupt its spread Friday by diverting it to a dead end on the internet.

    Ryan Kalember, senior vice-president at Proofpoint Inc, said the version with no kill switch was able to spread but it contained a flaw that wouldn't allow it to take over a computer and demand ransom to unlock files. However, he said it's only a matter of time before such a version exists.

    "I still expect another to pop up and be fully operational," Kalember said. "We haven't fully dodged this bullet at all until we're patched against the vulnerability itself."

    The attack held users hostage by freezing their computers, encrypting their data and demanding money through online bitcoin payment — $300 at first, rising to $600 before it destroys files hours later.

    The 200,000 victims included more than 100,000 organizations, Europol spokesman Jan Op Gen Oorth told The Associated Press.

    He said it was too early to say who was behind the onslaught and what their motivation was, aside from the obvious demand for money. So far, he said, not many people have paid the ransom demanded by the malware.

    The effects were felt across the globe, with Britain's National Health Service, Russia's Interior Ministry and companies including Spain's Telefonica, FedEx Corp in the US and French carmaker Renault all reporting disruptions.

    Had it not been for a young British cybersecurity researcher's accidental discovery of a so-called "kill switch," the malicious software likely would have spread much farther and faster.

    The 22-year-old researcher known as "MalwareTech," who wanted to remain anonymous, said he spotted a hidden web address in the "WannaCry" code and made it official by registering its domain name. That move, which cost just $10.69, redirected the attacks to the server of Kryptos Logic, the security company where he works. The server operates as a "sinkhole" to collect information about malware — and in Friday's case kept the malware from escaping.

    Security officials urged organizations to protect themselves by installing security fixes right away, running antivirus software and backing up data elsewhere.

    "Just patch their systems as soon as possible," MalwareTech said. "It won't be too late as long as they're not infected. It should just be a case of making sure installing updates is enabled, installing the updates, and reboot."

    The ransomware appeared to exploit a vulnerability in Microsoft Windows that was purportedly identified by the US National Security Agency for its own intelligence-gathering purposes. The NSA tools were stolen by hackers and dumped on the internet.

    Experts say this vulnerability has been understood among experts for months, yet too many groups failed to take it seriously. Microsoft had "patched," or fixed it, in updates of recent versions of Windows since March, but many users did not apply the software fix.

    Worse, the malware was able to create so much chaos because it was designed to self-replicate like a virus, spreading quickly once inside university, business and government networks.

    Microsoft was quick to change its policy, announcing free security patches to fix this vulnerability in the older Windows systems still used by millions of individuals and smaller businesses. Before Friday's attack, Microsoft had made fixes for older systems, such as 2001's Windows XP, available only to those who paid extra for extended technical support.

    "The problem is the larger organizations are still running on old, no longer supported operating systems," said Lawrence Abrams, a New York-based blogger who runs BleepingComputer.com. "So they no longer get the security updates they should be."

    Short of paying, options for those already infected are usually limited to recovering data files from a backup, if available, or living without them.

    British cybersecurity expert Graham Cluley doesn't want to blame the NSA for the attack, though he said they have a duty to citizens who "are living an online life."

    "Obviously, they want those tools in order to spy on people of interest, on other countries, to conduct surveillance," Cluley said. "It's a handy thing to have, but it's a dangerous thing to have, because they can be used against you. And that's what's happening right now."

    AP

    Most Viewed in 24 Hours
    Copyright 1995 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
    License for publishing multimedia online 0108263

    Registration Number: 130349
    FOLLOW US
    熟妇人妻久久中文字幕| 亚洲av福利无码无一区二区| 无码人妻熟妇AV又粗又大| 久久精品中文无码资源站| 无码午夜人妻一区二区三区不卡视频| 中文字幕人妻中文AV不卡专区| 日韩丰满少妇无码内射| 一本一道色欲综合网中文字幕| 欧美日本道中文高清| 国产成人无码久久久精品一| 中文字幕日韩精品在线| 中文一国产一无码一日韩| 69天堂人成无码麻豆免费视频| 国产综合无码一区二区辣椒| 亚洲精品无码成人片在线观看| 国精品无码一区二区三区在线| 亚洲中久无码永久在线观看同| 日韩欧美一区二区三区中文精品| 午夜无码视频一区二区三区| AV无码精品一区二区三区| 无码乱人伦一区二区亚洲一| 久久无码高潮喷水| 中文字幕日韩理论在线| 免费无码国产在线观国内自拍中文字幕| 无码人妻精品中文字幕免费东京热| 国产亚洲精久久久久久无码AV| 日韩精品无码中文字幕一区二区 | 精品无码国产一区二区三区51安| 中文字幕久久精品无码| 中文字幕亚洲精品无码| 亚洲欧美在线一区中文字幕| 最近最新高清免费中文字幕| 最近中文字幕视频在线资源| 亚洲国产午夜中文字幕精品黄网站 | 无码色AV一二区在线播放| 精品无码久久久久久久久久| 成人无码小视频在线观看| 精品亚洲成α人无码成α在线观看| 91精品久久久久久无码| 日韩视频无码日韩视频又2021 | 亚洲av午夜国产精品无码中文字|