AIRLINK 72.59 Increased By ▲ 3.39 (4.9%)
BOP 4.99 Increased By ▲ 0.09 (1.84%)
CNERGY 4.29 Increased By ▲ 0.03 (0.7%)
DFML 31.71 Increased By ▲ 0.46 (1.47%)
DGKC 80.90 Increased By ▲ 3.65 (4.72%)
FCCL 21.42 Increased By ▲ 1.42 (7.1%)
FFBL 35.19 Increased By ▲ 0.19 (0.54%)
FFL 9.33 Increased By ▲ 0.21 (2.3%)
GGL 9.82 Increased By ▲ 0.02 (0.2%)
HBL 112.40 Decreased By ▼ -0.36 (-0.32%)
HUBC 136.50 Increased By ▲ 3.46 (2.6%)
HUMNL 7.14 Increased By ▲ 0.19 (2.73%)
KEL 4.35 Increased By ▲ 0.12 (2.84%)
KOSM 4.35 Increased By ▲ 0.10 (2.35%)
MLCF 37.67 Increased By ▲ 1.07 (2.92%)
OGDC 137.75 Increased By ▲ 4.88 (3.67%)
PAEL 23.41 Increased By ▲ 0.77 (3.4%)
PIAA 24.55 Increased By ▲ 0.35 (1.45%)
PIBTL 6.63 Increased By ▲ 0.17 (2.63%)
PPL 125.05 Increased By ▲ 8.75 (7.52%)
PRL 26.99 Increased By ▲ 1.09 (4.21%)
PTC 13.32 Increased By ▲ 0.24 (1.83%)
SEARL 52.70 Increased By ▲ 0.70 (1.35%)
SNGP 70.80 Increased By ▲ 3.20 (4.73%)
SSGC 10.54 No Change ▼ 0.00 (0%)
TELE 8.33 Increased By ▲ 0.05 (0.6%)
TPLP 10.95 Increased By ▲ 0.15 (1.39%)
TRG 60.60 Increased By ▲ 1.31 (2.21%)
UNITY 25.10 Decreased By ▼ -0.03 (-0.12%)
WTL 1.28 Increased By ▲ 0.01 (0.79%)
BR100 7,566 Increased By 157.7 (2.13%)
BR30 24,786 Increased By 749.4 (3.12%)
KSE100 71,902 Increased By 1235.2 (1.75%)
KSE30 23,595 Increased By 371 (1.6%)
World

Another large-scale cyberattack underway: experts

  PARIS: Another large-scale, stealthy cyberattack is underway on a scale that could dwarf last week's assault o
Published May 17, 2017

 

PARIS: Another large-scale, stealthy cyberattack is underway on a scale that could dwarf last week's assault on computers worldwide, a global cybersecurity firm told AFP on Wednesday.

The new attack targets the same vulnerabilities the WannaCry ransomware worm exploited but, rather than freeze files, uses the hundreds of thousands of computers believed to have been infected to mine virtual currency.

Following the detection of the WannaCry attack on Friday, "researchers at Proofpoint discovered a new attack linked to WannaCry called Adylkuzz," said Nicolas Godier, a researcher at the computer security firm.

"It uses the hacking tools recently disclosed by the NSA and which have since been fixed by Microsoft in a more stealthy manner and for a different purpose," he said.

Instead of completely disabling an infected computer by encrypting data and seeking a ransom payment, Adylkuzz uses the machines it infects to "mine" in a background task a virtual currency, Monero, and transfer the money created to the authors of the virus.

Virtual currencies such as Monero and Bitcoin use the computers of volunteers for recording transactions. They are said to "mine" for the currency and are occasionally rewarded with a piece of it.

Proofpoint said in a blog that symptoms of the attack include loss of access to shared Windows resources and degradation of PC and server performance, effects which some users may not notice immediately.

"As it is silent and doesn't trouble the user, the Adylkuzz attack is much more profitable for the cyber criminals. It transforms the infected users into unwitting financial supporters of their attackers," said Godier.

Proofpoint said it has detected infected machines that have transferred several thousand dollars worth of Monero to the creators of the virus.

The firm believes Adylkuzz has been on the loose since at least May 2, and perhaps even since April 24, but due to its stealthy nature was not immediately detected.

"We don't know how big it is" but "it's much bigger than WannaCry", Proofpoint's vice president for email products, Robert Holmes, told AFP.

A US official on Tuesday put the number of computers infected by WannaCry at over 300,000.

"We have seen that before -- malwares mining cryptocurrency -- but not this scale," said Holmes.

The WannaCry attack has sparked havoc in computer systems worldwide.

Britain's National Health Service, US package delivery giant FedEx, Spanish telecoms giant Telefonica and Germany's Deutsche Bahn rail network were among those hit.

 

Copyright AFP (Agence France-Press), 2017
 

 

 

 

Comments

Comments are closed.