New week,Dear Utol (2025): Doctor, Doctor I'm Sick Episode 41 new ransomware.
A new form of ransomware surfaced in Russia, Ukraine and elsewhere this week. Known as Bad Rabbit, it's employed a leaked NSA exploit to do some of its damage.
SEE ALSO: Paying for antivirus software is mostly BSRansomware works by freezing up a computer in an attempt to force the user to pay a fee if they want their machine to be normal again.
The trick for hackers, of course, is how to get the malicious agent onto machines in the first place.
Bad Rabbit does this in a few steps. Here's how the cybersecurity firm Symantec described it in a post analyzing the ransomware:
"The initial infection method is through drive-by downloads on compromised websites. The malware is disguised as a fake update to Adobe Flash Player. The download originates from a domain named 1dnscontrol[dot]com, although visitors may have been redirected there from another compromised website."
After the malware's been installed, according to cybersecurity firm Cisco Talos, "there is an SMB component used for lateral movement and further infection."
SMB refers to Server Message Block, which is a means by which networked Windows machines share information. Bad Rabbit attacks SMB in several ways, according to Symantec, looking to spread to other vulnerable Windows machines in the same network as the computer on which it was first installed. One of the ways is through an SMB exploit known as EternalRomance, according to Talos and Symantec.
This takes us back to April, when a group of hackers known as the Shadow Brokers dumped a trove of NSA exploits on the internet for anyone to use them, assuming they have the knowledge required. Those exploits pertained to computers running Windows, putting millions of Windows users at risk of ransomware broadsides. Microsoft had actually released patches to ameliorate this and other exploits in March, but folks have to update their computers in order for those patches to take effect, and people looking to use this ransomware surely know that many folks simply never hit update (if you're running Windows and reading this, make sure to patch up your system if you haven't already).
"Ransomware is the threat of choice for both its monetary gain as well as destructive nature"
"The distribution of BadRabbit was massive," a threat intelligence expert at the cybersecurity firm Group-IBwrote on the company's website, though he noted that the distribution resulted in "much fewer victims" than another recent ransomware attack. The "primary" victims of the attack included "several Ukrainian strategic enterprises" including Odessa International Airport and the metro in Kiev, as well as "federal mass media" in Russia.
Wrapping up its Bad Rabbit analysis, Talos concluded that the world can expect more fast-spreading attacks that strike quickly and are designed "to inflict maximum damage."
"Ransomware is the threat of choice for both its monetary gain as well as destructive nature," they wrote. "As long as there is money to be made or destruction to be had these threats are going to continue."
Topics Cybersecurity
Elon Musk says Starlink now has more than 1,500 satellites in orbitTesla recalls 285,000 cars, this time over faulty cruiseTelegram now lets you video chat on group callsHow to add apps to an Apple TVThe oldest U.S. polar bear turned 37 years old and she had a better birthday than youOne app allows you to send coal to the naughtiest person of 2017How to go live on TikTokWatch the moment a fan holding a sign completely derailed the Tour de France10 years on, 'Kerbal Space Program' shoots for more distant starsListen to sounds from Mars, as recorded by China's Zhurong rover'F9' opens with the biggest U.S. box office since 2019, a huge win for theatersApple might launch a cheaper 6.7Everything coming to Netflix in JulyInstagram might finally let users post from desktop14 jokes about net neutrality while they're still freeToast the dog has diedPeople are tweeting their failed attempts to make gingerbread houses'Black Widow' reviews are in: What critics have to say about Marvel's latestWhen no one comes to dad's art show, his daughter makes sure people see his workThe 18 best motivational podcasts that could change your life 'Last Week Tonight with John Oliver' renewed for three more seasons Kid from 'It' attends 'It' screening dressed as kid from 'It' The iPhone 6S is the last of the great iPhones, everything else is trash The new Apple Watch with LTE connectivity won't get you out of buying an iPhone A teenage skier manages to keep all bones intact after an intense Parkour training session 'Metroid' is finally back and the reviews are GREAT Apple event kicks off with touching Steve Jobs tribute Hillary Clinton may have found the one person more annoying than Ted Cruz 'Star Wars' Episode IX: J.J. Abrams will return to write and direct I have spent YEARS designing the iPhone 9 and I am mad as hell NES Classic Edition is coming in 2018, Nintendo promises Hilariously, Nintendo doesn't want you to overpay for the SNES Classic There's a new massive clump of wet trash under London, heavier than 11 double decker buses If you have an iPhone 7, you should not buy an iPhone 8 Your reading list just got longer—the 2017 National Book Awards longlist is here Good lord, please get this snake off the subway iPhone X face scanners create 3D emojis based on your expressions When someone tells you to make a 'silly face,' take this bridesmaid's advice 'It' sequel plot details reveal a big change for one character Facebook is testing a new video feature for Android and it could be a game
1.1954s , 8222.6015625 kb
Copyright © 2025 Powered by 【Dear Utol (2025): Doctor, Doctor I'm Sick Episode 41】,Steady Information Network