Story image

Sophos responds to new variant of Petya ransomware

05 Jul 17

Sophos has responded to the new variant of Petya ransomware family also known as NotPetya.

Petya is a ransomware that encrypts MFT (Master File Tree) tables and overwrites the MBR (Master Boot Record), dropping a ransom note and leaving victims unable to boot their computer.

The variant is particularly virulent because it uses multiple techniques to spread automatically within a company’s network once the first computer is infected.

The Petya ransomware was discovered in 2016 and has the new variant has since affected companies in Europe.

The latest massive cyberattack to hit the globe is evidence of how hackers are upping the ante, says Martin Walshaw, F5 Networks senior engineer.

“The ransomworm NotPetya has been wreaking havoc across the world, highlighting the need for greater focus on cyber security education.

“The cyberattack originated in the Ukraine. It has hit major infrastructure in the areas where it has spread, with security experts speculating that it might be functioning in a similar manner to the infamous ‘Wannacry’ attack,” Walshaw says.

“This latest wave of what looks to be ransomware is just another example of the real-world threats encountered by organisations, governments and countries all over the world.

“These attacks are upping the ante, as they hit services that affect people’s day-to-day activity; such as healthcare, postal services, and transport services.

“While the reported ransom demands of $300 to release the encrypted data seems low, this will scale up very quickly.

“The more concerning issue is how national infrastructure is being impacted. There is no easy solution to eradicate ransomware, but when the dust settles, the source of the compromises needs to be determined and remediated,” he adds.

“Going into the new world of IoT and connected devices, with every element focusing on the application, the digital attack surface area will continue to grow.

"This gives the attackers more opportunities to infiltrate data. More focus needs to be put on the application and data security. In addition, more cyber security education should be integral in everybody’s daily lives.” he says.

According to Sophos, “Customers with Sophos Endpoint Protection products are protected against this new variant. Sophos Intercept X customers were proactively protected with no data encrypted, from the moment this new ransomware variant appeared.”

Sophos urges users to ensure systems have the latest patches.

Disruption in the supply chain: Why IT resilience is a collective responsibility
"A truly resilient organisation will invest in building strong relationships while the sun shines so they can draw on goodwill when it rains."
Businesses too slow on attack detection – CrowdStrike
The 2018 CrowdStrike Services Cyber Intrusion Casebook reveals IR strategies, lessons learned, and trends derived from more than 200 cases.
What disaster recovery will look like in 2019
“With nearly half of all businesses experiencing an unrecoverable data event in the last three years, current backup solutions are no longer fit for purpose."
Proofpoint launches feature to identify most targeted users
“One of the largest security industry misconceptions is that most cyberattacks target top executives and management.”
McAfee named Leader in Magic Quadrant an eighth time
The company has been once again named as a Leader in the Gartner Magic Quadrant for Security Information and Event Management.
Symantec and Fortinet partner for integration
The partnership will deliver essential security controls across endpoint, network, and cloud environments.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.
25% of malicious emails still make it through to recipients
Popular email security programmes may fail to detect as much as 25% of all emails with malicious or dangerous attachments, a study from Mimecast says.