Bitcoin 24 maggio

bitcoin 24 maggio

Please also see Regulation of Cryptocurrency in Selected Jurisdictions for more detailed reports On August 24, 2017, the Canadian Securities Administrators (​CSA) published CSA Staff Notice [246] Decreto Legislativo 25 maggio 2017, n. ShapeShift is the easiest way to get started with top cryptocurrencies. Buy, trade, track, receive, share, and even win! A random ShapeShift user is rewarded with. Sarà lanciata il 19 Maggio e sembra la notizia sia 100% veritiera, in. Sep 24, 2020 · Bitcoin's meteoric investimento bitcoin sb rise in prices in 2017 awakened​. bitcoin 24 maggio

Are: Bitcoin 24 maggio

BITCOIN GOLD 16000 86
AMAZON RUMOR BITCOIN 75
FLICK BITCOINTALK 625
CX BITCOIN 390

WannaCry ransomware attack

Screenshot of the ransom note left on an infected system
Date12 May 2017 – 15 May 2017
(initial outbreak)[1]
Duration4 days
LocationWorldwide
Also known asTransformations:
Wanna → Wana
Cryptor → Crypt0r
Cryptor → Decryptor
Cryptor → Crypt → Cry
Addition of "2.0"
Short names:
Wanna → WN → W
Cry → CRY
TypeCyberattack
ThemeRansomware encrypting files with $300 – $600 USD demand (via bitcoin)
CauseWannaCry worm
Outcome
ArrestsNone
SuspectsLazarus Group
AccusedTwo North Koreans Indicted
ConvictionsNone

The WannaCry ransomware attack was a May 2017 worldwidecyberattack by the WannaCry ransomwarecryptoworm, which targeted computers running the Microsoft Windowsoperating system by encrypting data and demanding ransom payments in the Bitcoincryptocurrency.[citation needed] It propagated through EternalBlue, an exploit discovered by the United States National Security Agency (NSA) for older Windows systems. EternalBlue was stolen and leaked by a group called The Shadow Brokers at least a year prior to the attack. While Microsoft had released patches previously to close the exploit, much of WannaCry's spread was from organizations that had not applied these, or were using older Windows systems that were past their end-of-life. These patches are imperative to an organization's cyber-security but many were not applied because of needing 24/7 operation, risking having applications that used to work break, inconvenience, or other reasons.

The attack was halted within a few days of its discovery due to emergency patches released by Microsoft and the discovery of a kill switch that prevented infected computers from spreading WannaCry further. The attack was estimated to have affected more than 200,000 computers across 150 countries, with total damages ranging from hundreds of millions to billions of dollars. Security experts believed from preliminary evaluation of the worm that the attack originated from North Korea or agencies working for the country.

In December 2017, the United States, United Kingdom and Australia formally asserted that North Korea was behind the attack.[5]

A new variant of WannaCry forced Taiwan Semiconductor Manufacturing Company (TSMC) to temporarily shut down several of its chip-fabrication factories in August 2018. The virus spread to 10,000 machines in TSMC's most advanced facilities.[6]

Description[edit]

WannaCry is a ransomwarecryptoworm, which targeted computers running the Microsoft Windowsoperating system by encrypting data and demanding ransom payments in the Bitcoincryptocurrency. The worm is also known as WannaCrypt,[7] Wana Decrypt0r 2.0,[8] WanaCrypt0r 2.0,[9] and Wanna Decryptor.[10] It is considered a network worm because it also includes a "transport" mechanism to automatically spread itself. This transport code scans for vulnerable systems, then uses the EternalBlue exploit to gain access, and the DoublePulsar tool to install and execute a copy of itself.[11] WannaCry versions 0, 1, and 2 were created using Microsoft Visual C++ 6.0.[12]

EternalBlue is an exploit of Windows' Server Message Block (SMB) protocol released by The Shadow Brokers. Much of the attention and comment around the event was occasioned by the fact that the U.S. National Security Agency (NSA) (from whom the exploit was likely stolen) had already discovered the vulnerability, but used it to create an exploit for its own offensive work, rather than report it to Microsoft.[13][14] Microsoft eventually discovered the vulnerability, and on Tuesday, 14 March 2017, they issued security bulletin MS17-010, which detailed the flaw and announced that patches had been released for all Windows versions that were currently supported at that time, these being Windows Vista, Windows 7, Windows 8.1, Windows 10, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2016.[15]

DoublePulsar is a backdoor tool, also released by The Shadow Brokers on 14 April 2017. Starting from 21 April 2017, security researchers reported that there were tens of thousands of computers with the DoublePulsar backdoor installed.[16] By 25 April, reports estimated that the number of infected computers could be up to several hundred thousand, with numbers increasing every day.[17][18] The WannaCry code can take advantage of any existing DoublePulsar infection, or installs it itself.[11][19][20] On 9 May 2017, private cybersecurity company RiskSense released code on GitHub with the stated purpose of allowing legal “white hat” penetration testers to test the CVE-2017-0144 exploit on unpatched systems.

When executed, the WannaCry malware first checks the "kill switch" domain name; if it is not found, then the ransomware encrypts the computer's data,[21][22][23] then attempts to exploit the SMB vulnerability to spread out to random computers on the Internet,[24] and "laterally" to computers on the same network.[25] As with other modern ransomware, the payload displays a message informing the user that files have been encrypted, and demands a payment of around US$300 in bitcoin within three days, or US$600 within seven days.[22][26] Three hardcoded bitcoin addresses, or "wallets", are used to receive the payments of victims. As with all such wallets, their transactions and balances are publicly accessible even though the cryptocurrency wallet owners remain unknown.[27]

Several organizations released detailed technical writeups of the malware, including a senior security analyst at RiskSense,[28][29] Microsoft,[30]Cisco,[11]Malwarebytes,[24]Symantec and McAfee.[25]

Attack[edit]

The attack began on Friday, 12 May 2017,[31][32] with evidence pointing to an initial infection in Asia at 07:44 UTC.[31][33] The initial infection was likely through an exposed vulnerable SMB port,[34] rather than email phishing as initially assumed.[31] Within a day the code was reported to have infected more than 230,000 computers in over 150 countries.[35][36]

Organizations that had not installed Microsoft's security update from April 2017 were affected by the attack.[37] Those still running unsupported versions of Microsoft Windows, such as Windows XP and Windows Server 2003[38][39] were at particularly high risk because no security patches had been released since April 2014 for Windows XP (with the exception of one emergency patch released in May 2014) and July 2015 for Windows Server 2003.[7] A Kaspersky Lab study reported however, that less than 0.1 percent of the affected computers were running Windows XP, and that 98 percent of the affected computers were running Windows 7.[7][40] In a controlled testing environment, the cybersecurity firm Kryptos Logic found that it was unable to infect a Windows XP system with WannaCry using just the exploits, as the payload failed to load, or caused the operating system to crash rather than actually execute and encrypt files. However, when executed manually, WannaCry could still operate on Windows XP.[41][42][43]

Defensive response[edit]

Experts quickly advised affected users against paying the ransom due to no reports of people getting their data back after payment and as high revenues would encourage more of such campaigns.[44][45][46] As of 14 June 2017, after the attack had subsided, a total of 327 payments totaling US$130,634.77 (51.62396539 XBT) had been transferred.[47]

The day after the initial attack in May, Microsoft released out-of-band security updates for end of life products Windows XP, Windows Server 2003 and Windows 8; these patches had been created in February of that year following a tip off about the vulnerability in January of that year.[48][39] Organizations were advised to patch Windows and plug the vulnerability in order to protect themselves from the cyber attack.[49] The head of Microsoft's Cyber Defense Operations Center, Adrienne Hall, said that “Due to the elevated risk for destructive cyber-attacks at this time, we made the decision to take this action because applying these updates provides further protection against potential attacks with characteristics similar to WannaCrypt [alternative name to WannaCry]”.[50][51]

Researcher Marcus Hutchins[52][53] discovered the kill switch domain hardcoded in the malware.[54][55][56] Registering a domain name for a DNS sinkhole stopped the attack spreading as a worm, because the ransomware only encrypted the computer's files if it was unable to connect to that domain, which all computers infected with WannaCry before the website's registration had been unable to do. While this did not help already infected systems, it severely slowed the spread of the initial infection and gave time for defensive measures to be deployed worldwide, particularly in North America and Asia, which had not been attacked to the same extent as elsewhere.[57][58][59][60][61] On 14 May, a first variant of WannaCry appeared with a new and second[62] kill-switch registered by Matt Suiche on the same day. This was followed by a second variant with the third and last kill-switch on 15 May, which was registered by Check Point threat intelligence analysts.[63][64] A few days later, a new version of WannaCry was detected that lacked the kill switch altogether.[65][66][67][68]

On 19 May, it was reported that hackers were trying to use a Mirai botnet variant to effect a distributed attack on WannaCry's kill-switch domain with the intention of knocking it offline.[69] On 22 May, Hutchins protected the domain by switching to a cached version of the site, capable of dealing with much higher traffic loads than the live site.[70]

Separately, researchers from University College London and Boston University reported that their PayBreak system could defeat WannaCry and several other families of ransomware by recovering the keys used to encrypt the user's data.[71][72]

It was discovered that Windows encryption APIs used by WannaCry may not completely clear the prime numbers used to generate the payload's private keys from the memory, making it potentially possible to retrieve the required key if they had not yet been overwritten or cleared from resident memory. The key is kept in the memory if the WannaCry process has not been killed and the computer has not been rebooted after being infected.[73] This behaviour was used by a French researcher to develop a tool known as WannaKey, which automates this process on Windows XP systems.[74][75][76] This approach was iterated upon by a second tool known as Wanakiwi, which was tested to work on Windows 7 and Server 2008 R2 as well.[77]

Within four days of the initial outbreak, new infections had slowed to a trickle due to these responses.[78]

Attribution[edit]

Linguistic analysis of the ransom notes indicated the authors were likely fluent in Chinese and proficient in English, as the versions of the notes in those languages were probably human-written while the rest seemed to be machine-translated.[79][80] According to an analysis by the FBI's Cyber Behavioral Analysis Center, the computer that created the ransomware language files had Hangul language fonts installed, as evidenced by the presence of the "\fcharset129" Rich Text Format tag.[12] Metadata in the language files also indicated that the computers that created the ransomware were set to UTC+09:00, used in Korea.[12]

A Google security researcher[81][82] initially posted a tweet[83] referencing code similarities between WannaCry and previous malware. The cybersecurity companies[84]Kaspersky Lab and Symantec have both said the code has some similarities with that previously used by the Lazarus Group[85] (believed to have carried out the cyberattack on Sony Pictures in 2014 and a Bangladesh bank heist in 2016—and linked to North Korea).[85] This could also be either simple re-use of code by another group[86] or an attempt to shift blame—as in a cyber false flag operation;[85] but a leaked internal NSA memo is alleged to have also linked the creation of the worm to North Korea.[87]Brad Smith, the president of Microsoft, said he believed North Korea was the originator of the WannaCry attack,[88] and the UK's National Cyber Security Centre reached the same conclusion.[89]

On 18 December 2017, the United States Government formally announced that it publicly considers North Korea to be the main culprit behind the WannaCry attack.[90]PresidentTrump's Homeland Security Advisor, Tom Bossert, wrote an op-ed in The Wall Street Journal about this charge, saying "We do not make this allegation lightly. It is based on evidence."[91] In a press conference the following day, Bossert said that the evidence indicates that Kim Jong-un had given the order to launch the malware attack.[92] Bossert said that Canada, New Zealand and Japan agree with the United States' assessment of the evidence that links the attack to North Korea,[93] while the United Kingdom's Foreign and Commonwealth Office says it also stands behind the United States' assertion.[94]

North Korea, however, denied being responsible for the cyberattack.[95][96]

On 6 September 2018, the US Department of Justice (DoJ) announced formal charges against Park Jin-hyok for involvement in the Sony Pictures hack of 2014. The DoJ contended that Park was a North Korean hacker working as part of a team of experts for the North Korean Reconnaissance General Bureau. The Department of Justice asserted this team also had been involved in the WannaCry attack, among other activities.[97][98]

Impact[edit]

The ransomware campaign was unprecedented in scale according to Europol,[35] which estimates that around 200,000 computers were infected across 150 countries. According to Kaspersky Lab, the four most affected countries were Russia, Ukraine, India and Taiwan.[100]

One of the largest agencies struck by the attack was the National Health Service hospitals in England and Scotland,[101][102] and up to 70,000 devices – including computers, MRI scanners, blood-storage refrigerators and theatre equipment – may have been affected.[103] On 12 May, some NHS services had to turn away non-critical emergencies, and some ambulances were diverted.[104][105] In 2016, thousands of computers in 42 separate NHS trusts in England were reported to be still running Windows XP.[38] In 2018 a report by Members of Parliament concluded that all 200 NHS hospitals or other organizations checked in the wake of the WannaCry attack still failed cyber security checks.[106][107] NHS hospitals in Wales and Northern Ireland were unaffected by the attack.[108][104]

Nissan Motor Manufacturing UK in Tyne and Wear, England, halted production after the ransomware infected some of their systems. Renault also stopped production at several sites in an attempt to stop the spread of the ransomware.[109][110] Spain's Telefónica, FedEx and Deutsche Bahn were hit, along with many other countries and companies worldwide.[111][112][113]

The attack's impact is said to be relatively low compared to other potential attacks of the same type and could have been much worse had Marcus Hutchins not discovered that a kill-switch had been built in by its creators[114][115] or if it had been specifically targeted on highly critical infrastructure, like nuclear power plants, dams or railway systems.[116][117]

According to cyber-risk-modeling firm Cyence, economic losses from the cyber attack could reach up to US$4 billion, with other groups estimating the losses to be in the hundreds of millions.[118]

Affected organizations[edit]

The following is an alphabetical list of organisations confirmed to have been affected:

  • Andhra Pradesh Police, India[119]
  • Aristotle University of Thessaloniki, Greece[120][121]
  • Automobile Dacia, Romania[122]
  • Boeing Commercial Airplanes[123]
  • Cambrian College, Canada[124]
  • Chinese public security bureau[125]
  • CJ CGV (a cinema chain)[126]
  • Dalian Maritime University[127]
  • Deutsche Bahn[128]
  • Dharmais Hospital, Indonesia[129]
  • Faculty Hospital, Nitra, Slovakia[130]
  • FedEx[131]
  • Garena Blade and Soul[132]
  • Guilin University of Aerospace Technology[127]
  • Guilin University of Electronic Technology[127]
  • Harapan Kita Hospital, Indonesia[129]
  • Hezhou University[127]
  • Hitachi[133]
  • Honda[134]
  • Instituto Nacional de Salud, Colombia[135]
  • Lakeridge Health[136]
  • LAKS, Netherlands [137]
  • LATAM Airlines Group[138]
  • MegaFon[139]
  • Ministry of Internal Affairs of the Russian Federation[140]
  • National Health Service (England)[141][104][108]
  • NHS Scotland[104][108]
  • Nissan Motor Manufacturing UK[141]
  • O2, Germany[142][143]
  • Petrobrás[144]
  • PetroChina[111][125]
  • Portugal Telecom[145]
  • Pulse FM[146]
  • Q-Park[147]
  • Renault[148]
  • Russian Railways[149]
  • Sandvik[129]
  • Justice Court of São Paulo[144]
  • Saudi Telecom Company[150]
  • Sberbank[151]
  • Shandong University[127]
  • State Governments of India
  • Suzhou Vehicle Administration[127]
  • Sun Yat-sen University, China[129]
  • Telefónica, Spain[154]
  • Telenor Hungary, Hungary[155]
  • Telkom (South Africa)[156]
  • Timrå Municipality, Sweden[157]
  • TSMC, Taiwan[158]
  • Universitas Jember, Indonesia[159]
  • University of Milano-Bicocca, Italy[160]
  • University of Montreal, Canada[161]
  • Vivo, Brazil[144]

Reactions[edit]

A number of experts highlighted the NSA's non-disclosure of the underlying vulnerability, and their loss of control over the EternalBlue attack tool that exploited it. Edward Snowden said that if the NSA had "privately disclosed the flaw used to attack hospitals when they found it, not when they lost it, the attack may not have happened".[162] British cybersecurity expert Graham Cluley also sees "some culpability on the part of the U.S. intelligence services". According to him and others "they could have done something ages ago to get this problem fixed, and they didn't do it". He also said that despite obvious uses for such tools to spy on people of interest, they have a duty to protect their countries' citizens.[163] Others have also commented that this attack shows that the practice of intelligence agencies to stockpile exploits for offensive purposes rather than disclosing them for defensive purposes may be problematic.[115] Microsoft president and chief legal officer Brad Smith wrote, "Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen."[164][165][166] Russian President Vladimir Putin placed the responsibility of the attack on U.S. intelligence services, for having created EternalBlue.[151]

On 17 May 2017, United States bipartisan lawmakers introduced the PATCH Act[167] that aims to have exploits reviewed by an independent board to "balance the need to disclose vulnerabilities with other national security interests while increasing transparency and accountability to maintain public trust in the process".[168]

On 15 June 2017, the United States Congress was to hold a hearing on the attack.[169] Two subpanels of the House Science Committee were to hear the testimonies from various individuals working in the government and non-governmental sector about how the US can improve its protection mechanisms for its systems against similar attacks in the future.[169]

Marcus Hutchins, a cybersecurity researcher, working in loose collaboration with UK's National Cyber Security Centre,[170][171] researched the malware and discovered a "kill switch".[53] Later globally dispersed security researchers collaborated online to developopen source tools[172][173] that allow for decryption without payment under some circumstances.[174] Snowden states that when "NSA-enabled ransomware eats the Internet, help comes from researchers, not spy agencies" and asks why this is the case.[175][176][171]

Other experts also used the publicity around the attack as a chance to reiterate the value and importance of having good, regular and securebackups, good cybersecurity including isolating critical systems, using appropriate software, and having the latest security patches installed.[177]Adam Segal, director of the digital and cyberspace policy program at the Council on Foreign Relations, stated that "the patching and updating systems are broken, basically, in the private sector and in government agencies".[115] In addition, Segal said that governments' apparent inability to secure vulnerabilities "opens a lot of questions about backdoors and access to encryption that the government argues it needs from the private sector for security".[115]Arne Schönbohm, president of Germany's Federal Office for Information Security (BSI), stated that "the current attacks show how vulnerable our digital society is. It's a wake-up call for companies to finally take IT security [seriously]".[178]

United Kingdom[edit]

The effects of the attack also had political implications; in the United Kingdom, the impact on the National Health Service quickly became political, with claims that the effects were exacerbated by Government underfunding of the NHS; in particular, the NHS ceased its paid Custom Support arrangement to continue receiving support for unsupported Microsoft software used within the organization, including Windows XP.[179]Home SecretaryAmber Rudd refused to say whether patient data had been backed up, and Shadow Health SecretaryJon Ashworth accused Health SecretaryJeremy Hunt of refusing to act on a critical note from Microsoft, the National Cyber Security Centre (NCSC) and the National Crime Agency that had been received two months previously.[180]

Others argued that hardware and software vendors often fail to account for future security flaws, selling systems that − due to their technical design and market incentives − eventually won't be able to properly receive and apply patches.[181]

The NHS denied that it was still using XP, claiming only 4.7% of devices within the organization ran Windows XP.[182][41] The cost of the attack to the NHS was estimated as £92 million in disruption to services and IT upgrades.[183]

After the attack, NHS Digital refused to finance the estimated £1 billion to meet the Cyber Essentials Plus standard, an information security certification organized by the UK NCSC, saying this would not constitute "value for money", and that it had invested over £60 million and planned "to spend a further £150 [million] over the next two years" to address key cyber security weaknesses.[184]

2018 email scam[edit]

In late June, hundreds of computer users reported being sent an email from someone (or multiple people), claiming to be the developers of WannaCry.[185] The email threatened to destroy the victims' data unless they sent 0.1 BTC to the Bitcoin address of the hackers. This has also happened in 2019.[citation needed]

See also[edit]

References[edit]

  1. ^"The WannaCry ransomware attack was temporarily halted. But it's not over yet". 15 May 2017.
  2. ^"Ransomware attack still looms in Australia as Government warns WannaCry threat not over". Australian Broadcasting Corporation. 14 May 2017. Retrieved 15 May 2017.
  3. ^Cameron, Dell (13 May 2017). "Today's Massive Ransomware Attack Was Mostly Preventable; Here's How To Avoid It". Gizmodo. Retrieved 13 May 2017.
  4. ^"Shadow Brokers threaten to release Windows 10 hacking tools". The Express Tribune. 31 May 2017. Retrieved 31 May 2017.
  5. ^Thomas P. Bossert (18 December 2017). "It's Official: North Korea Is Behind WannaCry". The Wall Street Journal. Retrieved 19 December 2017.
  6. ^"TSMC Chip Maker Blames WannaCry Malware for Production Halt". The Hacker News. Retrieved 7 August 2018.
  7. ^ abcMSRC Team (13 May 2017). "Customer Guidance for WannaCrypt attacks". Microsoft. Retrieved 13 May 2017.
  8. ^Jakub Kroustek (12 May 2017). "Avast reports on WanaCrypt0r 2.0 ransomware that infected NHS and Telefonica". Avast Security News. Avast Software, Inc.
  9. ^Fox-Brewster, Thomas. "An NSA Cyber Weapon Might Be Behind A Massive Global Ransomware Outbreak". Forbes. Retrieved 12 May 2017.
  10. ^Woollaston, Victoria. "Wanna Decryptor: what is the 'atom bomb of ransomware' behind the NHS attack?". WIRED UK. Retrieved 13 May 2017.
  11. ^ abc"Player 3 Has Entered the Game: Say Hello to 'WannaCry'". blog.talosintelligence.com. Retrieved 16 May 2017.
  12. ^ abcShields, Nathan P. (8 June 2018). "Criminal Complaint". United States Department of Justice.
  13. ^"NHS cyber attack: Edward Snowden says NSA should have prevented cyber attack". The Independent. Retrieved 13 May 2017.
  14. ^Graham, Chris (13 May 2017). "NHS cyber attack: Everything you need to know about 'biggest ransomware' offensive in history". The Daily Telegraph. Retrieved 13 May 2017.
  15. ^"NSA-leaking Shadow Brokers just dumped its most damaging release yet". Ars Technica. Retrieved 15 April 2017.
  16. ^Goodin, Dan. "10,000 Windows computers may be infected by advanced NSA backdoor". ARS Technica. Retrieved 14 May 2017.
  17. ^Goodin, Dan. "NSA backdoor detected on >55,000 Windows boxes can now be remotely removed". ARS Technica. Retrieved 14 May 2017.
  18. ^Broersma, Matthew. "NSA Malware 'Infects Nearly 200,000 Systems'". Silicon. Retrieved 14 May 2017.
  19. ^Cameron, Dell (13 May 2017). "Today's Massive Ransomware Attack Was Mostly Preventable; Here's How To Avoid It". Gizmodo. Retrieved 15 May 2017.
  20. ^"How One Simple Trick Just Put Out That Huge Ransomware Fire". Forbes. 24 April 2017. Retrieved 15 May 2017.
  21. ^"Russian-linked cyber gang blamed for NHS computer hack using bug stolen from US spy agency". The Telegraph. Retrieved 12 May 2017.
  22. ^ ab"What you need to know about the WannaCry Ransomware". Symantec Security Response. Retrieved 14 May 2017.
  23. ^Bilefsky, Dan; Perlroth, Nicole (12 May 2017). "Hackers Hit Dozens of Countries Exploiting Stolen N.S.A. Tool". The New York Times. ISSN 0362-4331. Retrieved 12 May 2017.
  24. ^ abClark, Zammis (13 May 2017). "The worm that spreads WanaCrypt0r". Malwarebytes Labs. malwarebytes.com. Retrieved 13 May 2017.
  25. ^ abSamani, Raj. "An Analysis of the WANNACRY Ransomware outbreak". McAfee. Retrieved 13 May 2017.
  26. ^Thomas, Andrea; Grove, Thomas; Gross, Jenny (13 May 2017). "More Cyberattack Victims Emerge as Agencies Search for Clues". The Wall Street Journal. ISSN 0099-9660. Retrieved 14 May 2017.
  27. ^Collins, Keith. "Watch as these bitcoin wallets receive ransomware payments from the global cyberattack". Quartz
Источник: https://en.wikipedia.org/wiki/WannaCry_ransomware_attack

1 thoughts to “Bitcoin 24 maggio”

Leave a Reply

Your email address will not be published. Required fields are marked *