Results 1 to 9 of 9

Thread: NHS allegedly hit by ransomeware attack

  1. #1
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    NHS allegedly hit by ransomeware attack

    No details yet, but just spotted this

    http://www.telegraph.co.uk/news/2017...e-cyberattack/
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  2. #2
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,027 times in 678 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS

    Re: NHS allegedly hit by ransomeware attack

    It relies on a WIndows flaw fixed in March, which NHS IT didn't bother applying.

  3. #3
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: NHS allegedly hit by ransomeware attack

    Seems the NHS isn't alone, Telefonica in Spain and several other corporations affected. It seems that fake invoice e mails have been used as the vector - I had a couple of those two days ago! One was allegedly from BT, quite plausible until I checked the headers.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  4. #4
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,027 times in 678 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS

    Re: NHS allegedly hit by ransomeware attack

    Quote Originally Posted by peterb View Post
    Seems the NHS isn't alone, Telefonica in Spain and several other corporations affected. It seems that fake invoice e mails have been used as the vector - I had a couple of those two days ago! One was allegedly from BT, quite plausible until I checked the headers.
    Yeah, lots of targets hit around Europe. Nobody applying their "this is critical apply this or die" security fixes.

  5. #5
    Cul-de-Sachian sybrows's Avatar
    Join Date
    Apr 2004
    Location
    Brighthelm
    Posts
    841
    Thanks
    11
    Thanked
    7 times in 7 posts
    • sybrows's system
      • Motherboard:
      • MSI P55-GD65
      • CPU:
      • Intel Core i5 750 @ 3.8+Corsair H50
      • Memory:
      • 8 gig Crucial XMS 3 DDR3 1600
      • Storage:
      • 1X2tb WD Green
      • Graphics card(s):
      • EVGA 670 FTW edition
      • PSU:
      • Akasa 500 Watt
      • Case:
      • Coolermaster Stacker 8100
      • Operating System:
      • Win 8.1 Pro 64bit
      • Monitor(s):
      • 24" Iiyama LED LCD
      • Internet:
      • Virgin 75MB

    Re: NHS allegedly hit by ransomeware attack

    I've worked in an environment with a recurrent rmware issue


    This maybe more directed?!
    Last edited by sybrows; 12-05-2017 at 10:38 PM. Reason: forgot the last bit

  6. #6
    Senior Member walibe's Avatar
    Join Date
    Jul 2003
    Location
    Lyneham
    Posts
    941
    Thanks
    22
    Thanked
    24 times in 18 posts
    • walibe's system
      • Motherboard:
      • ASUS P8P67B Pro
      • CPU:
      • iMac 2017
      • Memory:
      • 16 Gig Corsair Vegence
      • Storage:
      • 10 T.B Total
      • Graphics card(s):
      • Nvida GTX 755M
      • Operating System:
      • Mavericks / Windows 8.1
      • Monitor(s):
      • 27"
      • Internet:
      • BT Fibre

    Re: NHS allegedly hit by ransomeware attack

    These were all made possible thanks to an exploit the NSA had which was made public by wiki leaks who are now calling for the NSA to release information of all exploits that they know of.

    Well done wiki leaks... well done.

    This appears to be world wide. I've seen a lot of ransomewear recently but it's been in the background and hasn't been close to the scale of state sponsored campaigns. Well looks like some criminals gangs have been busy. Russians also hit btw.

    Oddly I finished a SANS forensic course today and was looking at just this kind of thing this afternoon on my home lab including how to exploit the older versions of the SMB protocol.

    To me this is far more scary than nuclear weapons or chemical weapons. The cold war and Cuban missile crisis have nothing on what's happening now days.

    Guess the new (ish) NCSC is going to be busy.
    Last edited by walibe; 12-05-2017 at 11:39 PM.
    Laptop - Macbook Pro Retina 13" (Early 2015) i5/8GB/256GB
    Desktop 1 - iMac 27" (late 2012) i7/32GB/1TB Fusion Drive
    Desktop 2 - i7 2600K/32GB/1TB/GTX 760
    Server - HP DL160 G6 2 x Hex Core Xenon x5650/64GB/8TB
    NAS - ASUSTOR 604T ATOM Dual Core/3GB/16TB

  7. #7
    Senior Member walibe's Avatar
    Join Date
    Jul 2003
    Location
    Lyneham
    Posts
    941
    Thanks
    22
    Thanked
    24 times in 18 posts
    • walibe's system
      • Motherboard:
      • ASUS P8P67B Pro
      • CPU:
      • iMac 2017
      • Memory:
      • 16 Gig Corsair Vegence
      • Storage:
      • 10 T.B Total
      • Graphics card(s):
      • Nvida GTX 755M
      • Operating System:
      • Mavericks / Windows 8.1
      • Monitor(s):
      • 27"
      • Internet:
      • BT Fibre

    Re: NHS allegedly hit by ransomeware attack

    If any of you are genuinely interesting in following this keep an eye on the internet store center.

    https://isc.sans.edu

    They are 24/7 and as many of them are SANS instructors who have taught us and other well establish SMEs they tend to get samples of new malware etc pretty damn quickly forward often by former students etc.
    Laptop - Macbook Pro Retina 13" (Early 2015) i5/8GB/256GB
    Desktop 1 - iMac 27" (late 2012) i7/32GB/1TB Fusion Drive
    Desktop 2 - i7 2600K/32GB/1TB/GTX 760
    Server - HP DL160 G6 2 x Hex Core Xenon x5650/64GB/8TB
    NAS - ASUSTOR 604T ATOM Dual Core/3GB/16TB

  8. Received thanks from:

    peterb (14-05-2017)

  9. #8
    Splash
    Guest

    Re: NHS allegedly hit by ransomeware attack

    As it's not been mentioned yet - Microsoft have released patches for a bunch of unsupported platforms to protect against this

    https://blogs.technet.microsoft.com/...acrypt-attacks

    I know that everyone here is patched and running a supported OS, or has some form of mitigation against this kind of risk in place (see Saracen's number of posts on the matter), but you probably have family and friends that don't (and who also have no backups). Do them a favour and share that information with them.

  10. Received thanks from:

    peterb (14-05-2017)

  11. #9
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: NHS allegedly hit by ransomeware attack

    Thank you everyone who posted here. As this now covered on a general HEXUS news post here http://forums.hexus.net/hexus-news/3...cross-nhs.html

    I'll close this thread.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •