РЕКЛАМА
РЕКЛАМА
HomeRussian hacker groups have used WinRAR as a "cyber weapon" to attack Ukraine
Russian hacker groups have used WinRAR as a "cyber weapon" to attack Ukraine
7196
Add as a Preferred Source
0
0

Russian hacker groups have used WinRAR as a "cyber weapon" to attack Ukraine

Ця стаття доступна наступними мовами

The Ukrainian government has reported that Russian hackers used the WinRAR file compression utility to delete data from computers at several government agencies. According to the Ukrainian Computer Emergency Response Team (CERT-UA), the Sandworm group may have gained access to compromised VPN accounts that provided access to Ukraine's official government networks.

The hackers apparently used a script called RoarBAT to search for files on the target machine with extensions including.doc,.docx,.rtf,.txt,.xls,.xlsx,.ppt,.pptx,.jpeg,.jpg,.zip,.rar,.7z, and several others, and then used WinRAR to archive the files and the "-df" option, which automatically deletes the source files after archiving. The RoarBAT script then deleted the archived files, resulting in a complete loss of data.

The WinRAR utility, which is widely used on most modern computers, can be a reason for their compromise. It seems that Linux systems are not immune to such attacks, and the BASH script and the standard dd tool can be used to compromise them, despite the initial impression of security.

CS2Skin
100% Deposit Bonus, Daily Giveaways, Highest RTP + Rewards
CS2Skin
Отримати бонус
CSGOGem
Free Coins Hourly + 5% Deposit Bonus
CSGOGem
Отримати бонус
Clash GG
5% deposit bonus up to 100 gems
Clash GG
CS:GO
Отримати бонус
CSGOEmpire
FREE CASE on Signup - code: EGW
CSGOEmpire
CS:GO
Отримати бонус
CaseHug
Bonus: 20% to every top-up + 1$ with code EGWNEWS
CaseHug
Отримати бонус

The Ukrainian Center for Information Security CERT-UA claims that the recent hack resembles the attack on the state information agency "Ukrinform" earlier this year, which was linked to the Sandworm group.

"The methods of implementing the malicious plan, the IP addresses of the attackers, and the use of a modified version of RoarBat indicate similarity to the cyber attack on Ukrinform," noted CERT-UA.

Не пропустіть кіберспортивні новини та оновлення! Підпишіться та отримуйте щотижневий дайджест статей!
Зареєструватися

The center also strongly recommends that all Ukrainian state operators improve the security of their VPNs with multi-factor authentication. This should probably be a lesson for all of us.

РЕКЛАМА
Залишити коментар
Вам сподобалася стаття?
0
0

Коментарі

Останні новини
Funko Pops розкрили нові подробиці персонажів фільму «Месники: Судний день»
612
«Месники: Завершення» знову став найкасовішим фільмом, побивши рекорд «Аватара»
631
«Людина-павук: Абсюлютно новий день» отримає перевипуск – включаючи деякі видалені сцени
1220
Новий фільм «Зоряні війни» зніме колишній режисер «Людини-павука»
1384
«Месники: Завершення. Екстра» – Злито нові кадри та сцени після титрів: розкрито всі деталі
1832
Результати тестування Apple M6 демонструють можливості 2-нм мікросхем
1522
«Шибайголова: Народжений заново» офіційно завершується після 3-го сезону
1368
Sony запатентувала спосіб оплати ігор для PS5 за допомогою контролера
1485
«Месники: Завершення. Екстра» —: оприлюднено подробиці нових сцен та сцен після титрів
3719
Від пасивного оплески до взаємодії в реальному часі: як технології трансформують цифрові розваги
1155
РЕКЛАМА
БЕЗКОШТОВНА ПІДПИСКА НА ЕКСКЛЮЗИВНИЙ ВМІСТ
Отримайте добірку найважливіших і найактуальніших новин галузі.
*
*Тільки важливі новини, без спаму.
ПІДПИСАТИСЯ
ПІЗНІШЕ