Egypt to begin second phase of universal health insurance in Minya    Madrid trade talks focus on TikTok as US and China seek agreement    Egypt hosts 4th African Trade Ministers' Retreat to accelerate AfCFTA implementation    Egypt's Investment Minister, World Bank discuss strengthening partnership    El Hamra Port emerges as regional energy hub attracting foreign investment: Petroleum Minister    Power of Proximity: How Egyptian University Students Fall in Love with Their Schools Via Social Media Influencers    Egypt wins Aga Khan Award for Architecture for Esna revival project    Egypt's Sisi, Qatar's Emir condemn Israeli strikes, call for Gaza ceasefire    Egypt's gold prices hold steady on Sep. 15th    EHA launches national telemedicine platform with support from Egyptian doctors abroad    Egypt's Foreign Minister, Pakistani counterpart meet in Doha    Egypt condemns terrorist attack in northwest Pakistan    Emergency summit in Doha as Gaza toll rises, Israel targets Qatar    Egypt advances plans to upgrade historic Cairo with Azbakeya, Ataba projects    Egyptian pound ends week lower against US dollar – CBE    Egypt hosts G20 meeting for 1st time outside member states    Lebanese Prime Minister visits Egypt's Grand Egyptian Museum    Egypt to tighten waste rules, cut rice straw fees to curb pollution    Egypt seeks Indian expertise to boost pharmaceutical industry    Egypt prepares unified stance ahead of COP30 in Brazil    Egypt harvests 315,000 cubic metres of rainwater in Sinai as part of flash flood protection measures    Egyptian, Ugandan Presidents open business forum to boost trade    Al-Sisi says any party thinking Egypt will neglect water rights is 'completely mistaken'    Egypt's Sisi warns against unilateral Nile measures, reaffirms Egypt's water security stance    Egypt's Sisi, Uganda's Museveni discuss boosting ties    Egypt, Huawei explore healthcare digital transformation cooperation    Greco-Roman rock-cut tombs unearthed in Egypt's Aswan    Egypt reveals heritage e-training portal    Sisi launches new support initiative for families of war, terrorism victims    Egypt expands e-ticketing to 110 heritage sites, adds self-service kiosks at Saqqara    Palm Hills Squash Open debuts with 48 international stars, $250,000 prize pool    On Sport to broadcast Pan Arab Golf Championship for Juniors and Ladies in Egypt    Golf Festival in Cairo to mark Arab Golf Federation's 50th anniversary    Germany among EU's priciest labour markets – official data    Paris Olympic gold '24 medals hit record value    A minute of silence for Egyptian sports    Russia says it's in sync with US, China, Pakistan on Taliban    It's a bit frustrating to draw at home: Real Madrid keeper after Villarreal game    Shoukry reviews with Guterres Egypt's efforts to achieve SDGs, promote human rights    Sudan says countries must cooperate on vaccines    Johnson & Johnson: Second shot boosts antibodies and protection against COVID-19    Egypt to tax bloggers, YouTubers    Egypt's FM asserts importance of stability in Libya, holding elections as scheduled    We mustn't lose touch: Muller after Bayern win in Bundesliga    Egypt records 36 new deaths from Covid-19, highest since mid June    Egypt sells $3 bln US-dollar dominated eurobonds    Gamal Hanafy's ceramic exhibition at Gezira Arts Centre is a must go    Italian Institute Director Davide Scalmani presents activities of the Cairo Institute for ITALIANA.IT platform    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



An alert researcher, teamwork helped stem huge cyberattack
Published in Ahram Online on 14 - 05 - 2017

The cyberattack that spread malicious software around the world, shutting down networks at hospitals, banks and government agencies, was thwarted by a young British researcher and an inexpensive domain registration, with help from another 20-something security engineer in the U.S.
Britain's National Cyber Security Center and others were hailing the cybersecurity researcher, a 22-year-old identified online only as MalwareTech, who — unintentionally at first — discovered a so-called "kill switch" that halted the unprecedented outbreak.
By then the "ransomware" attack had crippled Britain's hospital network and computer systems in several countries in an effort to extort money from computer users. But the researcher's actions may have saved companies and governments millions of dollars and slowed the outbreak before computers in the U.S. were more widely affected.
MalwareTech, who works for cybersecurity firm Kryptos Logic, is part of a large global cybersecurity community who are constantly watching for attacks and working together to stop or prevent them, often sharing information via Twitter. It's not uncommon for them to use aliases, either to protect themselves from retaliatory attacks or for privacy.
In a blog post Saturday, MalwareTech explained he learned on Friday that networks across Britain's health system had been hit by ransomware, tipping him off that "this was something big."
He began analyzing a sample of the malicious software and noticed its code included a hidden web address that wasn't registered. He said he "promptly" registered the domain, something he regularly does to try to discover ways to track or stop malicious software.
Across an ocean, Darien Huss, a 28-year-old research engineer for the cybersecurity firm Proofpoint, was doing his own analysis. The western Michigan resident said he noticed the authors of the malware had left in a feature known as a kill switch. Huss took a screen shot of his discovery and shared it on Twitter.
Soon he and MalwareTech were communicating about what they'd found: That registering the domain name and redirecting the attacks to the server of Kryptos Logic had activated the kill switch, halting the ransomware's infections.
Huss and others were calling MalwareTech a hero on Saturday, with Huss adding that the global cybersecurity community was working "as a team" to stop the infections from spreading.
"I think the security industry as a whole should be considered heroes," he said.
But he also said he's concerned the authors of the malware could re-release it without a kill switch or with a better one, or that copycats could mimic the attack.
"I think it is concerning that we could definitely see a similar attack occur, maybe in the next 24 to 48 hours or maybe in the next week or two," Huss said. "It could be very possible."
Who perpetrated this wave of attacks remains unknown. This is already believed to be the biggest online extortion attack ever recorded, disrupting services in nations as diverse as the U.S., Russia, Ukraine, Brazil, Spain and India.
Europol, Europe's policing agency, called the attack unprecedented and said computers in more than 150 countries have been affected. Two security firms — Kaspersky Lab and Avast —said Russia was hit hardest.
These hackers "have caused enormous amounts of disruption— probably the biggest ransomware cyberattack in history," said Graham Cluley, a veteran of the anti-virus industry in Oxford, England.
In Russia, government agencies insisted that all attacks had been resolved. Russian Interior Ministry, which runs the national police, said the problem had been "localized" with no information compromised. Russia's health ministry said its attacks were "effectively repelled."
The ransomware exploits a vulnerability in Microsoft Windows that was purportedly identified by the U.S. National Security Agency for its own intelligence-gathering purposes.
Hackers said they stole the tools from the NSA and dumped them on the internet.


Clic here to read the story from its source.