{"id":9569,"date":"2020-02-07T10:42:23","date_gmt":"2020-02-07T15:42:23","guid":{"rendered":"http:\/\/pappp.net\/?guid=e5a8a3ec31b6917cf26c6a99d026d00c"},"modified":"2020-02-07T10:42:23","modified_gmt":"2020-02-07T15:42:23","slug":"new-ransomware-targets-industrial-control-systems","status":"publish","type":"post","link":"https:\/\/pappp.net\/?p=9569","title":{"rendered":"New Ransomware Targets Industrial Control Systems"},"content":{"rendered":"<p class=\"syndicated-attribution\">Source: <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2020\/02\/new_ransomware_.html\">Schneier on Security<\/a><\/p>\n<div style=\"background-color : #fff7d5;\n\t\t\tborder-width : 1px; padding : 5px; border-style : dashed; border-color : #e7d796;margin-bottom : 1em; color : #9a8c59;\">Article note: Your regularly scheduled reminder about not plugging critical systems into the Internet. \r\nAs the footnote indicates, this is going to complicate the \"Technology term or Pok\u00e9mon\" game, because now Ekans is both.<\/div><p>EKANS is a <a href=\"https:\/\/www.wired.com\/story\/ekans-ransomware-industrial-control-systems\/\" rel=\"noopener noreferrer\">new ransomware<\/a> that targets industrial control systems:<\/p>\n\n<blockquote><p>But EKANS also uses another trick to ratchet up the pain: It's designed to terminate 64 different software processes on victim computers, including many that are specific to industrial control systems. That allows it to then encrypt the data that those control system programs interact with. While crude compared to other malware purpose-built for industrial sabotage, that targeting can nonetheless break the software used to monitor infrastructure, like an oil firm's pipelines or a factory's robots. That could have potentially dangerous consequences, like preventing staff from remotely monitoring or controlling the equipment's operation.\n\n<\/p><p>EKANS is actually the second ransomware to hit industrial control systems. According to Dragos, another ransomware strain known as Megacortex that first appeared last spring <a href=\"https:\/\/www.accenture.com\/_acnmedia\/pdf-106\/accenture-technical-analysis-megacortex.pdf\" rel=\"noopener noreferrer\">included all of the same industrial control system process-killing features<\/a>, and may in fact be a predecessor to EKANS developed by the same hackers. But because Megacortex also terminated hundreds of other processes, its industrial-control-system targeted features went largely overlooked. <\/p><\/blockquote>\n\n<p>Speculation is that this is criminal in origin, and not the work of a government.<\/p>\n\n<p>It's also the first malware that is named after a Pok&eacute;mon character. <\/p>","protected":false},"excerpt":{"rendered":"<p>EKANS is a new ransomware that targets industrial control systems:<\/p>\n<p>But EKANS also uses another tri&#8230;<\/p>\n<p> <a href=\"https:\/\/pappp.net\/?p=9569\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[226],"tags":[],"class_list":["post-9569","post","type-post","status-publish","format-standard","hentry","category-news-2"],"_links":{"self":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/9569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9569"}],"version-history":[{"count":0,"href":"https:\/\/pappp.net\/index.php?rest_route=\/wp\/v2\/posts\/9569\/revisions"}],"wp:attachment":[{"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pappp.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}