Swiper! No Wiping!

Last night I put together some words called p0wn3d . This was basically an outlet after watching things unfold … again … with malware encrypting machines. My point was as much as anything the unseen impact, the real payloads, and the fact that now this Pandora’s Box of tricks has been opened. There is no closing it.

The news yesterday showed the email/account the alleged perpetrator (avoiding using the phrase ‘threat actor’ here as it leaves me as uncomfortable as when people use the word ‘cyber’) had set up being closed down by the provider.

Closed down you say. Riiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiight.

Abuse tickets. ‘Funny old game. You are either the company that “gives them 24/48 hours to respond” (values money over reputation / damage) – or you are the company “who checks it out and uses common sense to close it down” (smaller, more vulnerable to the damage a prolonged attack, ethics). However, whoever you are, you get a bell from New Scotland Yard / NCSC (or to be fair – trading standards et al.) and you listen in.

… allegedly … what would I know about such things afterall …

So why was this not kept up, and monitored?

…or is that just me.

Equally – high value targets? … but asking for a tiny ransome?

Not. Adding. up.

This morning the news regarding what not/petya does seemed to be coming through that this was in fact even more suspect, and looked to be a state level attack – with no means to decrypt – this was simply wiping away the hopes and dreams of the filesystem leaving you up shit creek sans paddle.

Here is a nice article – if a little long, breaking down what petya / notpetya does for a day job. Without putting too fine a point on it – it wipes not encrypts. It trashes file systems, no coming back from that. Money is not an object, it is a distraction, gravy for the media.

Ladies and gentlemen. It has begun.

