
The true goal of hackers, who, with the help of the Petya -Member virus (Expetr, Notpetya, Petrwrap), attacked computer networks in dozens of countries of the world, was not receiving money, but the introduction of a malicious program in the infrastructure of Ukraine. This was reported by Reuters with reference to the statement of the Ukrainian cyber police.
Last Tuesday, June 27, the Mistress Virus, blocking access to data and requiring money for unlocking, attacked dozens of energy, telecommunication and financial companies and organizations first in Ukraine and Russia, and then spread around the world.
As it became known later, the experts suspected that the introduction of the Monk virus could be an operation of cover in order to quietly install hacker software on computers in state structures and commercial enterprises in Ukraine - such a "cyber bomb" can be used to conduct a large -scale attack on Ukrainian infrastructure.
The agency, citing a senior law enforcement source of Ukraine, reports that in Kyiv they also adhere to the version that the extortion of money from users of blocked computers was only a cover for the implementation of more global goals.
After the first reports appeared in the media about the distribution of Petya virus in Ukraine, official Kyiv accused the Russian intelligence services of Kiberatak. “Kiberataka was made under disguise that it is supposedly a virus that extracts money from a computer. According to preliminary information, this is an organized system from the special services of the Russian Federation. The purpose of this cyber attack is banks, the media, Ukrzaliznitsy, Ukrtelecom,” said Anton Gerashchenko, member of the College of the Ministry of Internal Affairs of Ukraine.
The press secretary of the Security Service of Ukraine Elena Gitlyanskaya, in turn, emphasized that mass hacker attacks on a number of Ukrainian companies could be organized from the territory of the Russian Federation or Donbass, which in Kyiv is considered occupied territory.
Bloomberg columnist Leonid Burshid notes that Kiev’s accusations against Moscow are absolutely not surprising, given the relationship between the two countries recently. Initially, experts did not see the geographical aspect in the spread of the virus, in many ways because Russian companies also hit, including Rosneft.
At the same time, in Ukraine, which was the first to suffer from the spread of the malicious program, the Petya virus was initially distributed through the ME DOC program, which replaced the Russian software for the 1C accounting department, after President Petro Poroshenko imposed sanctions against Russian IT companies.
The ME DOC program was installed in hundreds of state institutions and commercial organizations in Ukraine, and that is why, according to experts, Kiberatak was of such a large -scale nature. As a result of the cipher infection in Ukraine, computer networks of airports, railway stations, banks, mobile operators, energy companies, nuclear power plants and state institutions were out of order.
Specialists of the Kaspersky Laboratory and Comae, engaged in cybersecurity, also came to the conclusion that the distribution of the Mount virus could only be a cover. They drew attention to the fact that the Petya virus irrevocably encrypts files and the ability to return access to them, even paying the necessary ransom of $ 300, is simply not provided for, the Vedomosti newspaper writes.
The General Director and founder of Group-IB, which specializes in computer security and protection against cyberosis, Ilya Sachkov the day before suggested that the robber virus could be a method of testing cyber weapons, and not a banal way of hackers to make money.
“Perhaps this is a test of a certain technology of mass distribution of malicious code for impact on critical infrastructure objects. The opinion that this is testing cyber weapons, it is possible. Theoretically, it can be cyberism or special services of a country,” he said on the air of the Russia 24 television channel.
Skachkov added that this opinion is based on the massive distribution of the virus and a small amount of funds raised by PETYA developers. According to him, the dissemination of information about the virus in the media did not allow developers to raise significant funds.
“Now everyone is waiting for“ medicines ”, a unique“ pill ”that deciphers the computer. Given the media of history, a huge number of security specialists are trying to write it now unsuccessfully. People see information in the media, they are simply waiting,” Sachkov explained.
The first from the Petya virus attack on June 27, Russian and Ukrainian oil, telecommunication and financial companies suffered. According to preliminary estimates by Group -Ib, the virus attacked about 80 companies, most of which are Ukrainian.
In Russia, Rosneft, Bashneft, Mars, Nivea and Mondelez International (Alpen Gold chocolate) were attacked. The Bank of Russia also announced cyber attacks on Russian credit organizations that did not lead to violations in the work of banks.
The encrycher spread similarly to Wannacry Virus, the sensational in May. Petya blocks computers and requires $ 300 in bitcoins for unlocking. The Americans have already started an investigation into a new large -scale cyber attack. In addition, the United States and Israel decided to create a working group to prepare new methods for detecting cyberosis.
ESET viral laboratory experts believe that Petya’s infection began with Ukraine. According to the ESET rating for countries affected by the virus, Ukraine was most harmful. In second place among the affected states is Italy, in the third - Israel. The top ten also included Serbia, Hungary, Romania, Poland, Argentina, Czech Republic and Germany. Russia in this list is in 14th place.