
The new Badrabbit-Milk virus struck computers in five countries, according to the International Company to prevent and investigate cybercressions of Group-Ib. The infection began on Tuesday after noon in Russia on and Ukraine.
Most infections, 65 percent, occurred in Russia. Due to the Badrabbit attack, the sites of Interfax and Fontanka became inaccessible . The virus also tried to infect the systems of Russian banks from the first twenty. In Ukraine (12 percent of the infection), servers of the Odessa Airport and the Kyiv Metro were injured. Computers were also attacked in Bulgaria, Turkey and Japan. Now, according to Group-Ib, the distribution of the virus is completed.
The virus used fake certificates that simulate Symantec to penetrate computers. This allowed the virus to remain unnoticed until activation. A code that demonstrated to visitors a fake window, offering to install the Adobe Flash player, was loaded to the infected resources.
After activating the virus, part of the data on the disk was encrypted. Attackers demanded to transfer 0.05 bitcoin (at the current rate - about $ 283), promising to give the key to decryption.
Badrabbit is a more advanced version of the Petya virus because it also encrypts the contents of the hard drive, but uses fundamentally new vulnerabilities for this.
At the end of June, the Petya Milu-Miller, which blocks the loading of the operating system, appeared. The attack began with Ukraine, which suffered the most from the cyber attack, computer networks of the government of Ukraine, the Kiev city government administration, dozens of state and private large banks and companies becamevictims of a massive cyber attack , which in some cases led to the stop of their operations.
The virus quickly spread around the world. According to the ESET antivirus laboratory, in the top ten countries that the virus affected the most sensitive, Italy, Israel, Serbia, Hungary, Romania, Poland, Argentina, the Czech Republic and Germany also entered. In Russia, which was in 14th place, the Rosneft and Bashneft server, the Evraz metallurgical company and a number of smaller companies were subjected to the virus attack.