Skip to main content

Black Listed News
Trending Articles:
Trending Articles:

Virus That Haunted Aramco In 2012 Is Back

Published: December 12, 2018
Share | Print This


Source: Oil Price

A variant of the Shamoon malware that hit Saudi Aramco’s servers six years ago is back, Axios reports, citing a release from the cybersecurity unit of Alphabet, Chronicle. According to the Chronicle release, the company had detected a file infected with Shamoon in its database VirusTotal.

The malware, Chronicle said, was uploaded from Italy and is different from the previous two variants. Those moved through networks via pre-programmed credentials while this one stays on the computer it is installed on first. There is no command and control infrastructure that would allow the attackers to communicate with the virus, and what the virus does this time is encrypt all files irreversibley rather than replacing them with politically significant images, Axios reports.

While the cybersecurity experts at Chronicle figure out what the malware is all about this time, they do note it comes on the heels of a report from Italy’s oilfield services major Saipem that it had become the target of a cyberattack, with the most severe blow suffered by its network in the Middle East.

 

Reuters quoted Saipem’s head of digital and innovation operations, Mauro Piasere, as saying the company’s servers in the UAE, Saudi Arabia, and Kuwait had been affected by malware, with the origin of the attack Chennai, India.

“The servers involved have been shut down for the time being to assess the scale of the attack,” Piasere said.

Chronicle’s experts, for their part, said "While Chronicle cannot directly link the new Shamoon variant to an active attack, the timing of the malware files comes close to news of an attack on an Italian energy corporation with assets in the Middle East."

In January 2017, Saudi Arabia issued a warning to local organizations that the Shamoon virus that had hit state-held oil giant Saudi Aramco in 2012 has resurfaced in a new variant. The Shamoon 2, which completely wiped out computer disks, reportedly targeted 15 government agencies and private organizations, state media reported at the time.

By Irina Slav for Oilprice.com

Related Articles:

The Russian military is inside hundreds of thousands of routers owned by Americans and others around the world, a top U.S. cybersecurity official said on Friday. The presence of Russian malware on the routers, first revealed in May, could enable the Kremlin to steal individuals’ data or enlist their devices in a massive attack intended to disrupt global economic activity or target institutions.

In what may soon emerge as the latest middle-east diplomatic scandal, not to mention roil the just concluded OPEC deal, Bloomberg reports that state-sponsored hackers have conducted a "series of destructive attacks on Saudi Arabia over the last two weeks, erasing data and wreaking havoc in the computer banks of the agency running the country’s airports and hitting five additional targets." Additionally, “several” government agencies were also targeted in attacks that came from outside the Kingdom, according to state media.

Share This Article...



Image result for patreon

Emigrate While You Still Can!

Loading...


Image result for patreon


PLEASE DISABLE AD BLOCKER TO VIEW DISQUS COMMENTS

Ad Blocking software disables some of the functionality of our website, including our comments section for some browsers.





Login with patreon to gain access to perks!

SIGN UP TO GET BLACKLISTED NEWS DELIVERED RIGHT TO YOUR INBOX

Enter your email address:





More Blacklisted News...

Blacklisted Radio
Blacklisted Nation
On Patreon
On Gab
On Twitter
On Reddit
On Facebook
Blacklisted Radio:
Republic Broadcasting
Podcasts on Youtube
Podcasts on Demand
On Iheart Radio
On Spreaker
On Stitcher
On iTunes
On Tunein

Our IP Address:
198.245.55.242

Sponsors:
Garden office

good
longboard
brands


Advertise Here...






BlackListed News 2006-2019
Privacy Policy