Microsoft Uncovers Disguised Destructive Malware Targeting Ukrainian Government

Microsoft reveals that destructive malware disguised as ransomware is infecting Ukrainian government agencies and related IT firms. The company deploys defensive updates and shares threat intelligence to help the cybersecurity community counter the ongoing attacks.

Microsoft reports the discovery of destructive malware targeting several Ukrainian government agencies and affiliated organizations. The malicious software is disguised as ransomware, but it actually renders infected computer systems completely inoperable if activated by the threat actors. The company detects this activity on January 13, 2022, and immediately begins analyzing the unique characteristics of the unknown group behind the attacks.

The impacted organizations include critical executive branch agencies, emergency response functions, and an IT firm that manages websites for both public and private sector clients. Microsoft actively notifies all identified victims and partners with other cybersecurity providers to share critical intelligence. The company also alerts appropriate government authorities in the United States and other nations, warning that the total number of infected organizations could grow as the investigation continues.

To combat this threat, the Microsoft Threat Intelligence Center (MSTIC) publishes a detailed technical blog post to help the security community detect and defend against the malware. Microsoft already builds and deploys protective updates through Microsoft 365 Defender Endpoint Detection and Anti-virus protections for all cloud and on-premises users. Furthermore, the investigation finds no evidence that these attacks exploit any vulnerabilities in Microsoft products or services.

Read More at the original source →