CMC Infosec says malware used to attack Noi Bai Airport
VietNamNet Bridge - Soon after receiving a malware sample provided by Noi Bai International Airport, the victim of the cyberattack on July 29, CMC Infosec found it had the execution name ‘diskperf.exe’.
VietNamNet Bridge - Soon after receiving a malware sample provided by Noi Bai International Airport, the victim of the cyberattack on July 29, CMC Infosec found it had the execution name ‘diskperf.exe’.
Vietnam Airlines and VNCERT (Vietnam Computer Emergency Response Team) belonging to the Ministry of Information and Communication (MIC) then asked for help from Viettel, FPT, CMC and VNPT to deal with the incident, which affected more than 100 flights.
According to CMC Infosec, the name of the malware in CMC’s data was Troijan.Win32.Dropper.Encrypt.K.
When infected with the malware, computers see an image displayed on main screens, and many data files are encrypted and cannot be not restored without the key held by hackers.
CMC Infosec has updated the identification of diskperf.exe in the data base of all CMC anti-virus (free version) CMC Internet Security, and CISE versions (for businesses).
Businesses and users can download the latest version of the products from www.cmcinfosec.com, or contact 0932 206 446 for further support.
VnExpress quoted its sources as reporting that it was an intentional attack, which was considered thoroughly for a long time before the attack date.
According to VNISA (Vietnam Information Security Association), there are signs showing that hackers intruded into the system in mid-2014.
However, the malware used in the July 29 attack was the new one specifically for the attack. It went through normal security check tools, including anti-virus software.
VNISA said the traces left on the scene were not enough to say who the attackers were.
However, they had knowledge about the information system at the airports, both information structure and equipment operation. They also had the intention of controlling and completely disabling the system’s data.
Security experts have discovered that the back door had been exploited for a long time up until the attack was deployed.
According to Pham Hong Phuc, an independent expert, when attacking Vietnam Airlines’ website, hackers shared three links to the files containing customer data. The account there was created on July 25, 2016, or four days before the attack.
Therefore, the expert believes that the information about 400,000 members of Vietnam Airlines’ Golden Lotus Program might have been exploited four days before the attack.
Meanwhile, Nguyen Hai Tung, CIO of Vietnam Airlines, said Vietnam Airlines’ partners discovered abnormal signs on July 28 and issued warnings.
Kim Chi
Vietnam Airlines and VNCERT (Vietnam Computer Emergency Response Team) belonging to the Ministry of Information and Communication (MIC) then asked for help from Viettel, FPT, CMC and VNPT to deal with the incident, which affected more than 100 flights.
According to CMC Infosec, the name of the malware in CMC’s data was Troijan.Win32.Dropper.Encrypt.K.
When infected with the malware, computers see an image displayed on main screens, and many data files are encrypted and cannot be not restored without the key held by hackers.
CMC Infosec has updated the identification of diskperf.exe in the data base of all CMC anti-virus (free version) CMC Internet Security, and CISE versions (for businesses).
CMC Infosec has updated the identification of diskperf.exe in the data base of all CMC anti-virus (free version) CMC Internet Security, and CISE versions (for businesses). |
VnExpress quoted its sources as reporting that it was an intentional attack, which was considered thoroughly for a long time before the attack date.
According to VNISA (Vietnam Information Security Association), there are signs showing that hackers intruded into the system in mid-2014.
However, the malware used in the July 29 attack was the new one specifically for the attack. It went through normal security check tools, including anti-virus software.
VNISA said the traces left on the scene were not enough to say who the attackers were.
However, they had knowledge about the information system at the airports, both information structure and equipment operation. They also had the intention of controlling and completely disabling the system’s data.
Security experts have discovered that the back door had been exploited for a long time up until the attack was deployed.
According to Pham Hong Phuc, an independent expert, when attacking Vietnam Airlines’ website, hackers shared three links to the files containing customer data. The account there was created on July 25, 2016, or four days before the attack.
Therefore, the expert believes that the information about 400,000 members of Vietnam Airlines’ Golden Lotus Program might have been exploited four days before the attack.
Meanwhile, Nguyen Hai Tung, CIO of Vietnam Airlines, said Vietnam Airlines’ partners discovered abnormal signs on July 28 and issued warnings.
related news |
Kim Chi
MORE NEWS
Vietnamese retail market appealing to foreign investors
The nation is becoming an attractive retail market for companies globally with many regional and global FDI investors recently revealing their plans to increase capital and expand distribution networks here.
Eel porridge evokes hometown nostalgia
A warm bowl of Quang-style eel porridge with a fragrant aroma not only can win the hearts of diners, but also create nostalgia for the Quang people who live far from home.
Vietnamese banks that 'disappear' from the market
Some banks used to be very popular, with hundreds of thousands of customers, but they gradually disappeared from the market because of many reasons.
Discovering Hanoi’s famous incense making village
The craft village with a tradition of more than 100 years impresses visitors for its space that is filled with vibrant colors such as blue, red, yellow, etc. of beautifully shaped bouquets of incense.
Vietnam to reassert its position on the world coffee map
Vietnam is the world's second largest coffee exporter, but its impact on the world coffee market is not commensurate with its position, experts say.
VIETNAM BUSINESS NEWS MARCH 27/2023
Coffee exports to Netherlands enjoy three-digit growth
Youngest female Vietnamese Associate Professor receives Kovalevskaia Awards 2022
Prof. Dr. Le Minh Thang on March 7, 2023 was presented the 2022 Kovalevskaia Awards 2022 by Prime Minister Pham Minh Chinh.
Third pedestrian street opens in Hue City
The Hai Ba Trung Pedestrian Street was opened on Sunday evening in Hue City, becoming the third walking street in the central province of Thua Thien-Hue.
Entertainment and cultural events of the week (March 27-April 2)
Entertainment and cultural events in Vietnam's major cities on March 27-April 2.
VIETNAM NEWS HEADLINES MARCH 27/2023
Vietnam wins 17 prizes at International Robothon 2023
K'Duong breaks three youth weightlifting world records
Vietnamese weightlifter K'Duong broke three youth 55kg world records during the 2023 International Weightlifting Federation (IWF) World Youth Championships on March 26 which is taking place in Albania.
Struggling hoteliers seek Government support to revive from COVID-19 crisis
Small- and medium-sized hotels in HCM City are struggling with low occupancy rates and labour shortages, and are in need of support to recover from a COVID-19-induced slump, according to the municipal Department of Tourism.
Lion Championship MMA returns, first fight in Hanoi on April 1
The second season of the Lion Championship mixed martial arts will be back with great fighters and frightening fights in April.
Driftwood space launches in Hoi An
The first ever wood recycle space – driftwood village’s studio – has been launched in the ancient’s Cam Ha Commune on the most favourite bicycle riding road connecting the Old Quarter and An Bang beach.
Hoi An to host International Choir Competition
The event has received registrations from 20 teams representing nine countries and territories, and will feature 13 events with eight grades held at the city’s theatre.