{"id":14525,"date":"2020-05-22T12:18:28","date_gmt":"2020-05-22T10:18:28","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=14525"},"modified":"2024-10-05T23:03:50","modified_gmt":"2024-10-05T21:03:50","slug":"sterreich-it-der-stadt-weiz-mit-ransomware-infiziert","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/05\/22\/sterreich-it-der-stadt-weiz-mit-ransomware-infiziert\/","title":{"rendered":"City of Weiz (Austria): Computers infected with ransomware?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/05\/22\/sterreich-it-der-stadt-weiz-mit-ransomware-infiziert\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]The group behind the ransomware NetWalker claim to have infiltrated the computer networks of the city of Weiz in Austria. Currently I only have two sources, but no confirmation from the city, on this subject.<\/p>\n<p><!--more--><\/p>\n<h2>Background information about Weiz<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg04.met.vgwort.de\/na\/8bd84f02129a4b86bb668a3cf6ab1489\" width=\"1\" height=\"1\"><a href=\"https:\/\/de.wikipedia.org\/wiki\/Weiz\" target=\"_blank\" rel=\"noopener noreferrer\">Weiz<\/a>&nbsp; is a town with 11,701 citizens, which is located in the eastern part of Styria, Austria. The city is located on the Weizbach, a tributary of the Raab, a few kilometers south of the <a href=\"https:\/\/de.wikipedia.org\/wiki\/Liste_der_Landschaftsschutzgebiete_in_der_Steiermark\" target=\"_blank\" rel=\"noopener noreferrer\">Weizklamm<\/a> and about 25 kilometers northeast of <a href=\"https:\/\/de.wikipedia.org\/wiki\/Graz\" target=\"_blank\" rel=\"noopener noreferrer\">Graz<\/a>, the capital of Styria. Personally, I never made it to this area during my stays to <a href=\"https:\/\/web.archive.org\/web\/20240715012321\/https:\/\/www.borncity.com\/blog\/2014\/03\/06\/videotraining-windows-8-1-tipps-tricks-troubleshooting\/\" target=\"_blank\" rel=\"noopener noreferrer\">record video trainings for video2brain<\/a> in Graz. But it seems to be a nice place to go for hikers, according to <a href=\"https:\/\/www.steiermark.com\/de\/steiermark\/staedte-orte\/weiz_c1339\" target=\"_blank\" rel=\"noopener noreferrer\">this tourism site<\/a>. <\/p>\n<p>Weiz also seems to be the economic heart of the region, as several large companies of the automotive supplier MAGNA as well as construction companies like LIEB-Bau-Weiz and Strobl Construction are located in the area. Successor companies of the former ELIN UNION &#8211; Siemens AG \u00d6sterreich Transformatoren Weiz, Andritz HYDRO and ELIN Motoren &#8211; as well as the international Knill Group &#8211; are probably also represented there.<\/p>\n<h2>The Netwalker Group<\/h2>\n<p>Netwalker is a malicious software that infects Windows systems and encrypts files. In the <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/Ransom.PS1.NETWALKER.B?_ga=2.193533613.1079877318.1590136763-1671730187.1589220654\" target=\"_blank\" rel=\"noopener noreferrer\">Ransom.PS1.NETWALKER.B short description<\/a> by Trend Micro first samples of the ransomware were found as PowerShell scripts only at the beginning of May 2020. The distribution is done via downloads or in email attachments &#8211; probably using 'information about the corona virus' as bait. The <a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/netwalker-fileless-ransomware-injected-via-reflective-loading\/\" target=\"_blank\" rel=\"noopener noreferrer\">Trend Micro article here<\/a> deals with one case. The security researchers of Cynet have published <a href=\"https:\/\/www.cynet.com\/blog\/netwalker-ransomware-report\/\" target=\"_blank\" rel=\"noopener noreferrer\">this Netwalker ransomware<\/a> report with more information.&nbsp; <\/p>\n<p>In <a href=\"https:\/\/web.archive.org\/web\/20191104211732\/https:\/\/www.bundeskriminalamt.at\/202\/Internet_kennen\/files\/882016_Neue_in_sterreich_auftretende_Verschlsselungs_Trojaner_Ransomware.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">this document<\/a>, the Austrian Federal Criminal Police Office (Bundeskriminalamt \u00d6sterreich) warns in a more general form against ransomware attacks on companies and authorities in Austria. At the moment hardly a week passes without new types of malware appearing in Austria. New encryption Trojans (ransomware) appearing in Austria make the data of the infected systems irretrievably unusable! Even if victims pay a ransom, there is no guarantee that the data can be recovered. In addition, ransomware groups start uploading files to their own servers before encrypting them. Then they threaten to publish the often sensitive data.&nbsp; <\/p>\n<h2>Netwalker ransom group reports infection<\/h2>\n<p>I just found the following tweet from Catalin Cimpanu. He got the information that the NetWalker ransomware gang claims to have successfully infected the public administration network of the Austrian city of Weiz.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">The NetWalker ransomware gang claims to have infected the government network of Weiz, an Austrian town <a href=\"https:\/\/t.co\/zp9RcILQCB\">pic.twitter.com\/zp9RcILQCB<\/a><\/p>\n<p>\u2014 Catalin Cimpanu (@campuscodi) <a href=\"https:\/\/twitter.com\/campuscodi\/status\/1263659093627146242?ref_src=twsrc%5Etfw\">May 22, 2020<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/p>\n<p>&nbsp;<\/p>\n<p>The security company cybleinc.com <a href=\"https:\/\/web.archive.org\/web\/20200621131913\/https:\/\/cybleinc.com\/2020\/05\/20\/netwalker-ransomware-operators-targets-city-of-weiz-data-leak\/\" target=\"_blank\" rel=\"noopener noreferrer\">reports here<\/a>, that the backers of the NetWalker Ransomware have successfully infiltrated the IT of the city of Weiz. Afterwards the cyber criminals have probably leaked the captured confidential data. On the website of the security company you can find the following screenshot with the message of the ransomware group about the infection:<\/p>\n<p>(Source: cybleinc.com)  <\/p>\n<p>At present, cyber criminals seem to have only put excerpts of the data they have captured online. cybleinc.com has posted a screenshot of the directories.  <\/p>\n<p>(Source: cybleinc.com)  <\/p>\n<p>On the website of the security researchers there are screenshots of various files with the communication of employees of the building authority of the city of Weiz with applicants for building projects etc. What I can estimate so roughly: The files contain communication data of employees of the city of Weiz as well as companies and citizens. These personal data could be used for phishing attacks.  <\/p>\n<p>I have looked on the <a href=\"https:\/\/www.weiz.at\/\" target=\"_blank\" rel=\"noopener noreferrer\">website of the city<\/a>, but have not yet found any information about it. A press enquiry is in progress &#8211; in the hope that the city's e-mail system is not affected and that a reply will be sent.&nbsp; <\/p>\n<p><strong>Similar articles:<br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/2020\/05\/18\/revil-ransomware-hacker-verffentlichen-erste-trump-files\/\">Revil Ransomware hackers release first Trump files<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/05\/15\/neues-zum-ransomware-angriff-auf-ludwigshafener-versorger\/\">News on the ransomware attack on Ludwigshafen supplier<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/05\/12\/clop-ransomware-bei-technische-werke-ludwigshafen\/\">Clop Ransomware attack at Technische Werke Ludwigshafen<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/05\/12\/ransomware-bei-diebold-nixdorf\/\">Diebold Nixdorf victim of a Ransomware Attack<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/05\/07\/fresenius-vermutlich-opfer-eines-snake-ransomware-angriffs\/\">Fresenius probably victim of a Snake Ransomware attack<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/03\/14\/ransomware-infection-in-czech-university-hospital-of-brno\/\">Ransomware infection in Czech University Hospital of Brno<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/05\/20\/warning-infected-cookie-consent-logo-delivers-ransomware\/\">Warning: Infected Cookie Consent logo delivers Ransomware<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2020\/03\/17\/ransomware-schlgt-nachts-und-am-wochenende-zu\/\">Ransomware strikes at night and on weekends<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]The group behind the ransomware NetWalker claim to have infiltrated the computer networks of the city of Weiz in Austria. Currently I only have two sources, but no confirmation from the city, on this subject.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[243,69],"class_list":["post-14525","post","type-post","status-publish","format-standard","hentry","category-security","tag-ransomware","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=14525"}],"version-history":[{"count":1,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14525\/revisions"}],"predecessor-version":[{"id":35926,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/14525\/revisions\/35926"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=14525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=14525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=14525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}