{"id":3929,"date":"2017-09-30T10:59:13","date_gmt":"2017-09-30T08:59:13","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=3929"},"modified":"2023-02-14T15:32:03","modified_gmt":"2023-02-14T14:32:03","slug":"wannacry-infection-stops-mercedes-benz-production","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2017\/09\/30\/wannacry-infection-stops-mercedes-benz-production\/","title":{"rendered":"WannaCry infection stops Mercedes Benz production?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"http:\/\/www.borncity.com\/blog\/2017\/09\/30\/wannacry-infektionen-bei-daimler\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Strange story that's going around right now. In German factories of car maker Mercedes Benz (Daimler AG) production computers are supposed to be infected with WannaCry ransomware. Also vendor Festo is claimed to be infected with WannaCry.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/ssl-vg03.met.vgwort.de\/na\/64bee3c3ee6c4a71b6f6b679ae7dc4a2\" alt=\"\" width=\"1\" height=\"1\" \/>First of all, I must say, that the story isn't officially confirmed (from the companies &#8211; but I have my own sources). German news site heise.de has published yesterday the article <a href=\"https:\/\/www.heise.de\/security\/meldung\/Daimler-WannaCry-hat-offenbar-neue-Opfer-gefunden-3847232.html\" target=\"_blank\" rel=\"noopener\">Daimler: WannaCry hat offenbar neue Opfer gefunden<\/a> (translation means <em>Daimler: WannaCry found new victims<\/em>).<\/p>\n<h2>First reports \u2013 after reader tips<\/h2>\n<p>The editorial team at heise refers to reports from different readers that production at <a href=\"https:\/\/www.daimler.com\/en\/\" target=\"_blank\" rel=\"noopener\">Daimler<\/a> sites is affected. According to these sources, a WannaCry infection is believed to have taken place in Mercedes-Benz plants such as Bremen, Hamburg and Untert\u00fcrkheim.<\/p>\n<h2>Unpatched Windows XP systems are involved?<\/h2>\n<p>How can this happens at end of September 2017? It is reported that industrial robots, using Windows XP for control, were no longer functional. So it seems, that unpatched Windows XP systems was involved into this case. Manufacturer Festo is also said to have been affected by the WannaCry Trojan horse.<\/p>\n<blockquote><p>Note: I'm aware, that Windows XP, Windows 8.x and Windows 10 are probably not vulnerable for WannaCry. But maybe there are Windows 7 machines involved &#8211; or it's a modified version of this trojan. And it is known, that WannaCry infections forces Windows XP systems into a blue screen &#8211; so reports, that industry robots controlled by Windows XP makes a lot of sense. Windows XP isn't the source to spread a WannaCry infection, but will be affected too.<\/p><\/blockquote>\n<h2>Not confirmed by speakers of Daimler and Festo \u2026<\/h2>\n<p>The editorial team at heise has reached out to Daimler and Festo for a statement. A speaker from Festo states that no attacks are known. A speaker from Daimler\/Mercedes Benz explained that production is running &#8211; but no statement has been made about WannaCry infection.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"WannaCry-Meldung\" src=\"https:\/\/web.archive.org\/web\/20220130150333\/https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/05\/Ransom.WannaCrypt2.1.png\" alt=\"WannaCry-Meldung\" width=\"661\" height=\"497\" \/><\/p>\n<p>The WannaCry Trojan has led to a number of failures in the automotive industry. At Renault, the initial infection in May 2017 led to production stoppages, and Honda was also affected by something like this. And Korean electronic producer LG was still a victim of WannaCry in South Korea in August 2017.<\/p>\n<blockquote><p>Remark: I've covered the production stops in the car manufacturing industry within my German blog in several blog posts. Links may be found within my <a href=\"http:\/\/www.borncity.com\/blog\/2017\/09\/30\/wannacry-infektionen-bei-daimler\/\" target=\"_blank\" rel=\"noopener\">German article<\/a>.<\/p><\/blockquote>\n<h2>\u2026 but my source confirmed it also<\/h2>\n<p><strong>Update:<\/strong> An reliable source (that will stay anonymous) has told me today (September 30, 2017) that the German Daimler plant in Rastatt is\/was also affected. My source spoke of a 'quite upset mood' within the IT department.<\/p>\n<p><strong>Update 2:<\/strong> Another source (that will stay anonymous) has send me the following details \u2013 I've translated it to English.<\/p>\n<blockquote><p>&#8230; but the production IT of Daimler in K\u00f6lleda (motor factury) and Kamenz (LiIon battery factory) almost breathed a sigh of relief yesterday at 9h, after [Mercedes Benz production IT at] Untert\u00fcrkheim reported more than 1500 cases.<\/p>\n<p>This infections affects massively virtual machines from plant suppliers, personal measuring computers and systems in 24\/7 operation.<\/p><\/blockquote>\n<p><strong>Update 3:<\/strong> I've reached out to Daimler Press department and received the following statement from a speaker:<\/p>\n<blockquote><p>Our production is running. Please understand that we do not comment on IT security issues.<\/p><\/blockquote>\n<p><strong>Update 4:<\/strong>\u00a0I found a German\u00a0<a href=\"https:\/\/twitter.com\/Flusslied\/status\/914166600915472384\" target=\"_blank\" rel=\"noopener\">Tweet<\/a>\u00a0&#8211; which makes a lot sense, if we know the context.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p dir=\"ltr\" lang=\"de\">Auf Dads Arbeit wird das sogar f\u00fcr die Steuerung von Industrierobotern benutzt. Gestern wurde es von WannaCry befallen.<\/p>\n<p>\u2014 Relaxo (@Flusslied) <a href=\"https:\/\/twitter.com\/Flusslied\/status\/914166600915472384?ref_src=twsrc%5Etfw\">30. September 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>A raw translation says: '<em>On some computers at my parents workplaces, Windows XP is still in use. That's digitalisation in Germany. In dad's company they are using still Windows XP to control industry robots. Yesterday they had a WannaCry infection.<\/em>'<\/p>\n<p>So, independent from what speakers of Mercedes Benz\/Daimler told us, the incident seems real.<\/p>\n<p><strong>Similar articles:<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2017\/06\/27\/petya-ransomware-is-back-using-wannacry-vulnerabilties\/\">Petya ransomware is back \u2013 using WannaCry vulnerabilties<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2017\/05\/13\/ransomware-wannacry-infected-worldwide-thousands-of-windows-systems\/\">Ransomware WannaCry infected worldwide thousands of Windows systems<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2017\/05\/25\/wannacry-co-eternalblue-vulnerability-checker-und-crysis-ransomware-decryptor\/\">WannaCry &amp; Co.: EternalBlue Vulnerability Checker and Crysis Ransomware Decryptor<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Strange story that's going around right now. In German factories of car maker Mercedes Benz (Daimler AG) production computers are supposed to be infected with WannaCry ransomware. Also vendor Festo is claimed to be infected with WannaCry.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[243,832,194],"class_list":["post-3929","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-ransomware","tag-wannacry","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/3929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=3929"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/3929\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=3929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=3929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=3929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}