December 3, 2014 By Jaikumar Vijayan 3 min read

The FBI has told U.S. businesses to be on the lookout for a particularly destructive type of malware that can wipe data from any system it infects. The malicious software is believed to be the same as the one recently used in the devastating attacks against Sony Pictures Entertainment, which resulted in the online leaks of five unreleased movies and corporate server downtime lasting several days.

Flash Alert

Details of the threat were contained in a flash alert that the FBI sent out late Monday to several businesses, Reuters said in a report Tuesday. The five-page document describes the malware as one capable of overwriting all data on the hard drives of infected computers, including the system master boot record, effectively making the computers unusable.

In its confidential email alert, the FBI warned that it will be extremely costly and nearly impossible to recover any overwritten data using standard forensic recovery processes. The alert notes that one company has already been victimized by the malware, but the company has not been specified, Reuters noted.

Email Delivery

The malware is typically delivered via a malicious email attachment, CSO Online said in its review of the FBI alert. Once installed on a system, the malicious software beacons its presence out to several hard-coded IP addresses belonging to command-and-control (C&C) servers in Italy, Thailand and Poland. The malware is designed to connect with the C&C servers every 10 minutes.

“If that fails, a two-hour sleep command is issued, after which the computer is shut down and rebooted,” the FBI memo reads. By the time the beaconing process starts, data is already being wiped from the hard drives.

Link to Sony Malware Attack

The alert’s timing has many convinced that the malware in the FBI advisory is the same or similar to the one used in the attack against Sony last week. If this is true, U.S. businesses have cause to be worried.

Though details of the Sony intrusion are only emerging, it appears the entertainment giant has suffered massive damage from the intrusion. Besides the five movies that were leaked, the cybercriminals also appear to have obtained a stunning amount of corporate data.

Documents released by the attackers include a spreadsheet with minute details on Sony’s payroll throughout divisions and a document that breaks down the severance costs for individual employees who were laid off this year at Sony and the reasons for their severance.

Other documents that were apparently grabbed from Sony’s corporate servers and leaked online include performance reviews for hundreds of employees; a spreadsheet comparing Sony employees’ salaries with those of its rivals; and a spreadsheet containing names, birth dates, Social Security numbers and other data from over 3,000 employees.

In addition to leaking data, the cybercriminals also appear to have wiped data from several of the company’s servers. The attacks, reportedly conducted by a group calling itself “Guardians of Peace,” are widely seen as retribution for Sony’s soon-to-be released movie “The Interview,” about a plot to assassinate North Korean leader Kim Jong-un.

Data Destruction

What has troubled many about the attacks is that the cybercriminals have actively sought to destroy data and systems in addition to stealing and leaking it.

“The main news story in the FBI advisory is the abrupt shift from theft to destructive vandalism,” said Mike Lloyd, chief technology officer at security vendor RedSeal, in an emailed statement. Most recent publicized breaches have involved the theft of payment card data, corporate information and other information, not sabotage and destruction.

“However, the attack on Sony appears to be quite distinct — while some theft of movie content did occur, the main attack was destructive,” Lloyd said. “This has happened occasionally — for example, an attack on Saudi Aramco — but not generally with this force, applied to a U.S.-based company.”

Image Source: Wikimedia Commons

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today