A new strain of ransomware nicknamed “Bad Rabbit” has been found spreading in Russia, Ukraine and elsewhere.

‘Bad Rabbit,’ bears similarities to the WannaCry and Petya outbreaks that hit computer systems earlier this year.

Bad Rabbit, which appears to have originated in Ukraine, hit computers at the Odessa international airport in southern Ukraine and the Kiev subway. Prominent Russian media outlets such as Interfax and Fontanka also reported being targeted Tuesday.

The Moscow-based cybersecurity firm Group-IB said Wednesday the ransomware also tried to penetrate the computers of major Russian banks but failed. None of the banks has reported any attacks, though the Russian Central Bank said Wednesday it had recorded BadRabbit’s attack on its systems but they were not compromised.

“In some of the companies, the work has been completely paralysed, servers and workstations are encrypted,” head of Russian cyber-security firm Group-IB, Ilya Sachkov, told the TASS news agency.

It is not yet known how far this new malware will be able to spread. Meanwhile, US officials said they had “received multiple reports of Bad Rabbit ransomware infections in many countries around the world”.

The US computer emergency readiness team said it “discourages individuals and organisations from paying the ransom, as this does not guarantee that access will be restored”.

Starts with social engineering

The Bad Rabbit outbreak appears to have got its start via files on hacked Russian media websites, using the popular guise of pretending to be an Adobe Flash installer.

If Bad Rabbit infects your computer, it attempts to spread across the network using a list of usernames and passwords buried inside the malware. These credentials include passwords straight out of a worst passwords list. Another reminder, if one were needed, that all your passwords need to be strong, even the ones you use behind the safety of a corporate firewall.

From there, it encrypts not only your files, adding encrypted at the end of each filename, but also your computer’s MBR (Master Boot Record). You are then greeted with the following message and asked to submit payment via a Tor hidden service (an anonymous Dark Web website):

If you visit the Bad Rabbit website using the Tor Browser, you will be “invited” to pay a fee for the decryption key; at the time of writing [2017-10-25T16:45Z], the crooks were demanding XBT 0.05 (1/20th of a Bitcoin), currently about $280:

Here are some general tips to raise your defenses againt this sort of outbreak:

  1. Ditch Flash altogether. Fake flash installers and updates only work as a social engineering tactic if you use or want Flash. By removing Flash entirely you not only protect yourself from Flash zero-day holes , but also eliminate the temptation to download fake updates.
  2. Patch promptly. Outbreaks such as NotPetya and WannaCry exploited a vulnerability for which patches were already available. Don’t lag behind once patches are available for known security holes, the crooks will be only too happy to take advantage.
  3. Remember your backups. Make them regularly, and keep a recent backup both offline and offsite, so you can access it even if your workplace ends up off limits due to fire, flood or some other cause not related to malware.
  4. Don’t make users into administrators. When you want to perform administrative tasks, promote yourself to an administrator account, and relinquish those privileges as soon as you can. Network-aware malware like Bad Rabbit can spread without even needing to guess passwords if you already have administrator-level access to other computers on the network.

Source :Naked security by Sophos