tao Posted June 14, 2017 Share Posted June 14, 2017 Don't touch that email! London uni fears 0-day used to cram network with ransomware Antivirus didn't pick up software nasty, say UCL IT peeps University College London is tonight tackling a serious ransom outbreak that has scrambled academics' files. It is feared the software nasty is exploiting a zero-day vulnerability, or is a previously unseen strain of malware as antivirus defenses did not spot it in time. Eggheads at the UK uni are urged to not open any more email attachments, which may be booby-trapped with the ransomware. The UCL Information Services Division (ISD) said it had locked down access to the shared and networked drives that have been under siege from the malware since it began infecting users around mid-day Wednesday via an email message. "Currently it appears the initial attack was through a phishing email, although this needs to be confirmed," the ISD said. "It appears the phishing email was opened by some users around lunchtime today. The malware payload then encrypted files on local drives and network shared drives. The virus checkers did not show any suspicious activity and so this could be a zero day attack." Both the shared (S) and network (N) storage drive services have been suspended as the university works to stop the outbreak. Service is expected to be restored in read-only mode later this evening, UK-time. The ISD said drives that have already been encrypted by the malware will be restored to their most recent backup once the infection is resolved. In the meantime, the university is warning all students and staff not to open any attachments or click links in emails, and to be wary of suspicious messages from contacts. "It is vital we all maintain a high level of vigilance when opening unexpected emails. If the email is unexpected or in any way suspicious, then you must not open any attachment or follow any link in the email," the ISD said. "Doing so may lead to loss of your data and very substantial disruption to the university." UCL said it will provide an update on the situation tomorrow. ® < Here > Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.