Pratica di Shadowing: NotPetya Attack - Impara a parlare inglese con i video

Creazione lezione...
1
This is one of the big cyber attacks.
2
NotPetya was the most damaging cyber attack in the history of the internet at the time.
3
And although it was a piece of malicious ransomware on the surface, the attack wasn't really about money.
4
It was about something much, much greater and much more sinister.
5
WannaCry, Petya, and NotPetya.
6
These were all infamous pieces of ransomware.
7
But NotPetya was in a league of its own.
8
As NotPetya spread and infected systems and security experts began to analyze it, a different reason for its creation emerged.
9
NotPetya was designed for cyber warfare.
10
When an entire country's infrastructure, such as the power grid, bus stations, banks, airports, and gas stations were affected by the most devastating a cyber attack to have ever occurred,
11
it became scarily apparent how much damage can be done with a cyber weapon.
12
No lives were lost due to NotPetya, but the impact was incomparable to any previous attack.
13
Hey, I'm Rob Witcher.
14
In this video series, we explore some of the biggest cybersecurity breaches in modern history.
15
If you find cybersecurity as fascinating as I do, then please subscribe and hit the bell icon to get notifications when we release new videos.
16
On June 27th, 2017, it was the summer eve of Ukrainian holiday Constitution Day.
17
Suddenly, computers around the country began to show one of two different screens,
18
a repairing file system on C with a stark warning to not turn the computer off, or a classic ransomware screen which read,
19
oops, your important files are encrypted, and demanded a payment of $300 worth of bitcoin to decrypt the files.
20
The attack began to spread across Ukraine, and then the globe.
21
It was reported by Kaspersky that within a single day, NotPetya had infected systems in France, Germany, Italy, Poland, the United Kingdom, and the United States.
22
The majority of infections, however, targeted Ukraine.
23
In fact, 80 % of infections in the first 24 hours were located in Ukraine.
24
As people's screens began to go black, no one truly realized that this was the beginning of the biggest cyber attack in history.
25
To understand not Petya, you first need to be familiar with Petya.
26
Petya was first discovered in March 2016, a piece of ransomware
27
that was said by Checkpoint at the time to have been immediately flagged as the next step in ransomware evolution.
28
It was named Petya after one of the Soviet weapons satellites from the James Bond movie, GoldenEye.
29
And in the hacking world, just like in the James Bond films, it's always the Russians, right?
30
2017 was a big year for ransomware attacks.
31
Just a month earlier, the infamous WannaCry attack had affected hundreds of thousands of computers across 150 countries, causing millions of dollars in damages.
32
And then in June, something even more damaging hit.
33
Kaspersky dubbed this new ransomware NotPetya.
34
This variant had major differences to the original Petya ransomware.
35
One of the main differences was that NotPetya had been created to spread quickly.
36
To date, it was simply one of the fastest propagating pieces of malware we've ever seen, said Craig Williams from Cisco's Talos division,
37
one of the very first security companies to investigate NotPetya and reverse engineer it.
38
He further told Wired, by the second you saw it, your data center was already gone.
39
NotPetya was spreading like wildfire, and it was targeting Ukraine's infrastructure.
40
And it then began to spread globally through companies who operate branches within Ukraine.
41
Anyone who thinks this was accidental is engaged in wishful thinking, Williams continued.
42
This was a piece of malware designed to send a political message.
43
If you do business in Ukraine, bad things are going to happen to you.
44
NotPetya affected countless small and large -scale companies, including Maersk, the world's largest container shipping company, Merck, a U .S pharmaceutical company,
45
Saint -Gobain, a French construction materials company, and even an Australian chocolate factory.
46
Various marketing firms, law firms, oil companies, and railway companies around the world were reeling from the chaos of NotPetya.
47
To understand this hack, it's worth knowing a little bit about the political context that led to it.
48
Russia and Ukraine have been engaged in an ongoing war since early 2014.
49
The conflict, like all conflicts, has a complex background, and some of the key moments surrounded Russia's annexation of the Ukrainian territory of Crimea
50
and conflicts surrounding the status of the Ukrainian region of Donbas.
51
According to human rights groups, around 13 ,000 Ukrainians have died since the conflict broke out in early 2014.
52
In 2017, NotPetya was quickly attributed to Russian hackers.
53
And this wasn't the first time Russians had used cyber warfare tactics against Ukraine.
54
Since 2014, they've attacked the Ukrainian power grid in the depths of the cold winter , attacked railways and other critical infrastructure,
55
and rigged election websites in their relentless hybrid warfare tactics.
56
Joshua Korman, a cybersecurity fellow at the Atlantic Council, said, The physics of cyberspace are wholly different from every other war domain.
57
And cyberspace has been one of the main fronts on this war from the start.
58
Russia have been essentially using Ukraine as a test lab for their latest innovations in cyber warfare.
59
Former Homeland Security Advisor Tom Bossert said that according to White House assessments, the NotPetya attack resulted in more than 10 billion,
60
with a B, billion in damages.
61
To put that into perspective, the previous WannaCry attack of the previous month resulted in an estimated 4 to 8 million in damages.
62
That's less than a tenth of a percent of the cost of NotPetya.
63
On October 20th, 2020, the United States Justice Department charged six Russian government hackers with the NotPetya attack
64
and the attacks on the power grid in the Ukraine.
65
No country has weaponized its cyber capabilities as maliciously or irresponsibly as Russia,
66
wantonly causing unprecedented damage to pursue small tactical advantages and to satisfy fits of spite, said John Demers, U .S.
67
Assistant Attorney General for National Security.
68
Today, the department has charged these Russian officers with conducting the most disruptive
69
and destructive series of computer attacks ever attributed to a single group, including unleashing the NotPetya malware.
70
No nation will recapture greatness while behaving in this way.
71
Strong words from the U .S.
72
NotPetya was so far -reaching and spread so quickly because it took advantage of two exploits, Eternal Blue and Mimikatz.
73
Used in tandem, these exploits allowed NotPetya to rip through machines around the world at a downright alarming rate.
74
Eternal Blue is the exploit created by the U .S.
75
National Security Agency, the NSA.
76
Eternal Blue takes advantage of a vulnerability in Windows SMB,
77
Server Message Block Protocol, a network protocol that enables users to communicate with remote computers and servers across a network.
78
Eternal Blue was leaked to the world in early 2017.
79
And although Microsoft had released a patch for the vulnerability as soon as it was disclosed, many computers around the world had not yet been patched.
80
MemeCats was an older invention created by a French security researcher in 2011.
81
It was released to show that Windows passwords could be found deep within RAM random access memory of a computer.
82
If hackers could gain even just guest accounts or limited access to a computer once inside,
83
they could use Mimikatz to find other users' passwords and hack into other computers using those same credentials.
84
The use of EternalBlue and Mimikatz together made for a scarily powerful piece of ransomware.
85
You can infect computers that aren't patched, and you can grab the passwords from those computers to infect computers that are patched,
86
said Benjamin Delpy, the researcher behind Mimikatz.
87
This meant that even patched computers weren't necessarily safe from the NotPetya rampage.
88
It was especially efficient within networks with multi -user computers, as it would automatically jump from one computer to the next within the network at lightning speeds.
89
It's often unclear whether paying the ransom associated with a ransomware
90
attack will actually allow users to gain access to their computers and files again.
91
But in this case, it was clear -cut.
92
No key existed to unencrypt the content.
93
NotPetya was purely built for one thing, maximum destruction.
94
It's also sometimes unclear whether a cyber attack can be labeled as cyber warfare.
95
But in the case of Notpetya, it was an open and shut case.
96
This was clearly an attack of cyber war against Ukraine, perpetrated by Russia.
97
The Linkos Group is a small, family -run Ukrainian software business.
98
They create and maintain a piece of software known as MEDOC, a piece of accounting software similar to TurboTax,
99
which almost everyone in the Ukraine uses to do their taxes online.
100
But on June 27th, 2017, the Linkos Group headquarters suddenly became ground zero for the release of the NotPetya ransomware.
101
Back in the spring of 2017, the hackers had targeted this small family -run business and hijacked their update servers.
102
They used these as a backdoor into thousands of Ukrainian households through the ME -DOC software, the accounting software that everyone uses and has downloaded on their computers.
103
By the summer of the same year, the Russians were poised and ready to pounce, using this backdoor to unleash the malicious software on the Ukraine and the world.
104
Being the most damaging cyber attack ever, you'd hope there'd be some takeaways from it.
105
So what have we learned from NotPetya?
106
Ransomware isn't going away.
107
Attacks are likely to get more and more sophisticated.
108
The best approach for any business is to assume that being hit by ransomware is inevitable.
109
It's going to happen.
110
This means having plans in place and knowing how to execute them
111
and knowing how long it would take to get things back up and running for your business.
112
It also means training in disaster recovery for these scenarios so
113
that everyone involved knows their roles and responsibilities in the case of a cyber incident like a ransomware attack.
114
You need to have a plan and you need to know
115
that that plan is going to work properly in the event of an actual cyber catastrophe such as NotPetya.
116
The importance of businesses taking back up seriously was highlighted especially clearly in the case of global shipping company Maersk, who reportedly didn't have proper backups in place.
117
The only reason they were able to access their data was
118
due to a power outage in one of their remote offices in Ghana.
119
A total fluke in West Africa had left one domain controller safe from the destructive forces of NotPetya,
120
and Maersk were luckily able to recover from this one data center that had been accidentally offline.
121
We need to be regularly backing up our data, and to help avoid ransomware, it is a good practice to use different encryption keys for our backups.
122
But the biggest thing we've learned from NotPetya is
123
that cyber warfare against a country's critical infrastructure isn't an abstract concept from science fiction anymore, something that might happen in the future.
124
Cyber weapons have already been used by governments against other nations.
125
It's a real issue that is occurring today, and it seems extremely likely that cyber warfare will only become more prevalent.
126
Notpetya's impact on Ukraine's infrastructure highlighted the far -reaching consequences of cyber attacks of this nature, affecting the power grid, transportation infrastructure, and banks.
127
Previous attacks have shown that healthcare infrastructure can also be vulnerable.
128
This is the beginning of a new age of warfare, attacking an enemy nation not just physically, but digitally as well.
129
This was one of the most fascinating and terrifying cyber attacks, and one of the costliest and most damaging to have ever occurred.
130
Although the U .S have officially charged Russian government hackers with the NotPetya attack, it doesn't seem likely that these attacks will disappear in any way.
131
In fact, it's highly plausible that an attack like this could happen against the United States or other countries.
132
It's clear
133
that countries need to be putting resources into trying to protect critical infrastructure from attacks such as this
134
and planning for disaster recovery when such an attack does occur.
135
If you found this video interesting and informative then please hit the thumbs up button
136
and let us know in the comments below what breaches you want us to cover in future videos.
137
See you in the next one.

Informazioni su questa lezione

Cos'è la tecnica dello Shadowing?

Shadowing è una tecnica di apprendimento delle lingue supportata da studi scientifici, originariamente sviluppata per la formazione dei traduttori professionisti e resa popolare dal poliglotta Dr. Alexander Arguelles. Il metodo è semplice ma potente: ascolti un audio in inglese di madrelingua e lo ripeti immediatamente ad alta voce — come un'ombra che segue il parlante con un ritardo di solo 1–2 secondi. A differenza dell'ascolto passivo o degli esercizi di grammatica, lo shadowing costringe il tuo cervello e i muscoli della bocca a elaborare e riprodurre simultaneamente i modelli di discorso reale. La ricerca dimostra che migliora significativamente la precisione della pronuncia, l'intonazione, il ritmo, il discorso connesso, la comprensione dell'ascolto e la fluidità del parlato — rendendolo uno dei metodi più efficaci per la preparazione alla prova di speaking dell'IELTS e per la comunicazione reale in inglese.

Tecnica dello shadowing: leggi la guida completa passo dopo passo →