web counter
LEXO PA REKLAMA!

SHKARKO APP

E fundit!

x

Cyber ​​attacks on INSTAT, ACESK: The virus infected 40 computers, deleted 6

2024-02-14 08:03:00, Aktualitet CNA

At least 40 computers have been infected with the virus that aimed to delete the data of the Institute of Statistics, and the goal has been achieved in at least six of them.

The National Authority for Electronic Certification and Cyber ??Security (ACESK) recently updated the balance that has resulted from the attack almost two weeks from this development giving details on the consequences and the measures taken.

"From the analysis conducted so far, it has been confirmed that the attackers used the MEK-DDMC.exe file to execute a virus with malicious content. This attack, known as Wiper, was aimed at erasing Boot sector data and touching devices within Active Directory (AD).

For logging in, it is assumed that the Exchange server was used due to an outdated version. Malicious actors were able to override privileges and take control of the Active Directory system and Data Protection Manager, spreading the virus to devices and servers on the network.

The distributed virus has infected 40 computers, from where it has deleted 6 of them. Then the virus deleted the server on which the commands were executed. After that, the actors have lost communication with the infrastructure," says the ACESK update.

This authority estimates that from the information available, the actors behind this cyber attack have been identified as "Homeland Justice", an attack group sponsored by the Iranian state that has already carried out other attacks in the past.

On February 1, 2024, the Institute of Statistics faced a cyber attack targeting its technological infrastructure. After ascertaining this, the responsible institutions continued with the process of clarifying and neutralizing the attacks for several days. In a statement to the media, INSTAT underlined that the Census data were not affected by this attack.

This is not the first time that Albanian institutions fall prey to cyber attacks. In the summer of 2022, the same group attacked the centralized platform for providing electronic services to citizens, businesses and public administration, paralyzing work for several days in a row.

At that time, foreign assistance was requested to identify and minimize the effects, as from that moment attacks on various public institutions have become common./ Monitor Magazine





Lajmet e fundit nga