Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure
  • Cyber Attacks
  • Data Breach
  • Malware

Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure

4 years ago Graham Cluley
Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure

Security researchers are warning biomanufacturing facilities around the world that they are being targeted by a sophisticated new strain of malware, known as Tardigrade.

The warning comes from the non-profit Bioeconomy Information Sharing and Analysis Center (BIO-ISAC) which revealed that at least two large facilities working on manufacturing bio-drugs and vaccines have been hit by the same malware this year, in what appear to be targeted attacks.

Charles Fracchia, founder of BioBright and a BIO-ISAC board member, says that Tardigrade is an APT targeting Windows computers in the bioeconomy and biomanufacturing sector “using tools of unprecedented sophistication and stealth.”

At first Tardigrade might be mistaken for a (sadly all-too-common) ransomware attack, but what makes it different is its sophistication and autonomy. And – unlike ransomware – if Tardigrade makes any attempts to extort money from its victims they appear to be half-hearted, with much more interest being paid on exfiltrating data and spying on its victims.

Security researchers claim that Tardigrade appears to be a variant of the SmokeLoader malware family, but is far more autonomous – able to decide for itself to select files for modification, and move laterally throughout an organisation and take other actions such as infect USB drives, rather than rely upon a command-and-control centre.

Fraccia told Wired that Tardigrade took things to a new level:

“This almost certainly started with espionage, but it has hit on everything — disruption, destruction, espionage, all of the above. It’s by far the most sophisticated malware we’ve seen in this space. This is eerily similar to other attacks and campaigns by nation state APTs targeting other industries.”

Attacks against pharmaceutical companies and the bioeconomy have happened around the world during the pandemic, as malicious attackers have found the sector to be poorly defended compared to its heightened value to society.

For now, as nations scramble to protect their citizens from COVID-19, no-one is publicly pointing fingers as to who might be responsible for Tardigrade’s attacks. Instead the focus is on spreading word of the threat, in fear that other biomanufacturing facilities may be hit.

Analysis of exactly what Tardigrade is capable of doing is ongoing, but researchers working with BIO-ISAC say that they felt it was right to make a public disclosure having seen the continuing spread of the attack.

Initial infections appear to be most likely to occur through a poisoned email, tricking recipients into opening a file. But the Tardigrade malware can also be spread laterally across networks, and even infect USB sticks.

Malware researcher Callie Churchwell says that one method Tardigrade uses for lateral spread was network shares and that it “creates folders with random names from a list (eg: ProfMargaretPredovic)”

BIO-ISAC recommends that at-risk biomanufacturing organisations review their network segmentation, determine what the “crown jewels” are to protect inside their company, test and perform offline backups of key infrastructure, inquire about lead times for key bio-infrastructure components should they need to be replaced or upgraded, and “assume you’re a target.”


Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” Sophisticated Tardigrade malware launches attacks on vaccine manufacturing infrastructure” appeared first on TripWire

Source:TripWire – Graham Cluley

Tags: APT, COVID-19, Encryption, Finance, Malware, Ransomware, TripWire

Continue Reading

Previous New Twists on Gift-Card Scams Flourish on Black Friday
Next Product Releases Should Not Be Scary

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

20 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

21 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

23 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

How Samsung Knox Helps Stop Your Network Security Breach

1 day ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

1 day ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries

1 day ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
  • CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
  • Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
  • How Samsung Knox Helps Stop Your Network Security Breach
  • Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT