إعلان
Big 5

Cyberattacks break into the files of some government agencies The Telecommunications Authority warns against the Shamoon 2 ransomware virus

Telecommunications Commission

Posted in

The Communications and Information Technology Commission, represented by the National Information Security Advisory Center, revealed that some government agencies have been subjected to various cyberattacks, including the ”Shamon 2” virus and "ransomware," which target information and files and wipe them completely, It recommended that all agencies increase their vigilance and caution and ensure that the necessary precautions are in place.

The Authority warned of the consequences of losing electronic data and having files wiped due to these attacks, and called on all agencies to increase their vigilance and caution and verify that the necessary precautions are in place.

The Communications Commission’s warning came after a number of government agencies and ministries were subjected to attacks that disrupted their internal systems; it recommended several proposed solutions that may help prevent infection and minimize damage.

The Authority emphasized the need to ensure that up-to-date backups of important information and files are available, and to avoid storing backups on the same device or on network-shared drives (Shared Drives) that may be vulnerable to infection. It also noted the importance of raising employee awareness through intensified awareness campaigns to highlight this type of infection, and emphasizing that employees should not open suspicious links or email attachments from unknown senders or those not expected from the other party, and not to browse suspicious or non-work-related websites, nor to download files from websites that are unknown or untrusted by the user.

The Authority recommended regularly and effectively updating operating systems and applications to prevent the exploitation of recent vulnerabilities that could lead to systems and devices being infected with this type of malware, as well as using antivirus software and ensuring it is updated regularly, and to update antivirus software to detect any signs of malware infection; the organization can also use advanced malware detection systems.

The Communications Commission has provided important recommendations to control the spread of malware within the organization’s network by isolating devices suspected of being infected from the network, limiting the number of employees and specialists who have accounts with administrative privileges on the organization’s networks, systems, and applications, and verifying that employees actually need these privileges, logging all operations they perform using these accounts and auditing them periodically; reviewing login logs and failed login attempts on servers and devices with administrative privileges; and emphasizing to specialists that they must not use administrative accounts to read email, view attachments, or browse the internet, given the risk this poses to the organization’s network, as these accounts have high-level privileges on the organization’s systems, which could enable malware to spread; Instead, an account with limited privileges should be used for employees’ routine tasks.