Crisis Update 7

Update on airport attack: Most airports have switched to analog communications. Some do not have these legacy systems anymore, and in those airports (Rome, JFK, Vilnius) planes are being diverted to local airports. In the process of some of these diversions, some local airports have also been infected by the malware.

Details on the malware: Using the USB power plug on the seatback entertainment system, an attacker plugged in a malicious USB flash drive. The data pins on the seatback USB plugs are not blocked on Ryanair, exposing this attack vector. The name of the passenger whose seatback entertainment system started this attack is Jacques Clouseau, a French citizen that, upon questioning, was visiting Estonia for the first time with his family this spring. Additionally, the attackers utilized American NSA hacking tools released in the 2016 Shadow Brokers leak to exploit the outdated Android operating system present on the Ryanair screens.

Comments

Popular posts from this blog

Postimees Report: Estonian Internal Security Services Identify Protest Leader

NATO begins investigating Estonian cyber attack - The New York Times

Crisis Update 6