Reply to post: Re: No word on how it got in?

Ransomware killed 70% of Washington DC CCTV ahead of inauguration

The IT Ghost

Re: No word on how it got in?

Since even basic perimeter security is aggressive about executables in emails, ransomware frequently comes in as a macro-laden DOC file while has to be executed, and the macros enabled on, or the machine has to go to a compromised website that installs the software as a background task to ease it past the filters. Neither of which would be expected to be something a CCTV camera was capable of. Perhaps every camera was set to dump its recorded footage to a central server, as AVI, MPG, whatever...and when a human who had access to those folders on the central server got hit, all the files were encrypted, including the ones the cameras were actively spooling into. The camera software, realizing it hadn't actually moved to a new file on its own and was unable to find the file it had been filling up, did its version of a blue-screen. A few cameras or controllers with an updated/different firmware may simply have handled the file-access break more easily.

And they are orange-neutral, so as not to inadvertently get footage of any coloration changes in the Chief Executive. That would put them in competition with CNN, NBC, CBS, and ABC, all of whom are rabidly recording, and reporting on, every time Trump blinks his eyes.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon