Year2017 |
MonthJune |
Reference number20170601 |
Impact areaShore |
Incident locationBuenos Aires |
Incident countryArgentina |
Victim countryArgentina |
Victim identityCofco |
Victim TypeSupply Chain Company |
MethodMalware |
Attacker countryRussia |
Cofco got hit by NotPetya Wiper virus in Argentina in June 2017. The cyber attack can be traced to software updates from the Ukrainian accounting program M.E.Doc. Investigators from the security firm Talos travel to Ukraine to assist M.E.Doc in the to analyse their systems and to find out how the company has penetrated. N477It gradually appears that hackers become ingeniously managed to gain access for months to the systems of Intellect Service, the parent company of M.E.Doc. This is a software developer of, among other things, the accounting system M.E.Doc, which is frequently used to exchange with the Ukrainian tax authorities. By hiding the malware in the software update process, NotPetya went undetected into the networks of companies that used this software. Updates have been released with a backdoor, a hacker-made change to the M.E.Doc software, which allowed them to distribute NotPetya to customers of this software vendor. it hit Argentina on Wednesday. The attack led to operational interruption. Slowing wheat and fertilizer shipments and threatening to impact the flow of soybeans to the country’s main client, China, at the height of export season. Cofco is collateral damage of the attack first targeting Ukrainian Computer Systems, carried out by Russia (Sandworm Team, also known as Unit74455).