New ransomware tactics ‘unstoppable’—as 1 county discovers

Hackers can strip away any sign that an email is fake and bypass normal safeguards.

  • By Tim Johnson McClatchy Washington Bureau (TNS)
  • Wednesday, December 6, 2017 4:15pm
  • Business

By Tim Johnson / McClatchy Washington Bureau

WASHINGTON — Hackers are growing much more adept at getting people to open email infected with worms, as the network operators of Mecklenburg County government in North Carolina are the latest to discover.

Practically any infected email can look like it’s from a trusted friend or co-worker.

New techniques that a researcher unveiled this week show how hackers can strip away any sign that an email is fake, and make it “virtually unstoppable” by normal safeguards such as spam filters on email servers.

Campaigns by criminal hackers are “becoming more and more sophisticated,” said Ken Spinner, vice president of global field engineering at Varonis, a New York City security firm.

“It’s really hard to determine, if you receive an email message, whether it is legitimate or not,” Spinner said. “What’s happening is that the hackers are well funded, and in a lot of cases, budgets (of governments) don’t keep up with the requirements of security and they don’t keep up with the sophistication of exploits.”

A German security researcher, Sabri Haddouche, discovered the latest tactics used by cybercriminals, announcing them on a website Tuesday that shows a collection of vicious bugs used to bypass the hurdles set up on more than 30 widely used email clients, like Apple Mail, Mozilla Thunderbird, Yahoo! Mail and Microsoft Outlook 2016.

Haddouche dubbed the malware technique Mailsploit, and said he’d notified major software vendors at least three months ago to protect against it. About 20 vendors dealt with the problem, but 15 either did not say if they would fix the bug or said they would not, he said.

“Mailsploit is a new way to easily spoof email addresses. It allows the attacker to display an arbitrary sender email address to the email recipient,” wrote Haddouche, who works for a European cybersecurity firm, Wire, with offices in Berlin; Zug, Switzerland; and San Francisco.

In his demonstration, Haddouche showed how he could make an email look like it was from President Donald Trump and originated from the email account potuswhitehouse.gov

By sending what are known as spoofing or spearphishing emails, hackers can either include a malicious link in the mail or attach an infected document, both of which can give intruders access into a network.

Governments are now falling victim to ransomware attacks just as thousands of corporations, small businesses, nonprofits and other entities, like hospitals, have worldwide.

An employee of the Mecklenburg County government Monday received an email routed from another employee’s account and opened it and a malicious attachment, infecting the county’s network. Hackers set a deadline of 1 p.m. Wednesday for officials to pay a ransom of about $23,000 but the deadline passed and it was not known whether a ransom was paid. The computers remained down.

“What makes this more dangerous is that hackers are now evolving different ways of getting inside the government network and employees can be the weakest link,” said Bob Noel, director of strategic relationships and marketing for Plixer, a Kennebunk, Maine, firm.

“In these sophisticated attempts, it is hard, if not impossible, for government employees to recognize a phishing email as the spoofing is so professional,” Noel added.

Ransomware attacks have become a global phenomenon. In at least two major waves of attacks this year, tens of thousands of infected computers in at least 150 countries displayed a message saying the hard drives had been frozen and would only be decrypted if a bitcoin ransom was paid.

Major corporations suffering large losses in the May and June attacks included the U.S. pharmaceutical giant Merck, the FedEx logistics and package delivery firm, and Danish shipping line Maersk.

Global ransomware damage is likely to rise from $5 billion this year to $11.5 billion in 2019, the Menlo Park, California, firm Cybersecurity Ventures said in a report last month.

Spoofing emails take many forms, including what appear to be requests from within a corporation to transfer money to an outside account to pay bills.

While some hackers use stolen personal identifying information to try to hack anyone, then penetrate into their workplace networks, few have targeted governments.

“A ransomware attacks relies on the victim being able to make a quick payment. Most government agencies would not have the capability of making a quick payment even if they wanted to,” said John Gunn, chief marketing officer at VASCO, an Oakbrook Terrace, Illinois, cybersecurity firm.

Moreover, Gunn said, “ransomware works best against victims that want to avoid a disruption of their business and the economic losses associated with losing customers. Government agencies generally don’t lose customers regardless of the level of service provided.”

One security researcher said ordinary citizens should not feel bad if they get taken in.

“Even the best of us can be fooled by a specially crafted phishing campaign,” said Travis Smith, principal security researcher at Tripwire, a software company with headquarters in Portland, Oregon. “The next step is to ensure updates are installed in a timely manner, as malware often takes advantages of known vulnerabilities.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

A person walks past the freshly painted exterior of the Everett Historic Theatre on Sept. 24, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Historic Everett Theatre reopens with a new look and a new owner

After a three-month closure, the venue’s new owner aims to keep the building as a cultural hub for Everett.

Everett businesses join forces to promote downtown nightlife

A group of downtown businesses will host monthly events as a way to bring more people to the city’s core during late nights.

Former barista claims Starbucks violated Everett law

The part-time worker wanted more hours, but other workers were hired instead, the lawsuit alleges.

Cierra Felder (left to right), Aaron Sheckler and Scott Hulme  inside Petrikor on Thursday, July 31, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Everett store sells unique home furnishings

Petrikor aims to sell unique merchandise.

The Sana Biotechnology building on Tuesday, Aug. 19, 2025 in Bothell, Washington. (Olivia Vanni / The Herald)
Bothell loses planned biotechnology manufacturing plant

New biotechnology manufacturing jobs in Bothell are on indefinite hold.

Water drips from an Alaska Airlines Boeing 737 after it received a water salute while becoming the first scheduled 737 arrival Thursday, Feb. 17, 2022, at Paine Field Airport in Everett, Washington. (Ryan Berry / The Herald)
Alaska Airlines travelers will need to choose an option to earn frequent flier points

Earning Alaska Airlines points will now involve strategy.

Customers walk in and out of Fred Meyer along Evergreen Way on Monday, Oct. 31, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Everett council rebukes Kroger for plans to close Fred Meyer store

In the resolution approved by 6-1 vote, the Everett City Council referred to store closure as “corporate neglect.”

Isaac Peterson, owner of the Reptile Zoo, outside of his business on Tuesday, Aug. 19, 2025 in Monroe, Washington. (Olivia Vanni / The Herald)
The Reptile Zoo, Monroe’s roadside zoo, slated to close

The Reptile Zoo has been a unique Snohomish County tourist attraction for nearly 30 years.

Inside El Sid, where the cocktail bar will also serve as a coffee house during the day on Tuesday, Aug. 12, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
New upscale bar El Sid opens in APEX complex

Upscale bar is latest venue to open in APEX Everett.

Delays, empty storefronts frustrate residents at Everett riverfront

At the newly built neighborhood, residents have waited years for a park and commercial businesses to open.

Funko headquarters in downtown Everett. (Sue Misao / Herald file)
FUNKO taps Netflix executive to lead company

FUNKO’s new CEO comes from Netflix

Customers walk in and out of Fred Meyer along Evergreen Way on Monday, Oct. 31, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Kroger said theft a reason for Everett Fred Meyer closure. Numbers say differently.

Statistics from Everett Police Department show shoplifting cut in half from 2023 to 2024.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.