Railways issues cyber-security alert to its staff after malware attack

The Indian Railways has issued a cyber-security advisory to all zonal railways and other key railway organisations following a script-based cyber incident reported in Central Railway on August 11 this year. The authorities warn that messaging applications, particularly WhatsApp Web, can be exploited to deliver malicious files and potentially compromise computers connected to railway networks.

As per root-cause analysis cited by the authorities, the incident happened when a user received a malicious “E-statement.vbs” file in a WhatsApp group. The file was downloaded onto the user’s computer through the WhatsApp Web application and was subsequently opened by double-clicking it.

“The incident has prompted the Railway Board to direct its units to strengthen endpoint protection and user awareness against malware campaigns exploiting messaging platforms. It is also consistent with a CERT-In warning about a wider campaign in which malicious VBScript files are distributed through WhatsApp, including through compromised accounts to make the messages appear trustworthy,” said the railway official.

Railway units have been asked to ensure that all endpoints connected to railway networks are covered by cyber-security solutions, including ITSM and Endpoint Detection and Response (EDR). The employees have been advised to avoid opening files with extensions such as .vbs, .vbe, .exe, .bat, .cmd, .js and .ps1, unless their authenticity and necessity have been independently verified.

Employees have been told to exercise caution while opening unexpected attachments, even when they appear to come from known contacts. They should verify the identity of the sender before opening suspicious files or clicking links, and keep operating systems, browsers and messaging applications updated.

They have been asked to enable two-factor authentication (2FA) or two-step verification on WhatsApp and other messaging applications. They have been advised to periodically review devices linked to messaging accounts and log out unfamiliar devices. They have been told to avoid downloading software distributed through messaging platforms. The Railways has asked its employees that they should never share passwords, OTPs, banking credentials or sensitive information through messaging applications.

According to Indian Computer Emergency Response Team (ICERT) of Ministry of Electronics and Information Technology Government of India, a large-scale malware distribution campaign is targeting users of WhatsApp Desktop and WhatsApp Web, with attackers using compromised WhatsApp accounts to spread malicious Visual Basic Script (VBScript) files, according to a cybersecurity alert.

Cybersecurity researchers have observed that some of the VBScript samples contain extensive comments designed to imitate legitimate Microsoft Windows or update-related components. This can make the malicious files appear more credible and potentially reduce suspicion among users.

Previous articleEU adds €130 million to drone funding in border security push
Next articleTSA officers now not allowed to sit down while checking boarding passes and IDs