Home / Business and Politics / Former Orqa Collaborator Conducted Hacking Attack on Company, Criminal Proceedings Underway

Former Orqa Collaborator Conducted Hacking Attack on Company, Criminal Proceedings Underway

The Osijek company Orqa, which specializes in the design and production of video glasses for drone pilots, was the target of a hacking attack this weekend. As reported by the company, the hacking attack, which they initially thought was a regular ‘bug‘, was actually a ransomware attack that began this Saturday and has been successfully resolved today.

– The team of engineers from Orqa successfully neutralized the ransomware that was inserted into a part of the code by a former collaborator – they reported from Orqa.

They also informed their users about the entire situation, advising them over the weekend not to use their glasses until they understand what the exact problem is.

– Dear Orqa pilots, it seems there is a bug in our firmware that affects the date/time feature and causes the glasses to enter system boot mode. We are making every effort to find a solution as soon as possible. We explicitly advise you not to turn on the glasses for the next few hours until we better understand the situation – they warned their users on Saturday.

Ransomware attacks work by the attacker entering the network (if a person clicks on a suspicious link or file in an email or if the attacker previously installed malware in the system) encrypting data and disabling work on the computer, which can happen at any time, sometimes even years after the attack. In exchange for the ‘locked’ data, the attacker demands a ransom from the victim.

In the case of Orqa, the attacker decided to activate the ransomware precisely during this weekend, which was extended due to Labor Day on Monday, and the firmware was compromised – simply put, the instructions that devices, in this case, glasses for drone pilots, use to perform their basic tasks, are stored within them.

The company decided to share the entire story about the hacking attack with users, and we are relaying it in full:

 

“Hey folks, here’s another update on the situation. Hold on and grab your popcorn, because you won’t believe how crazy this is.

Within five or six hours of this crisis, early Saturday afternoon, we discovered that this mysterious problem was the result of a time bomb ransomware that a greedy former contractor secretly planted in our bootloader a few years ago, intending to extract a large ransom from the Company.

The perpetrator was particularly cunning, as he maintained occasional business relations with us over the past few years, waiting to ‘detonate’ the encrypted bomb, presumably to avoid suspicion and hoping to extract more ransom, given that our business and our market share were growing.

The ransomware was programmed to ‘explode’ in a way that would cause maximum crisis: it was timed to activate on a spring Saturday, during the extended weekend, when most of you should be flying, and most of our engineering team should be enjoying their well-deserved days off. Supposedly, this would put the company in a state of panic, giving the perpetrator enough leverage to extort his ransom.

If you’re thinking something along the lines of ‘man, this has to be one of the dumbest cyber crimes ever committed in the history of cybercrime’, you’re probably right.

The reason for this, we believe, is that the perpetrator acted with a very simplistic worldview where, if you plan a ransomware attack, but instead of calling your ransom ‘ransom’, you (very cleverly) call it ‘license’, your timed ransomware bomb suddenly ceases to be a crime.

Unfortunately (for the perpetrator), a crime is a crime no matter how you choose to label it, and it seems he has begun to realize that.

We assume the perpetrator had his ‘oh, crap’ moment, as we were informed that he began to panic publish, likely in a poor attempt to control the damage. He posted a link with an unauthorized binary file that supposedly resolves the issues caused by his malware.

NOTE: We strongly discourage installing firmware that has not been released by Orqa. Furthermore, if you are considering installing a ‘fix’ consisting of a binary file published by someone known to have previously secretly planted a malware time bomb in the firmware – think again (just kidding, don’t think: just DO NOT install it).

Keep in mind that when we received the ransom request, we had to keep everything confidential, as parallel to the engineering team’s efforts to enable you to fly again, our legal team was working on preparing evidence to be submitted to the relevant authorities for criminal proceedings.

We did not want to go public with the criminal aspect of this event to avoid jeopardizing the ongoing judicial and criminal proceedings.

However, since the perpetrator went public with what he did and published what we fear is yet another compromised firmware, we decided it is in the interest of our users to be informed about the situation and warned about the risks of installing potentially compromised firmware on their devices.

We are working to provide you with a reliable and authorized solution as soon as possible.

Additionally, our security review revealed that this malware only affected a small portion of the code, and repairs are underway.”

 

As the company added, although Orqa is primarily a hardware-oriented company, it employs top engineers in the fields of software and security.

Ransomware was eliminated in an extremely short time and control was established over the part of the system that was compromised. It is also important to emphasize that the Orqa system is impossible to compromise by external actions, and they have raised internal security to the maximum level in the last two years – they explained from Orqa.

Tagged: