In a statement published today, the Ukrainian Cabinet said that "all strategic assets, including those involved in protecting state security, are working normally."
The same couldn't be said for India's largest container port, where one of the terminals was idled by the malicious software, which goes by a variety of names including ExPetr. M.K. Sirkar, a manager at the Jawaharlal Nehru Port Trust in Mumbai, said that no containers could be loaded or unloaded at the terminal operated by shipper A.P. Moller-Maersk today.
At the very least, thousands of computers worldwide have been struck by the malware, according to preliminary accounts published by cybersecurity firms, although most of the damage remains hidden away in corporate offices. Some names have trickled into the public domain as the disruption becomes obvious.
In Pennsylvania, lab and diagnostic services were closed at the satellite offices of Pennsylvania's Heritage Valley Health System, for example. In Tasmania, an Australian official said a Cadbury chocolate factory had stopped production after computers there crashed.
More From This Section
As IT security workers turned their eye toward cleaning up the mess, others wondered at the attackers' motives. Ransomware which scrambles a computer's data until a payment is made has grown explosively over the past couple of years, powered in part by the growing popularity of digital currencies such as Bitcoin.
But some believed that this latest ransomware outbreak was less aimed at gathering money than at sending a message to Ukraine and its allies.
That hunch was buttressed by the way the malware appears to have been seeded using a rogue update to a piece of Ukrainian accounting software and the timing coming the same day as the assassination of a senior Ukrainian military intelligence officer in the nation's capital and a day before a national holiday celebrating a new constitution signed after the breakup of the Soviet Union.
In a post published today, The Shadow Brokers made new threats, announced a new money-making scheme and made references to what happened yesterday.
"Another global cyber attack is fitting end for first month of theshadowbrokers dump service," the group said, referring to a subscription service which purportedly offers hackers early access to even more of the NSA's digital break- in tools.