What We Know About The WannaCry Cyberattack So Far

As danger from a global cyberattack that hit some 150 nations continues to fade, analysts are starting to assess the damage.

Hard-hit organisations such as the UK's National Health Service appear to be bouncing back, and few people seem to have actually paid the ransom. But the attack has served as a live demonstration of a new type of global threat, one that could encourage future hackers.

Here's what we currently know about the ransomware known as WannaCry, which locked up digital photos, documents and other files to hold them for ransom.

Where it came From

Researchers are still puzzling out how WannaCry got started. Figuring that out could yield important clues to the identity of its authors. The malware spread rapidly inside computer networks by taking advantage of vulnerabilities in mostly older versions of Microsoft Windows. That weakness was purportedly identified and stockpiled for use by the US National Security Agency; it was subsequently stolen and published on the internet.
But it remains unclear how WannaCry got onto computers in the first place. Experts said its rapid global spread suggests it did not rely on phishing, in which fake emails tempt the unwary to click on infected documents or links. Analysts at the European Union cybersecurity agency said the hackers likely scanned the internet for systems that were vulnerable to infection and exploited those computers remotely.
Once established, WannaCry encrypted computer files and displayed a message demanding $300 to $600 worth of the digital currency bitcoin into release them. Failure to pay would leave the data scrambled and likely beyond repair unless users had unaffected backup copies.

Ransomware

Investigators are closely watching three bitcoin accounts associated with WannaCry, where its victims were directed to send ransom payments. The digital currency is anonymized, but it's possible to track funds as they move from place to place until they end up with an identifiable person. So far, there have been no withdrawals from those accounts. Given the scope of the attack, relatively few people appear to have actually paid the ransom. According to a Twitter account that monitors those accounts, they've received only about 250 payments worth a total of slightly more than $72,000.

North Korea

Several sets of investigators have now reported tentative findings that suggest hackers linked to North Korea might have been involved with WannaCry. But they could all be drawing conclusions from a very small set of clues.

The security firm Kaspersky Lab said portions of the WannaCry program use the same code as malware previously distributed by the Lazarus Group, a hacker collective behind the 2014 Sony hack. Another security company, Symantec, related the same findings, which it characterized as intriguing but "weak" associations, since the code could have been copied from the Lazarus malware. Two law enforcement officials likewise said U.S. investigators suspect North Korea based on code similarities; the officials called that finding preliminary. The officials spoke to The Associated Press on condition of anonymity because they aren't authorized to speak publicly about an ongoing investigation.

But WannaCry remains a puzzle, in part because some of its elements seemed amateurish. Salim Neino, CEO of the Los Angeles-based security firm Kryptos Logic, said the WannaCry worm was "poorly designed" — patched together and consisting of a "sum of different parts" with an unsophisticated payment system.
Typical ransomware also generates a unique bitcoin account for each payment to make tracing difficult. That wasn't done here.

Digging-Out

One of the organizations hardest hit by WannaCry, the UK's National Health Service, appears to be recovering. On Friday, many NHS hospitals had to turn away patients after WannaCry locked up computers, forcing the closure of wards and emergency rooms. NHS Digital, the body that oversees cybersecurity in Britain's health system, said that as of now, it has "no evidence that patient data has been compromised." The agency told hospitals to disconnect all infected computers, apply a Microsoft patch that closes the vulnerability, then "roll back" the infected computers and restore them from backed-up files. UK hospitals are supposed to back up data frequently and at multiple locations. It's possible that some data that wasn't backed up could be lost.

Hacks to Come
WannaCry could also serve as a kind of template for future cyberattacks. Salim Neino, CEO of Kryptos Logic said the leak of the NSA hacking tools have significantly narrowed the gap between nations and individuals or cyber gangs.
"The concern has always been, when are the real bad guys, the ones that don't care about rules of engagement, the ones who are really out to hurt us, will they become cyber-capable?" he said in an interview with The Associated Press. "I think today we found out that those who really want to hurt us have begun to, because they became cyber-capable the moment that the NSA cyber-tools were released."

ABC News

You Might Also Read:

WannaCry Attack Is A Big Wake-Up Call:

Microsoft, Kaspersky & Symnantec  Weigh In On WannaCry Ransomware:

Massive Ransom Attack Hits 99 Countries:

 

« Trump Signs Cybersecurity Order
Directors Report June 2017: Cloud Security Analysed For Management (£) »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

LogRhythm

LogRhythm

LogRhythm's security platform unifies SIEM, log management, network and endpoint monitoring, user behaviour analytics, security automation and advanced security analytics.

Continuum

Continuum

Continuum is the IT management platform company that allows Managed IT Services Providers to maintain and back up on-premise and cloud-based servers, desktops, mobile devices and other endpoints

VTT Technical Research Centre of Finland

VTT Technical Research Centre of Finland

VTT is the leading research and technology company in the Nordic countries. Areas of activity include cyber security.

AppSec Labs

AppSec Labs

AppSec Labs specialise in application security. Our mission is to raise awareness in the software development world to the importance of integrating software security across the development lifecycle.

Applied Security (APSEC)

Applied Security (APSEC)

APSEC provides products and services in the areas of encryption, digital signature, authentication and data loss prevention.

QSecure

QSecure

QSecure specializes in the provision of information security and risk management services.

NSEIT

NSEIT

NSEIT offers end-to-end Information Technology products, solutions and services including cybersecurity to organizations in the financial sector.

CYQUEO

CYQUEO

CYQUEO is your professional partner and system integrator. We secure your organization against advanced cyber threats.

Granted Consultancy

Granted Consultancy

Granted Consultancy is a business consultancy that specialises in securing funding to support companies with the development and commercialisation of new and innovative products and technologies.

Aujus Cybersecurity

Aujus Cybersecurity

Aujas is a pure-play cyber security services company with deep expertise in Identity and Access Management, Managed Security and Security Testing services.

Boeing

Boeing

Boeing is the world's largest aerospace company and leading manufacturer of commercial jetliners, defense, space and security systems.

Kinetic Investments

Kinetic Investments

Kinetic Investments provide entrepreneurs with the capital and support required to transform their vision into a success, in return for shared ownership of the company.

Acronis

Acronis

At Acronis, we protect the data, applications, systems and productivity of every organization – safeguarding them against cyberattacks, hardware failures, natural disasters and human errors.

DigitalPlatforms

DigitalPlatforms

DigitalPlatforms SpA is an Italian group with the mission of providing end-to-end solutions and Internet of Things and Cyber technologies to companies that manage critical infrastructures.

Segra

Segra

Segra owns and operates one of the nation’s largest fiber networks and provides best-in-class broadband and data security solutions throughout the Southeast and Mid-Atlantic.

Conceal

Conceal

Conceal’s mission is to stop ransomware and credential theft for companies of all sizes by developing innovative solutions that provide social engineering protection in any browser.