Attacks/Breaches

5/12/2017
03:30 PM
100%
0%

'WannaCry' Rapidly Moving Ransomware Attack Spreads to 74 Countries

A wave of ransomware infections took down a wide swath of UK hospitals and is rapidly moving across the globe.

The so-called Wanna Decryptor ransomware is currently moving like wildfire across 74 countries in more than 45,000 attacks, including a massive takedown of several UK hospitals today.

The number of infections across the world is quickly growing, according to Kaspersky's Twitter post. So far, some of the countries that have been hit include Britain, Spain, Russia, Taiwan, India, and the Ukraine, according to various reports streaming across the WannaCry Twitter feed.

Security experts say the ransomware attack is exploiting the Server Message Block (SMB) critical vulnerability that was patched by Microsoft on March 14, MS17-010. The 0day exploit, aka ETERNALBLUE, believed to be an NSA exploit tool, initially was leaked by Shadowbrokers, prompting a patch from Microsoft.

"There is nothing comparable to date. This is a massive global ransomware operation, the largest and most effective to date. Unfortunately, not all organizations patched against ETERNALBLUE/shadowbrokers exploits," said Kurt Baumgartner, principal security researcher, Global Research and Analysis Team (GReAT) for Kaspersky Lab.

According to an Avast blog post, Telefonica in Spain and the National Health Service (NHS) hospitals in England have been hit.

In the UK, a large scale attack hit a number of hospitals across the region, forcing medical staff to re-route emergency patients to other hospitals in the area, according to a report in The Guardian.

The malware struck NHS hospitals around lunch time, with an initial email going out to employees that the email servers were encountering difficulty, followed by clinical and patient systems going down, the Guardian reported. That was followed by a ransom note appearing on employees' computer screens, demanding $300 in Bitcoins to be paid in three days, otherwise the ransom would double. And if no payment was made after seven days, then the files would be forever lost, according to the report.

The NHS issued an alert and confirmed 16 medical centers had been hit, according to Kaspersky Lab.

This ransom message also appeared in Spain, where telecom giant Telefonica was also targeted, the Guardian noted.

"The suspected syndicated attack is unique in that it’s not targeted at any one industry or region, and is using a particularly nasty form of malware that can move through a corporate network from a single entry point," says Simon Crosby, co-founder and chief technology officer at Bromium.

"As usual, it’s leveraging a recently patched vulnerability that many have failed to implement in a timely matter," he says. "As long as the industry continues to play this never ending cat and mouse game of patchwork systems, sophisticated attackers will easily find ways to exploit the public in increasingly large scale attacks such as this."

How WannaCry Makes You Cry

The ETERNALBLUE exploit tool surfaced on the Internet via the Shadowbrokers' dump on April 14. Although Microsoft had issued the March patch, many organizations have not yet installed it, according to Kaspersky's blog post on WannaCry.

The security firm said WannaCry initiates through an SMBv2 remote code execution in Microsoft Windows and then encrypts data with a file extension ".WCRY." It then drops and executes a decryptor tool that was designed to hit users in multiple countries with a ransom note translated to the appropriate language for that country, according to Kaspersky Lab.   

Kaspersky's Baumgartner describes the attack this way: "It is a worm over SMB and the communications are over TOR, directly to hidden services, so I would not call it a peer-to-peer worm."

Researchers recommend installing Microsoft's patch, which closes the affected SMB Server vulnerability used in the WannaCry attack.

For organizations that have older equipment or legacy software, such as hospitals, manufacturing plants, and power plants, deploying a patch can be complicated and disruptive, which may in part explain how a wide swath of NHS hospitals fell victim to WannaCry.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MattP654
100%
0%
MattP654,
User Rank: Apprentice
5/19/2017 | 5:32:57 AM
Re: WannaCry ransomware
According to the statistic the infected countries are increasing to over 99. This situation is deteriorating. We should be careful and update Windows Security. So that anyone can't interfare easily. Why not to udaptes Windows right now using a command line https://wuinstall.com/ so that the Admin can get the full access and Control the Windows Security.
inforobob
50%
50%
inforobob,
User Rank: Apprentice
5/15/2017 | 5:25:30 PM
Update
Hey Foks,

Time to update this article, eh?

Robert
mvalente
50%
50%
mvalente,
User Rank: Apprentice
5/12/2017 | 5:03:34 PM
Correction
Correction:

 

"Unfortunately, not all organizations patched against ETERNALBLUE/*NSA* exploits," "
NikNd
50%
50%
NikNd,
User Rank: Apprentice
5/12/2017 | 4:32:39 PM
WannaCry ransomware
Most infected computers are in Russia and it's a sign that WannaCry is a planned cyber-attack
against Russian organizations and institutions, including Ministry of Internal Affairs
of Russia and Investigative Committee of Russia as it's said there
https://malwareless.com/wannacry-ransomware-massively-attacks-computer-systems-world/.
Russian hackers never attacked computers inside their country with ransomware in order
to avoid further problems with police and FSB
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
How Well Is Your Organization Investing Its Cybersecurity Dollars?
Jack Jones, Chairman, FAIR Institute,  12/11/2018
The Case for a Human Security Officer
Ira Winkler, CISSP, President, Secure Mentem,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18397
PUBLISHED: 2018-12-12
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/us...
CVE-2018-20094
PUBLISHED: 2018-12-12
An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.
CVE-2018-20095
PUBLISHED: 2018-12-12
An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by mp42hls.
CVE-2018-20096
PUBLISHED: 2018-12-12
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
CVE-2018-20097
PUBLISHED: 2018-12-12
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.