Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

'WannaCry' Rapidly Moving Ransomware Attack Spreads to 74 Countries

A wave of ransomware infections took down a wide swath of UK hospitals and is rapidly moving across the globe.

The so-called Wanna Decryptor ransomware is currently moving like wildfire across 74 countries in more than 45,000 attacks, including a massive takedown of several UK hospitals today.

The number of infections across the world is quickly growing, according to Kaspersky's Twitter post. So far, some of the countries that have been hit include Britain, Spain, Russia, Taiwan, India, and the Ukraine, according to various reports streaming across the WannaCry Twitter feed.

Security experts say the ransomware attack is exploiting the Server Message Block (SMB) critical vulnerability that was patched by Microsoft on March 14, MS17-010. The 0day exploit, aka ETERNALBLUE, believed to be an NSA exploit tool, initially was leaked by Shadowbrokers, prompting a patch from Microsoft.

"There is nothing comparable to date. This is a massive global ransomware operation, the largest and most effective to date. Unfortunately, not all organizations patched against ETERNALBLUE/shadowbrokers exploits," said Kurt Baumgartner, principal security researcher, Global Research and Analysis Team (GReAT) for Kaspersky Lab.

According to an Avast blog post, Telefonica in Spain and the National Health Service (NHS) hospitals in England have been hit.

In the UK, a large scale attack hit a number of hospitals across the region, forcing medical staff to re-route emergency patients to other hospitals in the area, according to a report in The Guardian.

The malware struck NHS hospitals around lunch time, with an initial email going out to employees that the email servers were encountering difficulty, followed by clinical and patient systems going down, the Guardian reported. That was followed by a ransom note appearing on employees' computer screens, demanding $300 in Bitcoins to be paid in three days, otherwise the ransom would double. And if no payment was made after seven days, then the files would be forever lost, according to the report.

The NHS issued an alert and confirmed 16 medical centers had been hit, according to Kaspersky Lab.

This ransom message also appeared in Spain, where telecom giant Telefonica was also targeted, the Guardian noted.

"The suspected syndicated attack is unique in that it’s not targeted at any one industry or region, and is using a particularly nasty form of malware that can move through a corporate network from a single entry point," says Simon Crosby, co-founder and chief technology officer at Bromium.

"As usual, it’s leveraging a recently patched vulnerability that many have failed to implement in a timely matter," he says. "As long as the industry continues to play this never ending cat and mouse game of patchwork systems, sophisticated attackers will easily find ways to exploit the public in increasingly large scale attacks such as this."

How WannaCry Makes You Cry

The ETERNALBLUE exploit tool surfaced on the Internet via the Shadowbrokers' dump on April 14. Although Microsoft had issued the March patch, many organizations have not yet installed it, according to Kaspersky's blog post on WannaCry.

The security firm said WannaCry initiates through an SMBv2 remote code execution in Microsoft Windows and then encrypts data with a file extension ".WCRY." It then drops and executes a decryptor tool that was designed to hit users in multiple countries with a ransom note translated to the appropriate language for that country, according to Kaspersky Lab.   

Kaspersky's Baumgartner describes the attack this way: "It is a worm over SMB and the communications are over TOR, directly to hidden services, so I would not call it a peer-to-peer worm."

Researchers recommend installing Microsoft's patch, which closes the affected SMB Server vulnerability used in the WannaCry attack.

For organizations that have older equipment or legacy software, such as hospitals, manufacturing plants, and power plants, deploying a patch can be complicated and disruptive, which may in part explain how a wide swath of NHS hospitals fell victim to WannaCry.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MattP654
100%
0%
MattP654,
User Rank: Apprentice
5/19/2017 | 5:32:57 AM
Re: WannaCry ransomware
According to the statistic the infected countries are increasing to over 99. This situation is deteriorating. We should be careful and update Windows Security. So that anyone can't interfare easily. Why not to udaptes Windows right now using a command line https://wuinstall.com/ so that the Admin can get the full access and Control the Windows Security.
inforobob
50%
50%
inforobob,
User Rank: Apprentice
5/15/2017 | 5:25:30 PM
Update
Hey Foks,

Time to update this article, eh?

Robert
mvalente
50%
50%
mvalente,
User Rank: Apprentice
5/12/2017 | 5:03:34 PM
Correction
Correction:

 

"Unfortunately, not all organizations patched against ETERNALBLUE/*NSA* exploits," "
NikNd
50%
50%
NikNd,
User Rank: Apprentice
5/12/2017 | 4:32:39 PM
WannaCry ransomware
Most infected computers are in Russia and it's a sign that WannaCry is a planned cyber-attack
against Russian organizations and institutions, including Ministry of Internal Affairs
of Russia and Investigative Committee of Russia as it's said there
https://malwareless.com/wannacry-ransomware-massively-attacks-computer-systems-world/.
Russian hackers never attacked computers inside their country with ransomware in order
to avoid further problems with police and FSB
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Virginia a Hot Spot For Cybersecurity Jobs
Jai Vijayan, Contributing Writer,  10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14832
PUBLISHED: 2019-10-15
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.
CVE-2017-10022
PUBLISHED: 2019-10-15
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing ...
CVE-2019-10759
PUBLISHED: 2019-10-15
safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
CVE-2019-10760
PUBLISHED: 2019-10-15
safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
CVE-2019-17397
PUBLISHED: 2019-10-15
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.