EMZETT.
Login

WannaCry

In short: WannaCry was a worldwide ransomware attack in May 2017 that spread like a worm through Windows networks.

In more detail: Hundreds of thousands of computers in over 150 countries were affected, including hospitals of the British NHS, railway displays and industry. Encrypted files were released against bitcoin.

In Depth

Technology

WannaCry used EternalBlue (and the back door DoublePulsar) to spread by itself. The malware contained a “kill switch” domain; the researcher Marcus Hutchins registered it and slowed the spread.

Attribution

The group Lazarus (North Korea) is held responsible.

Lesson

Patches, backups, network segmentation, replace outdated systems. See worms, Locky.

See also: EternalBlue, Worms, Locky, Exploit