What is ransomware: All that we currently know about the global cyberattack
On the other hand, the attack has served as a live demonstration of a new type of global threat, one that could encourage future hackers.
Here’s what we currently know about the ransomware known as WannaCry, which locked up digital photos, documents and other files to hold them for ransom.
Researchers are still puzzling out how WannaCry got started. Figuring that out could yield important clues to the identity of its authors.
The malware spread rapidly inside computer networks by taking advantage of vulnerabilities in mostly older versions of Microsoft Windows. That weakness was purportedly identified and stockpiled for use by the US National Security Agency; it was subsequently stolen and published on the internet.
But it remains unclear how WannaCry got onto computers in the first place. Experts said its rapid global spread suggests it did not rely on phishing, in which fake emails tempt the unwary to click on infected documents or links. Analysts at the European Union cybersecurity agency said the hackers likely scanned the internet for systems that were vulnerable to infection and exploited those computers remotely.
Once established, WannaCry encrypted computer files and displayed a message demanding $300 to $600 worth of the digital currency bitcoin to release them. Failure to pay would leave the data scrambled and likely beyond repair unless users had unaffected backup copies.
Investigators are closely watching three bitcoin accounts associated with WannaCry, where its victims were directed to send ransom payments. The digital currency is anonymized, but it’s possible to track funds as they move from place to place until they end up with an identifiable person.
So far, there have been no withdrawals from those accounts.
Several sets of investigators have now reported tentative findings that suggest hackers linked to North Korea might have been involved with WannaCry. But they could all be drawing conclusions from a very small set of clues.
On Monday, the Russian security firm Kaspersky Lab said portions of the WannaCry program use the same code as malware previously distributed by the Lazarus Group, a hacker collective behind the 2014 Sony hack. Another security company, Symantec, related the same findings, which it characterized as intriguing but “weak” associations, since the code could have been copied from the Lazarus malware.
Two law enforcement officials likewise said US investigators suspect North Korea based on code similarities; the officials called that finding preliminary. The officials spoke to The Associated Press on condition of anonymity because they aren’t authorized to speak publicly about an ongoing investigation.
But WannaCry remains a puzzle, in part because some of its elements seemed amateurish. Salim Neino, CEO of the Los Angeles-based security firm Kryptos Logic, said the WannaCry worm was “poorly designed” — patched together and consisting of a “sum of different parts” with an unsophisticated payment system.
Typical ransomware also generates a unique bitcoin account for each payment to make tracing difficult. That wasn’t done here.
One of the organizations hardest hit by WannaCry — the UK’s National Health Service — appears to be recovering. On Friday, many NHS hospitals had to turn away patients after WannaCry locked up computers, forcing the closure of wards and emergency rooms.
NHS Digital, the body that oversees cybersecurity in Britain’s health system, said that as of now, it has “no evidence that patient data has been compromised.” The agency told hospitals to disconnect all infected computers, apply a Microsoft patch that closes the vulnerability, then “roll back” the infected computers and restore them from backed-up files.
Sign of hacks to come
WannaCry could also serve as a kind of template for future cyberattacks.