No Results Found.
The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.
Aaron R. Warner
•
May 15, 2017
The WannaCry (aka wCry or WannaCrypt) ransomware is making its way across the world, and there are several variants on their way to the united states. The original version of the ransomware behaves much like the Locky or other mainstay threats – it encrypts your data with military-grade encryption tech, starts a timer, and provides you with a place that you can pay to get a key which allows you to decrypt your valuable data.
Unfortunately, there are a few new twists on this latest bug. While the approach isn’t unique, the delivery mechanism is derived from several cyberweapons designed by the NSA and leaked (reported) by a group called “The Shadowbrokers” within the last few weeks.
There are also additional variants of the WannaCry ransomware that may complicate things. Rather than providing a ‘real’ key they’ve been modified to simply encrypt and forget, leaving out the option of ever seeing your data again.
The research firm MalwareTech took much of the steam out of the earlier versions of this ransomware. Without going into technical detail, the firm registered the domain of the site that the application uses to ‘call home’ and essentially stops it from propagating. Unfortunately, though, the new variants either use a new site or remove the ‘call home’ completely.
The most important things that organizations can do to protect yourself are listed below and adapted from some recent work by Troy Hunt at Microsoft. I’ve taken the liberty of changing the order of the recommendations so that if you only do one thing it’s at the top:
To pay or not to pay? Our advice is usually determined on a case by case basis. In the past we’d generally have recommended paying, but many of our sources lead us to believe that your likelihood of getting keys is lower with this particular strain.
ProCircular is available to assist with any sort of cybersecurity challenge. We can help to walk you through the steps necessary to deal with WannaCry or any other bug, and once you’re out of the woods we help you to avoid danger in the future.
(Image source: The Hacker News)
Talk with ProCircular about incident response, tabletop exercises, security assessment, and practical ways to reduce risk.