WannaCry Ransomware Anniversary Highlights Ongoing Cyber Threat Risks
Two years after the devastating WannaCry ransomware attack paralyzed global systems, the incident serves as a stark reminder of the dangers of leaked government cyberweapons and unpatched software.
Two years after the devastating WannaCry ransomware attack, the cybersecurity landscape still feels the impact of this unprecedented global event. The malware spreads rapidly across 150 countries by exploiting a Windows vulnerability, encrypting hundreds of thousands of computers and crippling essential services like the U.K.'s hospital networks, government systems, and railway networks. Security researchers quickly discover that the attack relies on highly classified hacking tools stolen from the National Security Agency and published online just weeks prior.
The unknown hackers, widely believed to be working for North Korea, weaponize the NSA's EternalBlue exploit and DoublePulsar backdoor to create a self-replicating computer worm. A single vulnerable, internet-exposed system is enough to allow the ransomware to infect every other unpatched computer on a local network. Although Microsoft releases patches in anticipation of the stolen tools being used, consumers and businesses move too slowly to update their systems, resulting in billions of dollars in damages as victims desperately send Bitcoin to the attackers with little hope of recovering their files.
The rapid spread of the ransomware finally halts thanks to the quick thinking of malware reverse engineer Marcus Hutchins, who cuts his vacation short to analyze the code. By examining data from his malware tracking system, he discovers a hardcoded domain name acting as a kill switch, and registering it immediately stops the wave of new infections. Despite recent legal troubles unrelated to the attack, Hutchins is hailed as a hero for stepping in to stop a cyberattack that easily overwhelms unprepared organizations around the globe.