A look at how the WannaCry ransomware works
KINIGUIDE It has been a week since the WannaCry ransomware made headlines worldwide by locking up hundreds of thousands of computers worldwide, and demanded payment for letting the users back into their own files.
As the dust settles, this instalment of KiniGuide takes a look at how WannaCry works and how it got so prolific.
What is a ransomware?
Ransomware is a type of malicious software (malware) that scrambles the information stored in the infected computer, which renders it unreadable.
As the name suggests, the ransomware then demands payment for unscrambling that same information.
The first ransomware dates back to 1989, but this type of cyberattack has gained popularity since 2013.
What exactly does WannaCry do?
It is unclear how the initial infection was made, but it was suspected to be an email with a link to the ransomware, or an email attachment masquerading as an invoice or some other documents. The first reports about WannaCry started on May 12.
Regardless of how a computer was initially infected, it would then exploit a security loophole in the computer’s file sharing system to quietly spread to other computers on the same network.
It would scramble the information on all the infected computers, and then demand a payment in US$300 (RM1,298) worth of BitCoins (a type of digital currency) in three days. Otherwise, the ransom doubles to US$600 (RM2,597).
After seven days from the ransom demand, the users are locked out for their files forever.
Who is vulnerable?
The WannaCry (also known as WannaCrypt, WanaCrypt0r, WCrypt, or WCRY) ransomware targets Microsoft Windows computers that have not been updated recently. Windows 10 is not being targeted.
Who has been hit?
According to the European Union Agency for Law Enforcement Cooperation director Rob Wainwright, there an estimated total of 200,000 victims in at least 150 countries. A more recent report claimed the figure to be closer to 300,000.
Among the worst hit are some hospitals in the UK, which were forced to turn away patients while staff got locked out of their computers....
KINIGUIDE | It has been a week since the WannaCry ransomware made headlines worldwide by locking up hundreds of thousands of computers worldwide, and demanded payment for letting the users back into their own files.
As the dust settles, this instalment of KiniGuide takes a look at how WannaCry works and how it got so prolific.
What is a ransomware?
Ransomware is a type of malicious software (malware) that scrambles the information stored in the infected computer, which renders it unreadable.
As the name suggests, the ransomware then demands payment for unscrambling that same information.
The first ransomware dates back to 1989, but this type of cyberattack has gained popularity since 2013.
What exactly does WannaCry do?
It is unclear how the initial infection was made, but it was suspected to be an email with a link to the ransomware, or an email attachment masquerading as an invoice or some other documents. The first reports about WannaCry started on May 12.
Regardless of how a computer was initially infected, it would then exploit a security loophole in the computer’s file sharing system to quietly spread to other computers on the same network.
It would scramble the information on all the infected computers, and then demand a payment in US$300 (RM1,298) worth of BitCoins (a type of digital currency) in three days. Otherwise, the ransom doubles to US$600 (RM2,597).
After seven days from the ransom demand, the users are locked out for their files forever.
Who is vulnerable?
The WannaCry (also known as WannaCrypt, WanaCrypt0r, WCrypt, or WCRY) ransomware targets Microsoft Windows computers that have not been updated recently. Windows 10 is not being targeted.
Who has been hit?
According to the European Union Agency for Law Enforcement Cooperation director Rob Wainwright, there are an estimated total of 200,000 victims in at least 150 countries. A more recent report claimed the figure to be closer to 300,000.
Among the worst hit are some hospitals in the UK, which were forced to turn away patients while staff got locked out of their computers.
Closer to home, cyber security firm LE Global Services reportedly said on Wednesday it had identified 12 cases so far, including a large government-linked corporation, a government-linked investment firm and an insurance company. It did not name the companies affected.
Has the danger passed?
Not really. A UK-based security researcher who goes by the pseudonym ‘MalwareTech’ noticed that WannaCry checks for a non-existent website, and decided to register the website for himself in an attempt to study the infection.
As it would turn out, he had accidentally flipped WannaCry’s kill-switch in doing so. When WannaCry checks and finds that the website is now live, it stops short of scrambling its host’s data.
This prevented further infections, but computers that have already had their data scrambled are still out of luck.
Since then, newer versions of WannaCry have emerged, but this time without a kill-switch.
Why was WannaCry so prolific?
WannaCry uses two exploits originally developed as intelligence-gathering tools by the US National Security Agency (NSA), which was stolen and leaked to the public in April.
One was codenamed EternalBlue, which allows malicious software to spread quietly through file sharing system known as the Server Message Block (SMB). WannaCry uses this to spread unnoticed through computer networks.
The other part was codenamed DoublePulsar, which provided NSA with a backdoor to take control of an infected computer. WannaCry installs this after it gains a foothold in a computer via EternalBlue, and uses this as a means to run software the scrambles its victim’s data.
According to a Washington Post report on May 16, the NSA had been using EternalBlue for over five years, and this helped yield an intelligence haul that one unnamed former employee compared to “fishing with dynamite”.
When the agency learnt that EternalBlue may have been stolen, it finally warned Microsoft about the vulnerability in its systems.
Microsoft released a patch to fix the vulnerability on March 14. Following recent attacks, Microsoft president Brad Smith publicly condemned the US government for stockpiling software vulnerabilities instead of reporting it to Microsoft.
“An equivalent scenario with conventional weapons would be the US military having some of its Tomahawk missiles stolen. And this most recent attack represents a completely unintended but disconcerting link between the two most serious forms of cybersecurity threats in the world today - nation-state action and organised criminal action,” Smith said.
For the record, security vulnerabilities discovered by security researchers are normally disclosed privately to the technology companies that make them, and the discovery is made public once it has been fixed. Many companies offer a bounty programme to encourage such disclosures.
However, information on vulnerabilities and exploits are also traded on a grey market for thousands - potentially hundreds of thousands - of dollars.
If the problem had been ‘fixed’ in March and made public in April, why did so many people get infected?
There are many possible reasons why people have not updated their computers.
Some organisations - particularly large ones - may have old but crucial software (such as for billing, databases, MRI scanners, and so on) that cannot run on newer versions of Microsoft Windows.
Therefore, these organisations kept using the older versions of Windows even though Microsoft has stopped providing updates for that version of Windows. This is cheaper for the organisation than updating the software to run on newer versions of Windows.
Alternatively, the organisation’s IT department may hold off an update until its sure that the update would go smoothly and would not break anything that the organisation was using.
Some users also find the way Windows Update works and restarts the computer by itself obnoxious, and simply turn it off. Or they may be running pirated versions of Windows, and turn off automatic updates so that they won’t be found out and nagged about buying genuine versions of Windows.
How many people have paid the ransom?
Since May 12 until 6pm yesterday, the three BitCoin accounts associated with WannaCry have logged 287 transactions into the accounts. This totals to 44.80393136 BitCoins, or the equivalent of US$81,240.98 (RM352,805).
To date, there has yet to be any transfers out of the accounts.
BitCoin accounts are anonymous, but the transactions between them are transparent. You can track the three BitCoin accounts here.
Is this the only way the NSA’s exploits are being used?
No. Researchers studying the WannaCry attack uncovered another one, dubbed Adylkuzz, which appeared some time between April 24 and May 2.
Adylkuzz exploits the same security weaknesses as WannaCry. Unlike WannaCry that announces its presence to its victim, Adylkuzz runs quietly in the background.
The only thing the victim would notice is that his computer is running much slower, as precious computer resources are sapped to “mint” a digital currency known as Monero, which is similar to BitCoin but is supposed to have a higher level of anonymity.
Reuters quoted Proofpoint executive Ryan Kalember as saying that this could have earned Adylkuzz’s authors over US$1 million.
What should I do?
Basic computer hygiene rules are adequate to protect against WannaCry and similar attacks, so you should do the following even if your computer does not run on Microsoft Windows. The list is arranged from the most important, to the least important:
- Update your operating system regularly. If your operating system is no longer eligible for regular updates, consider upgrading to a newer operating system.
- Keep other software you have installed up to date too.
- Make regular back-ups of your files and keep them somewhere safe and disconnected from the Internet.
- Do not click on links and attachments in emails unless you are sure about the sources. Be mindful that the ‘sender’ of an email can be faked.
- Consider installing an antivirus software, and keep it up to date.
If your computer is already infected, there is no known way to save your data, apart from paying the ransom and hope WannaCry’s authors hold up to their end of the bargain.
However, if you are considering this option, be mindful that you may end up funding criminal activity, and that may not be worth your data. It may be better to simply reformat your computer and start afresh, or from any back-ups that you may have.
This instalment of KiniGuide is compiled by Koh Jun Lin

