The first wave is over. The WannaCry ransomware campaign hit more than 70 countries, toppled high-profile companies, and compromised the UK's health system. Derived from an exploit created by the NSA and leaked by the Shadow Brokers group, WannaCry takes advantage of a vulnerability that Microsoft patched in March, though it's clear that administration practices worldwide leave much to be desired. In the best case, your system is already protected, but if you have doubts, it's best to keep reading…
A Global Outbreak
The situation was bizarre. Traditional media began talking about terms like "ransomware" and "cyberattack", and as hours passed it became clear this wasn't an isolated incident. A new campaign had gone active, and its first move hit hard. It reached more than 70 countries, taking out Telefónica, FedEx, and the British health system. Most of the attacks (more than 75,000 so far) were concentrated in Russia, Ukraine, and India, but it didn't take long to spread beyond those territories. And indeed it is a ransomware, a variant of malware we've been discussing a lot in recent months, and which apparently nobody took seriously until now. It has multiple names, but the most popular is WannaCry, and it basically demands $300 in bitcoins in exchange for the kidnapped information. If the victim doesn't pay before May 15, the price will increase and they'll get 96 additional hours.
What Makes WannaCry So Dangerous
Examining WannaCry more deeply reveals two very interesting and worrying details. First, its development is based on the ETERNALBLUE tool that attacks a vulnerability in Windows' SMB protocol. This resource was stolen from the NSA in April by the Shadow Brokers group, so a good part of the digital world just felt the fire of a military-grade weapon. Second, it's worth noting that Microsoft released a patch to neutralize ETERNALBLUE, under security bulletin MS17-010, classified as "critical". The hotfix has been available on all affected systems since March, and due to severity, Microsoft decided to publish an out-of-band patch for its three unsupported systems: Windows XP, Windows 8, and Windows Server 2003. Fortunately, security researcher MalwareTech discovered WannaCry's "kill switch" after taking control of a domain integrated with the exploit, and also created a map to help visualize the campaign's impact.
Four Steps to Stay Protected
The real problem is that with so many unprotected systems, it's only a matter of time before the responsible parties modify their code and try again. Recommendations? In theory, the average user with an up-to-date Windows should be immune to WannaCry, but let's review four points:
- If the hotfix equivalent to MS17-010 for your operating system isn't installed, do it now. Windows XP, Windows 8, and Windows Server 2003 received an "extraordinary exception" through a dedicated patch.
- Reinforce router security policies on TCP ports 139 and 445, historically associated with SMB. In other words, don't let anything in through there.
- Disable SMBv1. The process was explained in bulletin MS17-010, and applies only to Windows Vista onward. This is found under "Turn Windows features on or off" in "Programs", within the Control Panel.
- Explore an antiransomware option to complement traditional antiviruses.