The WannaCry malware attack that crippled computers around the world in May 2017 could have been much worse if not for the quick-thinking actions of a 22-year-old British cyber protector. His actions are a bright light on an incident that caused costly damage to companies and individuals who rely on a digital workplace — and its lessons still apply.
WannaCry Dominates Technology News
The attack began by exploiting software leaked by the U.S. National Security Agency. The ransomware spread rapidly to 150 countries and major companies such as FedEx and Nissan. The attack brought down portions of Britain's National Health Service, delaying treatment for patients at British hospitals.
Once infected, a computer would spread the malware throughout a networked system. An infected computer became inoperable, its monitor displaying a red sign instructing the user to pay about $300 in bitcoin to unlock the machine.
White-hat computer experts began reverse-engineering the code, looking for a solution. One of those experts used the handle "MalwareTech." Hackers often include a kill switch code — one theory is that if the perpetrators feel the attack has gone too far, they can stop it; another is that the code alerts the hackers when security analysts are trying to stop the attack. In this case, the plan backfired.
A Critical Discovery, a $10 Domain Fix
The WannaCry builders included a dummy URL in the code. MalwareTech found the URL, noted that it wasn't registered, and made the decision to spend $10 to register the domain. Once the website was registered and hosted, it activated a kill switch: when the WannaCry ransomware connected to the website and it was no longer gibberish, the program shut down.
MalwareTech then created a "sinkhole" on the domain. Malicious traffic directed to the server was captured and held there — committing server space and bandwidth to capture and kill attacks.
Buying Time
The sinkhole bought the extra time needed for security patches to be disseminated and installed. But it was not a permanent solution: a new strain that excludes the kill switch domain or uses a URL generator instead of a single static address could cause more havoc. The lesson for every digital workplace: patch promptly, back up religiously, and don't count on a hero with a $10 domain.
Read about NPA's ransomware protection.
← Back to Work It!