9 ms·
WannaCry – The largest ransom-ware infection in history
- sowbug 9y agoThese are the three Bitcoin addresses referenced in the article: https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX... https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8is... https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N... As of now, the three addresses have received a total of about 20 BTC, or about $36,000 at current exchange rates. The most typical transaction sends about $300 to the addresses. No funds have left the addresses yet.
- martinko 9y agohow is a specific computer linked to a payment if they reuse addresses? If they do not reuse addresses, why did those 4 receive so much btc?
- sowbug 9y agoI don't know, but I can think of a few possibilities: 1. The amount demanded varies from incident to incident. Bitcoin is fractional to 8 decimal places, so it's possible to narrow down the list of victims by the last N digits of the payment. 2. The original demand for payment includes instructions to list the address you sent from. This would be a lame solution for many reasons, including (1) these victims are probably all new to Bitcoin and would have no idea what an address is, and (2) according to an article I read, some security consultants keep a Bitcoin wallet handy to pay on behalf of their clients, leading to duplicate payer addresses. 3. Same as #2 but demanding that the victim include the transaction ID, which is a long hex string. Similar usability issues. 4. It's possible to embed metadata into Bitcoin transactions. As with the prior approaches, victims would likely get this wrong. Most likely there's a human criminal on the other end of the exchange, and that human matches up victims and payments. Because the paying victims are surely unsophisticated about Bitcoin and terrified about what is happening to them, it seems likely that the risk of one victim claiming another victim's payment is small, so the manual match-up method is probably the most practical solution from the criminals' standpoint.
- Scoundreller 9y ago> Because the paying victims are surely unsophisticated about Bitcoin and terrified about what is happening to them, it seems likely that the risk of one victim claiming another victim's payment is small, so the manual match-up method is probably the most practical solution from the criminals' standpoint. Is it really that small? What's stopping a victim from claiming someone else's payment by watching transactions and notifying the criminal that "their" payment has been sent?
- deleted 9y ago[deleted]
- sowbug 9y agoIf you barely understand how computers work, but you know your business's accounts receivables file is gone, and somebody is saying they will retrieve it if you send them some weird internet money, you're probably going to do exactly what they say rather than view this as a great opportunity to scam a scammer. Plus, the criminals they might be trying to scam are almost certainly the victims' only hope of obtaining the symmetric encryption key (there are exceptions; some of these programs have been shown to be written by people not entirely clear on how crypto works -- single global key, obfuscated key on client machine, etc.). By definition, the only people interested in paying are the people who have no backups of data they need, so they have no options, and taking the risk of pissing off the criminal doesn't really make sense. Moreover, for all we know, some victims haven't figured out that they're paying the same people who did the encryption in the first place. From their point of view, this is just like buying antivirus software or taking their computer to Geek Squad.
- SolarNet 9y ago> not entirely clear on how crypto works Sometimes they accidentally weaken the algorithm (like by chopping it's key bits in half through a weak RNG). Crypto is hard, even when the scammer probably has a good grasp. Which is useful in this case.
- Scoundreller 9y agoWhat's with the people sending 0.0001 BTC (~17 cents), and paying a .0004 transaction fee (~82 cents) all about?
- awake 9y agoPossibly researchers? Or people who don't know how bit coin works. No idea though...
- pmorici 9y agoThis is pretty common whenever there is a Bitcoin theft people sent small amounts of Bitcoin to the suspected theft address. I believe they do it as a means to tracking what happens to the stolen funds. It keeps them from having to keep track of every address instead they just send a small amount of BTC to it and then they just need to remember their wallet address in the future to track to all the addresses they "marked".
- Scoundreller 9y agoAnother theory is that it's Law Enforcement. In order to get a conviction, their case is improved if they can show a trail of money just in case they can't get a witness that paid the ransom to testify with proper documentation.
- easilyBored 9y ago"...or about $36,000 at current exchange rates" Not enough to make up for having every spy agency on your back. Is there a realistic way to get the funds free and clear even if NSA /FBI /CIA / et al are on your trail?
- grkvlt 9y agoSo, it would seem reasonable to assume that around ~120 people/entities have caved in to the ransom demand and paid the USD 300? I wonder if they all actually got their files decrypted?
- mcv 9y agoWhat surprises me about this case is how little information there is about that. Has anyone paid? Did they get their content back? If so, that would encourage others to pay up, making this attack more profitable, and more likely in the future. So I suppose that's why everybody keeps quiet about this. But for important systems, $300 is very cheap compared to restoring the system from backup including all the missed operation time, so I can imagine a lot of people would be tempted to pay. If really only 120 people paid, I'd find that quite surprising.
- liberte82 9y agoA lot of people probably don't know how to pay by bitcoin. I expect this number to jump up as deadlines approach and people figure it out.
- deleted 9y ago[deleted]
- dmix 9y agoIt's up to 32BTC / $55,400 today. Not much given the global outcry but I guess the ransom part wasn't the interesting thing. Is this just from the one version? Or are there other addresses in use?
- faragon 9y agoIn the meantime, what are doing the FBI, the NSA, and other agencies that exist precisely to avoid that?
- MichaelBurge 9y agoThe ransomware was built from NSA tools, and I think it's illegal for them to comment on leaked classified information. The FBI doesn't publicly comment on on-going investigations. You might be able to ask them if one exists, though.
- faragon 9y agoMy point was about those agencies catching ransomware authors.
- rl3 9y agoTheoretically there's nothing legally stopping a NSA/GCHQ tag team from mercilessly hunting down and destroying ransomware operations. NSA only has red tape when it comes to U.S. citizens, but GCHQ doesn't. GCHQ's mandate also includes serious organized crime. Moreover, considering the damage ransomware can do to critical government infrastructure (for example NHS), it's not a stretch to imagine that targeting ransomware operations would fall under legitimate national security grounds. Personally I'm surprised they don't just completely fuck these people up to set an example. On the other hand, there's always the possibility WannaCry could be a mud slinging attempt from a state actor, given the much-publicized fact it uses leaked NSA vulns.
- Freak_NL 9y ago> […] fuck these people up to set an example. I don't think it would be very effective. There are three reasons for hunting down and persecuting perpetrators of crime: vengeance, setting an example, and undoing the damage. Only the last reason makes any practical sense here. This attack works, so there will be others in the future, but it will happen regardless of the threat of punishment. Sure, if you set an example some people might be deterred, but surely not the bright hacker in a basement in Yekaterinburg, or the determined gang in Nigeria, or the mobsters in Chengdu City; i.e., anyone, anywhere without much to lose?
- edoceo 9y agoSo big that MS has to release a patch for Windows XP!
- johnnydoe9 9y agoXP, 8 and Server 2003. Patches for 3 unsupported versions edit: 2003* my bad https://arstechnica.com/security/2017/05/wcry-is-so-mean-microsoft-issues-patch-for-3-unsupported-windows-versions/ https://arstechnica.com/security/2017/05/wcry-is-so-mean-mic...
- firewalkwithme 9y agoI don't understand how a machine becomes infected, it is perhaps not very clear yet? this article explains receiving an email containing a link OR a PDF with a link to a .hta file ? what a strange sentence. Can one get infected without user interaction, or even with a passive client ?
- remx 9y agoThis is what I want to know[0] too. To mitigate, you can disable SMB1.0 with the following command. Make sure to run as administrator: dism /online /norestart /disable-feature /featurename:SMB1Protocol [0]: https://news.ycombinator.com/item?id=14335845 https://news.ycombinator.com/item?id=14335845
- syshum 9y agoTo mitigate, Install Security Patches in a Timely manner. Also note that only works on windows 7 and later, dism is not a tool for XP or Windows 2003 which seem to be the largest numbers hit by this since there is/was no patches for them
- technion 9y agoCareful, most old scanners out there only talk SMB1. I'm all for recommending defence in depth, but please study changes like this before doing them.
- Scoundreller 9y agoYes, a vulnerable system can get infected without user interaction. This malware somehow got seeded, either by (1) direct scanning the internet for vulnerable systems, or (2) traditional "open-this-link / install-this-file" emails/downloads. Maybe that's why we see at least 3 bitcoin addresses: 3 different "seeding" groups. Corp networks shouldn't be accepting outside SMB connections, and home routers will block them too, so that's where user-initiated emails/downloads come in (or someone connecting an outside laptop).
- cpncrunch 9y ago
- tbrock 9y agoI wish they hadn't patched XP so we can collectively put that one to rest.
- tristanho 9y agoDoes anyone have an estimate of how much money WannaCry has made in total? Incentives matter, and if the ransomeware developers are actually getting paid a lot, they will continue exploiting these vulnerabilities. On the other hand, if it turns out people don't actually bother paying despite being locked out of their computers, would the hackers even bother continuing this line of attack?
- jonursenbach 9y agoSome numbers I saw going around yesterday that were looking at the discovered Bitcoin addresses totaled around $18,000.
- tristanho 9y ago$18,000 (or $36,000 as another comment suggests) seems incredibly low for "The largest ransom-ware infection in history"... how can this be worth it for the hackers?
- deleted 9y ago[deleted]
- syshum 9y agoSince this happened over the weekend I am sure there are many business in for a nasty suprise on monday, as well users getting in contact with their "Technical Help" monday So I bet their plan was to infect as many as possible over the weekend, and see money roll in come Monday once the Business Decision makers are in play and IT has had time to say "Yea our backups are fucked so we either pay or lose all data"
- Scoundreller 9y agoIt started at 0700 on Friday, UK time. The infections to businesses in the Americas and EU has been done. Asia might be unscathed since the "killswitch" URL was registered. Until it mutates. Lots of money might pour in on Monday as those infected decide that paying the ransom maximizes business continuity.
- peter_retief 9y agoCan it attack Linux desktops?
- marsrover 9y agoNo
- 45h34jh53k4j 9y agoWannaBet? https://twitter.com/hackerfantastic/status/863359375787925505 https://twitter.com/hackerfantastic/status/86335937578792550...
- javier2 9y agoThat is magnificent.
- zokier 9y agoI don't quite understand how WannaCry became such a big deal. Ransomware is already old thing, SMB worms even older. WannaCry didn't even use a 0day ffs, the patch for this was already published few months ago (and not particularly quietly I might add). There is very little novel about WannaCry as far as I can tell. Additionally W10 apparently was not vulnerable in the first place. All this, and still WannaCry hit the main evening news, which at least around here is somewhat high bar. Not sure what to think about that.
- syshum 9y ago>>the patch for this was already published few months ago 2 months ago, March 17th, and many organizations do not patch as often as they should, Many have even started delaying longer since MS patches of late have been causing more problems for people breaking Office, Breaking WiFi and breaking other critical systems with MS normal response of "opps our bad, well fix it in another month until then get fucked" > Additionally W10 Win10 has about a 12% Market share, about the same as Windows XP still does. Win10 has not been widely adopted outside the consumer market. >All this, and still WannaCry hit the main evening news, Made the news because of the numbers of systems, and number of high profile systems like Hostipols that were infected not because it was a Technical marvel of malware engineering It also made the news because the NSA is indirectly responsible for not disclosing these vulnerabilities when they were discovered until they weaponized them for their own gain. While I do not blame the NSA for this infaction, I believe they should be forced, today, to disclose to all software vendors any other vulnerabilities they want to play Hacker with....
- cpncrunch 9y ago>Many have even started delaying longer since MS patches of late have been causing more problems for people breaking Office It's not just Office that's an issue, it's Windows Update itself. In late 2016 both a Vista and a Windows 7 machine stopped updating. The windows update service on both just hung at 100% cpu time, not updating anything. I didn't actually realise for a few months. Apparently it's a common problem, and the only solution is to manually download and install all the updates. Even after doing that, the problem kept occurring. I've now upgraded everything to windows 10, and so far no problems.
- edem 9y agoEveryone talks about how people get infected but is there a guide around somewhere about how do I protect my computer from such attacks? I install all updates and I have an antivirus program but I don't know what else can I do.
- SolarNet 9y agoDon't open dodgy files (like in emails), or if you must, do it in a VM. Run adblock and no-script on your web browser, only visit trusted sites. If you must, use a VM. Don't download and install software you don't trust. Either it should be a big company in the news regularly, have good reviews from people you trust, or it should be open source. If you must use a VM. Backup your files regularly (and have offline backups, the data is the most important thing), reinstall your OS regularly (this gets rid of old and outdated software you don't remember; because I doubt you install all updates, have you updated Java recently? How about adobe flash or reader? How about the chipset drivers that likely came with your machine?).
- edem 9y agoI'm more interested in the passive infections where I get infected without my prior actions (some comments say it is possible). Java is not a good example because I program (sometimes in java) and it is always up to date. I uninstalled Flash and I have the automatic updates enabled in all software I use day-to-day. Doing regular re-installs is a good idea though. Thanks for the tip.
- dafrankenstein2 9y agodoes this affect the google drive sync folder on windows machines?
- jayflux 9y agoCould someone explain how this spreads and then executes itself on other machines? Does it require user interaction?
- YZF 9y agoIt uses a vulnerability that allows another computer on the same network to execute arbitrary code on your computer. So you work for a UK hospital, your co-worker downloads an attachment and executes it, and that can be enough to get on your machine if it doesn't have up-to-date security patches.
- Andry8 9y agoI don't think it's needed users interface.
- xenadu02 9y agoOne day someone is going to write a filesystem filter driver that does this and build in a much longer delay, which will allow the malware to spread for a lot longer before dumping the keys and demanding ransom. The filter driver would ensure access to the files continues transparently even though the underlying data is encrypted. Things will get much worse.
- Andry8 9y agoyes, 'WannaCry Ransomeware Attack' is the largest ransom in history. However, it's the time to increase windows security and updates. So that anyone can't do this in future https://wuinstall.com/ https://wuinstall.com/