{"id":192958,"date":"2017-05-14T17:30:46","date_gmt":"2017-05-14T21:30:46","guid":{"rendered":"http:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/an-nsa-derived-ransomware-worm-is-shutting-down-computers-ars-technica\/"},"modified":"2017-05-14T17:30:46","modified_gmt":"2017-05-14T21:30:46","slug":"an-nsa-derived-ransomware-worm-is-shutting-down-computers-ars-technica","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/nsa-2\/an-nsa-derived-ransomware-worm-is-shutting-down-computers-ars-technica\/","title":{"rendered":"An NSA-derived ransomware worm is shutting down computers &#8230; &#8211; Ars Technica"},"content":{"rendered":"<p><p>    A highly virulent new strain of self-replicating ransomware    shut down computers all over the world, in part by    appropriating a National Security Agency exploit that was    publicly released last month by the mysterious group calling    itself Shadow Brokers.  <\/p>\n<p>    The malware, known as Wanna, Wannacry, or Wcry, has     infected at least 75,000 computers, according to antivirus    provider Avast. AV provider Kaspersky Lab said     organizations in at least 74 countries have been affected,    with Russia being disproportionately affected, followed by    Ukraine, India, and Taiwan. Infections are also spreading through    the United States. The malware is notable for its    multi-lingual ransom demands, which     support more than two-dozen languages.  <\/p>\n<p>    Wcry is reportedly causing disruptions at banks, hospitals,    telecommunications services, train stations, and other    mission-critical organizations in multiple countries, including    the UK, Spain, Germany, and Turkey. FedEx, the UK government's    National Health Service, and Spanish telecom Telefonica have    all been hit. The     Spanish CERT has called it a \"massive ransomware attack\"    that is encrypting all the files of entire networks and    spreading laterally through organizations.  <\/p>\n<p>    The virally spreading worm was ultimately stopped when a    researcher who uses the Twitter handle MalwareTech and works    for security firm Kryptos    Logic took control of a domain name that was hard-coded    into the self-replicating exploit. The domain registration,    which occurred around 6 AM California time, was a major stroke    of good luck, because it was possible only because the    attackers had failed to obtain the address first.  <\/p>\n<p>    The address appeared to serve as a sort of kill switch the    attackers could use to terminate the campaign. MalwareTech's    registration had the effect of ending the attacks that had    started earlier Friday morning in other parts of the world. As    a result, the number of infection detections plateaued    dramatically in the hours following the registration. It had no    effect on WCry infections that were initiated through earlier    campaigns.  <\/p>\n<p>    So-called worms, which spread quickly amid a chain of attacks,    are among the most virulent forms of malware. Researchers are    still investigating how Wcry takes hold. The awesome power of    worms came to the world's attention in 2001 when Code Red    managed to infect more    than 359,000 Windows computers around the world in 14    hours.  <\/p>\n<p>    \"The initial infection vector is something we are still trying    to find out,\" Adam Kujawa, a researcher at antivirus provider    Malwarebytes, told Ars. \"Considering that this attack seems    targeted, it might have been either through a vulnerability in    the network defenses or a very well-crafted spear phishing    attack. Regardless, it is spreading through infected networks    using the EternalBlue vulnerability, infecting additional    unpatched systems.\"  <\/p>\n<p>    Other organizations in Spain known to be disrupted include    telecom Vodafone Espana, the KPMG consultancy, banks BBVA and    Santander, and power company Iberdrola. The Blackpool Victoria    Hospital in the UK reportedly pleaded for patients to     seek treatment only for life-threatening emergencies after    Wcry crippled its network. Portugal Telecom has also     reported being infected. Meanwhile, Barts Health Hospital    in London is     redirecting ambulances to other facilities. At least two    train stations showed signs of infections according to display    pictures published here    and     here.  <\/p>\n<p>    According to an     article posted by Madrid-based El Mundo, 85    percent of computers at Telefonica, Spain's dominant telecom,    are affected by the worm, although that figure has not been    confirmed. Officials at Telefonicaand Spanish energy    companies Iberdrolaand Gas Natural Fenosa have all    instructed employees to shut down computers. While the paper    confirmed an attack on Telefonica, it said it was not yet clear    if the other two companies had been infected or ifthey    ordered the shutdown as a preventative measure.  <\/p>\n<p>    Wcry is demanding a ransom of $300 to $600 in Bitcoin to be    paid by May 15, or, in the event that deadline is missed, a    higher fee by May 19. The messages left on the screen say files    will remain encrypted. It's not yet clear if there are flaws in    the encryption scheme that might allow the victims to restore    the files without paying the ransom.  <\/p>\n<p>    People who have yet to install the Microsoft fixMS17-010should    do so right away. People should also be extremely suspicious of    all e-mails they receive, particularly those that ask the    recipient to open attached documents or click on Web links.  <\/p>\n<p>    This post was updated repeatedly over the first six hours    it was first published to report newly available    information.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more from the original source:<br \/>\n<a target=\"_blank\" href=\"https:\/\/arstechnica.com\/security\/2017\/05\/an-nsa-derived-ransomware-worm-is-shutting-down-computers-worldwide\/\" title=\"An NSA-derived ransomware worm is shutting down computers ... - Ars Technica\">An NSA-derived ransomware worm is shutting down computers ... - Ars Technica<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> A highly virulent new strain of self-replicating ransomware shut down computers all over the world, in part by appropriating a National Security Agency exploit that was publicly released last month by the mysterious group calling itself Shadow Brokers.  <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/nsa-2\/an-nsa-derived-ransomware-worm-is-shutting-down-computers-ars-technica\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[94881],"tags":[],"class_list":["post-192958","post","type-post","status-publish","format-standard","hentry","category-nsa-2"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/192958"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=192958"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/192958\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=192958"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=192958"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=192958"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}