WannaCry: The Stolen NSA Weapon, the Ignored Patch, and a Kill Switch

On Friday, May 12, 2017, screens around the world turned red with a padlock and a demand: pay 300 dollars in Bitcoin within three days or lose your files. WannaCry was a crypto worm, ransomware that needed no one to click a link. It spread on its own using EternalBlue, an exploit for a flaw in Microsoft’s Server Message Block protocol that the National Security Agency had found and kept secret, and DoublePulsar, a backdoor that held the door open. A group called the Shadow Brokers leaked both tools in April 2017.

This episode walks through how the outbreak hit an estimated 200,000 to 300,000 computers in 150 countries, even though Microsoft had released the fix, MS17-010, on March 14. It covers the damage to Britain’s National Health Service, the factories and railways that stalled, the strangely broken ransom system that collected only about 130,000 dollars, and the 22-year-old researcher who stopped the spread by registering a web address. It closes with the forensic trail that led investigators to North Korea.

  • Kaspersky research showed less than 0.1 percent of affected machines ran Windows XP; 98 percent ran fully supported Windows 7 that had not been patched.
  • Up to 70,000 NHS devices were hit, including MRI scanners and blood storage refrigerator monitors, and hospitals diverted ambulances.
  • Only about 327 ransom payments were recorded, and there were no confirmed reports of anyone getting data back after paying.
  • Marcus Hutchins found the worm checked a gibberish unregistered domain as a sandbox test, registered it for a few dollars, and created a sinkhole that halted new infections.
  • Clues such as a UTC plus nine time zone, Hangul fonts, and code shared with the Lazarus Group led the United States and Britain to blame North Korea in December 2017.

Leave a Reply

Discover more from pplpod

Subscribe now to keep reading and get access to the full archive.

Continue reading