Yesterday, in a series of posts, we announced that we know about the largest ransomware attack that began last Friday. Using one of the NSA exploits recently leaked by the Shadow Brokers group, the attackers were able to infect computers worldwide with WannaCry (a Windows exploit that was adopted from the NSA's EternalBlue tool).
Microsoft has already released several updates for this vulnerability, but many users and organizations did not bother to update their systems.
Faced with the devastating effects of the worm that continues to spread, the company went the extra mile and released updated versions even for systems that it no longer supports: Windows XP, Windows (server) 2003 and Windows 8.
Yesterday we also reported that the malware code contained a kill switch in the form of a kill switch domain.
What does this mean in simple terms? When the malware detects that a specific domain exists, it stops infections. This domain was created (registered) earlier today by a researcher who noticed the dot-com in the reverse-engineered binary. When the registration was detected by the malware, it immediately stopped the ransomware distribution, and its global spread.
But let's clarify what the kill switch does:
The kill switch cannot help devices that have already been infected and locked with WannaCry.
By registering the domain and then directing traffic to a server environment intended to record and hold malicious traffic (sinkhole), MalwareTech essentially bought time for systems that were not already infected.
“Fortunately, MalwareTech had the infrastructure to create a ‘sinkhole,’” says Darien Huss, senior security research engineer at security firm Proofpoint.
"If someone had bought doamin and not prepared then we would be seeing a lot of infections right now."
If the installation did not have enough space and the server did not have enough bandwidth, the malware would not be trapped and would not self-destruct.
It should be added that MalwareTech's discovery is not a permanent solution. All it would take to start again is a new WannaCry strain whose code would block the kill switch or use a more sophisticated URL generator instead of a static IP address.
However, the discovery of MalwareTech has helped slow down the process.
Hopefully, with so many security analysts observing and reverse-engineering the behavior of the WannaCry malware, someone else will eventually find a more permanent solution to disable it. Every minute counts….
