WannaCry: The global ransomware attack that operated like a worm and caused chaos is back, experts warn.
The spread of the lightning-fast WannaCrypt ransomware (WannaCry) attack was felt globally last week, causing problems for thousands of private and public sector organizations in dozens of countries on Friday, and forcing hospitals in the UK to resort to pen and paper. The ransomware also caused problems in Germany, Russia, the US and Spain.
After the impact of the first ransomware attack was mitigated, the attackers released a second variant of.WannaCry.
So now, because the attack began on Friday afternoon, there is concern that more computers worldwide may have been infected over the weekend – meaning companies will face problems starting Monday morning when employees return to work.
It should be noted here that the main reason for the spread of any ransomware is the human factor. So imagine what will happen with WannaCry 2, and the mistakes that millions of workers who return to their jobs can make.
The UK's National Cyber Security Centre, the agency tasked with securing the UK's critical infrastructure from cyberattacks, called what is happening a "globally coordinated ransomware attack" and that there have been no other attacks of this kind.
"It is important to understand that the way these attacks work is that they cause infections of computers and networks and are undetected, so they can spread within networks," the agency warned.
"This means that as a new working week begins, it is likely that, in the UK and elsewhere, more cases of ransomware infection will be found, potentially on a significant scale.".
The NCSC said there had been attempts to attack organisations beyond the NHS and that it was "absolutely imperative" that any organisation that believes it may be affected follow and implement security regulations with proper guidance.
Companies should ensure they have all software updates and are using appropriate antivirus software services. The agency also said that companies should keep important data safe (and of course, they mean backups) because “you shouldn’t pay ransom if you have your data somewhere else.”.
Home users and small businesses should use Windows Update, ensure their antivirus software is up to date, and back up their data.
Microsoft has stated that the exploit code used by WannaCrypt (WannaCry) is designed to only work against Windows 7 and Windows Server 2008 or even older systems like Windows XP.
This exploit, codenamed “EternalBlue”, was made available on the Internet by so-called Shadow brokers who stole the tools from the NSA.
A fix for the vulnerability was released by Microsoft in March, but many organizations and individuals failed to update their systems.
If you want to protect your system, update immediately.
You can download the updates for older systems (Windows XP, Windows 8, Windows Server 2003) from here. Anyone using a different (newer) system that is still supported by Microsoft, simply update your computer via Windows Update.
