HomeinetWannaCry: Why was Windows XP more resistant than Windows 7?

WannaCry: Why was Windows XP more resistant than Windows 7?

When WannaCry hit the world in mid-May, it was often reported that the widespread use of the old Windows XP operating system helped the infection spread very quickly.

The UK's National Health Service was one of the highest-profile victims of the attack – and many of its individual systems are still running Windows XP. Microsoft, if you recall, was quick to release a security update for the long-unsupported operating system.WannaCry

And while Windows XP systems were among those hit by WannaCry, later analysis showed that 98 percent of victims were using Windows 7.

But that doesn’t mean WannaCry didn’t work for targets using Windows XP. According to a new report by researchers at Kryptos, while that operating system was generally the most vulnerable to ransomware, many attacks simply resulted in systems crashing and displaying the “blue screen of death.” After that, a system restore was required.

The researchers tested the WannaCry ransomware on a number of operating systems in a test environment: Windows XP with Service Pack 2, Windows XP with Service Pack 3, Windows 7 x64bit with Service Pack 1, and Windows Server 2008 with Service Pack 1.

While attacks against Windows 7 successfully installed WannaCry, after several attempts, supposedly vulnerable Windows XPs were much more resistant to the ransomware than expected, and the operating system running Service Pack 2 was not infected at all.

However, Windows XP with SP 2 were affected, but instead of being infected with WannaCry and demanding a ransom in exchange for the locked files, the system displayed the blue-screen of death and performed continuous reboots.

The phenomenon was undoubtedly frustrating for organizations who found their systems undergoing constant reboots but at least they were not infected with ransomware.

This does not mean that Windows XP is not vulnerable, as this operating system remains a popular target for cybercriminals who try to exploit the weaknesses of unpatched systems.

WannaCry caused chaos across the globe, and the identity of the attackers remains unknown. Security companies such as Symantec and Kaspersky have linked the attack to the Lazarus group, which is believed to be operating for North Korea.

Meanwhile, linguistic analysis of the ransom notes displayed to victims of the malware suggests that the author, or at least the person who wrote the ransom note, was Chinese.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS