HomeinetWannaCry and ExPetr ransomware comparative analysis

WannaCry and ExPetr ransomware comparative analysis

WannaCry and ExPetr: The researchers of Kaspersky Lab performed a comparative analysis of the two latest attacks with ransomware programs, which were carried out with different modes of operation and against different targets. WannaCry and ExPetr

However, both attacks have some similarities, presenting signs of an emerging trend of concealed destructive targeted activity.

  •  In contrast to previous destructive attacks using Wiper technologies, such as BlackEnergy and Destover in 2014, and Shamoon and StonedDrill in 2016-2017, which were carried out in a very sophisticated and destructive manner, the motives of WannaCry and ExPetr – whether for destructive activity or for some sabotage – remain unclear.
  •  There was the same delay of about two months for the delivery of worm-enabled variants: according to the initial information regarding the targets, the development of WannaCry started in March, while that of ExPetr took place in April. But the ransomware/wiper themselves spread much later, in May and June respectively.
  •  The development of WannaCry was slow and practical, with scattered global targets, inconsistent profiles and no attention to collecting Bitcoins: the intruder sent a set of messages that encouraged users to pay the BTC to their wallet.
  •  The development of ExPetr was rapid, advanced and technically flexible, focusing on the software of organizations linked to Ukraine. However, the attackers of ExPetr apparently did not return either with widely disseminated messages or challenges for their targets, nor did they extend the incident by demanding transactions with Bitcoins for disk decryption.

According to Kaspersky Lab researchers, the differences in the development of each ransomware indicate that the two attacks were not carried out by the same attacker.

But there are obvious similarities regarding the tactics of both WannaCry and ExPetr, a fact that indicates the start of a new targeted APT attack activity behind ransomware.

For more information, you can visit thecompany's dedicated website Securelist.com.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS