HomeSecurityWannaRen ransomware: Creators released decryption key

WannaRen ransomware: Creators released decryption key

WannaRen ransomware

In April, Chinese users were attacked by a ransomware known as WannaRen. The ransomware targeted tens of thousands of home users and businesses in China and Taiwan within a week.

WannaRen's success may be due to its code having some connections to WannaCry, the ransomware that caused chaos worldwide in May 2017.

The creators of WannaRen ransomware (like WannaCry) integrated the EternalBlue exploit into their infection chain, allowing WannaRen to spread unrestricted within corporate networks before encrypting and displaying the ransom message.

Also like WannaCry, WannaRen spread like wildfire, far beyond what the ransomware creators had intended, creating more destruction than they had anticipated. So, the creators of the malware released the master decryption key so that all victims could recover their files.

Hidden Shadow group

Now, we can say with certainty that the WannaCry ransomware was created by North Korean government hackers, who wanted to infect a few victims, collect ransom , and use the funds for the Pyongyang regime. The authors of WannaCry did not want to cause this chaos, as it would have focused all the attention on them.

Something similar can also be said for the authors of the WannaRen ransomware, a group that Chinese antivirus company Qihoo 360 has dubbed Hidden Shadow .

The group has been active for years distributing a variety of malware (keyloggers, trojans, cryptocurrency-mining malware) usually through pirated software download websites.

WannaRen ransomware began to be used on April 4 of this year.

According to multiple sources, WannaRen's initial distribution point was a modified installer for the Notepad++ text editor.

Thousands of Chinese usersbegan asking for help decrypting their files on Chinese forums, social networks, and online chats from the first day WannaRen ransomware infections began to be detected.

WannaRen ransomware: Creators released decryption key

WannaRen ransomware spreads across networks

The victims were both home users and IT staff managing corporate networks (in which WannaRen was particularly aggressive).

Mode of infection

On computers where users installed this infected version of Notepad++, the installer installed a backdoor trojan, which deployed the EternalBlue exploit to spread across the network (via SMBv1). It also used a PowerShell script to download and install WannaRen ransomware or Monero-mining malware.

After encrypting systems, a message depicting Kim Jong-un and ask users to pay 0.05 bitcoin (~$550) to decrypt their files.

The encrypted files had the extension “.wannaren” added to them.

WannaRen ransomware creators provide decryption key

From the distribution method and the small ransom amount, it was clear that the Hidden Shadow group did not intend to spread the ransomware so quickly and target so many victims.

A few days after the WannaRen ransomware began to be distributed, the Hidden Shadow group contacted a local Chinese cybersecurity company called Huorong Security (火绉 or Tinder Security) and gave it the private encryption key of the ransomware, asking the company to create and share a free decryption program for victims.

On the same day, April 9, Huorong released the decryption tool for WannaRen ransomware. Later, a tool was also released by QiAnXin Technology's RedDrip.

However, while the vast majority of WannaRen victims were located in China, the ransomware had spread via internal networks from Chinese subsidiaries to some foreign companies.

Many of these companies may not be aware that a free decryption tool exists, or may not trust the tools created by the two Chinese security vendors. For this reason, Romanian company Bitdefender has also released its own decryption utility.

WannaRen infections appear to have disappeared, but victims who may have had files since April can now decrypt them for free.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS