The malware used to encrypt data on infected computers across the world on May 12, 2017 is known as WannaCry.
HOW DOES IT WORK?
WannaCry is a form of "ransomware" that locks up the files on your computer and encrypts them in a way that you cannot access them anymore.
HOW DOES IT SPREAD?
Ransomware is a program that gets into your computer, either by clicking on the wrong thing or downloading the wrong thing, and then it holds something you need to ransom.
In the case of WannaCry, the program encrypts your files and demands payment in bitcoin to regain access.
Security experts warn there is no guarantee that access will be granted after payment. Some ransomware that encrypts files ups the stakes after a few days, demanding more money and threatening to delete files altogether.
There are different variants of what happens: Other forms of ransomware execute programs that can lock your computer entirely, only showing a message to make payment to log in again. There are some that create pop-ups that are difficult or impossible to close, rendering the machine useless.
WHAT IS SO SPECIAL ABOUT WANNACRY?
WannaCry is not just a ransomware program, it's also a worm.
This means that it gets into your computer and looks for other computers to try to spread itself as far and wide as possible.
Ransomware has a habit of mutating and so it changes over time to find different ways to access computers or to get around patches (operating system updates that often include security updates). Many security firms are already aware of WannaCry in past forms and most are looking at this one right now to see how it might be stopped.
Several cyber security firms said WannaCry exploits a vulnerability in Microsoft and that Microsoft patched this in March. People don't always install updates and patches on their computers and so this means vulnerabilities can remain open a lot longer and make things easier for hackers to get in.
It exploited a vulnerability in the Windows operating system believed to have been developed by the National Security Agency, which became public last month. It was among a large number of hacking tools and other files that a group known as the Shadow Brokers released on the internet. Shadow Brokers said that they obtained it from a secret NSA server.
The identity of Shadow Brokers is unknown though many security experts believe the group that surfaced in 2016 is linked to the Russian government.
*Reuters
http://ift.tt/2r4HZGe
3Novices Europe
No comments:
Post a Comment