WannaCry Ransomware Crisis – Two Years On
It is two years since the WannaCry ransomware malware spread globally. Figures suggest it infected about 230,000 PC’s in nearly 150 countries. It also forced many organisations to shut down their PC’s and Internet access to prevent infections. Official figures published by the NHS in the UK show that a third of all the hospital trusts in England were adversely impacted in the week of the attack. This meant that many vital pieces of medical equipment that had PC based controllers, like MRI scanners, couldn’t be used.
People are very good at rationalising events, and also assuming that the steps taken to address an issue have solved it and that the problem has gone away. This is often mistaken thinking when it comes to cybersecurity. WannaCry and other malware variants are still a threat if defences are not maintained.
Why did WannaCry spread so quickly?
WannaCry was able to spread quickly during May 2017 due to it exploiting a vulnerability in Windows systems. It scanned for a known issue in the Microsoft SMB (Server Message Block) protocol used to allow Windows servers and PCs to share files, printers and other resources over networks. By using some well known and available hacking tools, WannaCry was able to install itself on vulnerable systems and then copy itself to other Windows machines via the SMB vulnerability.
Microsoft had issued a patch for the SMB vulnerability about two months before the May 2017 attack. It would be straightforward to say that if everyone had installed the security patch, then they would have been protected. However, we all know that the real world isn’t as clean and as simple as this.
Once a machine was infected the WannaCry malware encrypted the data on attached drives and demanded a ransom paid in a cryptocurrency to decrypt the data. The data could not be recovered in any other way.
Future threats
While WannaCry quickly spread, any systems that had the Microsoft security patch issued early in 2017 were protected from getting infected. Also, it was discovered that WannaCry made a call to a dummy URL during its spread from machine to machine and that this URL did not exist on the Internet and the domain had not been registered. A security analyst registered the domain and pointed it at a server 'kill switch', and this had the effect of stopping the spread of the malware.
This domain-based flaw in the WannaCry programming made it relatively easy to stop it spreading. However, it can be safely assumed that other future malware attacks won’t make the same mistake. The next one that appears, and one will that exploits some undiscovered flaw in an operating system, might not be as easy to stop.
Phishing with fear for bait
The publicity and panic that surrounded the 2017 WannaCry malware are still being exploited to underpin social and phishing email-based attacks. Email scams started to appear in late 2018 that said to users that their computer had been hacked, some personally sensitive information discovered, and that if the user didn’t send some cryptocurrency to an address, then their sensitive data would be released publicly and WannaCry installed on their PC. These emails are ongoing now in 2019 and are an evolution of the classic phishing email that attempts to use the general knowledge of WannaCry to coerce people into paying the attackers.
How to respond to the threats
The best way to guard against all malware threats is to use various tactics:
- Patch all systems - it’s vital to apply patches to operating systems and applications as soon as possible. Have a good TEST system that can be used to quickly test updates so they can be approved for release into LIVE as promptly as possible.
- Retire any systems that are out of support as soon as you can. Don’t run old operating systems with the “it isn’t broke so don't fix it" maxim. Doing so will lead to a future vulnerability going unpatched and will open a way for attackers to compromise your network.
- Do frequent backups - WannaCry encrypted data so it couldn’t be accessed. If you have regular backups, then the risk from this type of attack is reduced. You can wipe any infected machines and restore the data from a backup. Make sure that the backups are not vulnerable to the attack.
- Install anti-virus and anti-spam software - update definitions daily.
- Get expert advice from security resellers and vendors - this is a complicated area and requires full-time focus to stay current with emerging threats. Security companies are focused on this, and you should avail of their expertise.
Conclusion
WannaCry was a wake-up call that showed how damaging a breach of cyber defences could be. Many lessons were learnt from the May 2017 attack. Applying them today two years on is vital. Renaissance and our trusted partners are ideally placed to help ensure that threats similar to WannaCry won’t have a devastating impact on your business.

