WannaCry Malware

Organisations worldwide have been left cleaning up after being caught out by WannaCry ransomware, now authorities are turning their attention to discovering who the assailants are.

Mikko Hypponen, head of research at FSecure states that research is yet to reveal any suspects. ‘We’re tracking over 100 different ransom Trojan gangs, but we have no information on where WannaCry is coming from.’

Not the work of Russia
The 1st version of the Malware turned up on the 10th of February, and was used in a short ransomware campaign that began on the 25th of March. This was carried out through spam emails, and booby trapped websites- although very few were caught out by this first version.

Version 2 however was significantly more aggressive and consisted of a worm, capable of spreading itself. Consequently much more damage was caused by this version.

What people might be surprised by is that there is a considerable amount of evidence to show that this isn’t the work of Russia. Firstly, Malware from Russia actively tries to avoid affecting people in their own nation, contrary to how this malware is behaving. More so, the timestamp displayed in the code was four hours ahead of GMT time, indicating that the assailants come from an Asian country such as Japan or Indonesia.

It’s also likely that this Malware is the work of a new group, because is was strangely successful, having hit more than 200,000 – many times more than are usually caught out by ransomware aimed at large organisations.

The assailants though, made a mistake by not registering the domain name within the core code. Something Security researcher Marcus Hutchins took advantage of, to limit the malwares spread.

Paying the ransom
So, considering the plethora of issues this malware is proven to cause, the question on many people’s mind is whether or not to pay the ransom, and the experts say no. Even though £230 may not seem a lot in regards to important documents being held against your will.
Bare in mind that this whole campaign is being run by criminals, so you cannot guarantee an honest transaction. More so, due to the nature of WannaCry, it’s also unlikely you’ll even regain access to your files.

Cyber security researcher Matthew Hickey outlines that ‘A manual human operator must activate decryption,’

Security company Proofpoint suggests that a reliable way of decrypting files may not actually be built into the messy coding of WannaCrypt. Researchers have contacted those responsible for the malware but are yet to receive a reply.

One piece of closure amongst this whole crisis is that home users are unlikely to be affected. Wanna Cry has so far spread around business networks, throughout exposed parts of Windows. These parts are either unlikely to installed at home in the first place, or, there will not be any other vulnerable computers on their home network.

But, for those who’ve been unlucky enough to be affected by this malware, whether that be at work or in an establishment. Unfortunately it’s also safe to assume that files have been lost forever where they have not been backed up on a drive disconnected from your computer have been completely lost.

This whole crisis shows why it is imperative to regularly back up files from your computer to a separate drive or machine.

Though, there is hope, and you’ll be glad to know that it is possible to remove WannaCry from your computer once it is there- The downside though, is that it’s a rather difficult process, involving the download of programs to clear your computer of the infection- explains technical support website ‘Bleeping Computer’.

Although, the author makes sure to add that this will not decrypt files encrypted by the ransomware- Again, showing that there is no substitute for a reliable back-up.