What is WannaCry and how does ransomware work?


A global cyber attack has been underway since Friday, affecting more than 200,000 organisations in 150 countries. In the UK, the major assault hit 47 NHS trusts, leading to operations being cancelled and patients turned away from A&E.

The "WannaCry" ransomware appears to have used a flaw in Microsoft's software, discovered by the National Security Agency and leaked by hackers, to spread rapidly across networks locking away files.

A security expert managed to stop the attack by triggering a "kill switch" on Saturday but it has continued to wreak havoc.

What is ransomware? 

Ransomware is a kind of cyber attack that involves hackers taking control of a computer system and blocking access to it until a ransom is paid.

For cyber criminals to gain access to the system they need to download a type of malicious software onto a device within the network. This is often done by getting a victim to click on a link or download it by mistake.

Once the software is on a victim's computer the hackers can launch an attack that locks all files it can find within a network. This tends to be a gradual process with files being encrypted one after another.

Large companies with sophisticated security systems are able to spot this occurring and can isolate documents to minimise damage. Individuals might not be so lucky and could end up losing access to all of their information.

Cyber criminals often demand payment in return for unlocking the files. This is normally in the form of bitcoin, the online cryptocurrency

What is Wanna Decryptor?


Wanna Decryptor, also known as WannaCry or wcry, is a specific ransomware program that locks all the data on a computer system and leaves the user with only two files: instructions on what to do next and the Wanna Decryptor program itself.

When the software is opened it tells computer users that their files have been encryted, and gives them a few days to pay up, warning that their files will otherwise be deleted. It demands payment in Bitcoin, gives instructions on how to buy it, and provides a Bitcoin address to send it to.

Most computer security companies have ransomware decryption tools that can bypass the software.It was used in a major cyber attack that affected organisations across the world including the NHS and Telefonica in Spain.

When the WannaCry program infects a new computer it contacts the web address. It is programmed to terminate itself if it manages to get through. When the 22-year-old researcher bought the domain the ransomware could connect and was therefore stopped.

How to protect yourself against ransomware attacks


The best protection against ransomware attacks is to have all files backed up in a completely separate system. This means that if you suffer an attack you won't lost any information to the hackers. It is difficult to prevent determined hackers from launching a ransomware attack, but exercising caution can help. Cyber attackers need to download the malicious software onto a computer, phone or other connected device.

The most common ways of installing the virus are through compromised emails and websites. For example, hackers could send an employee a phishing email that looks like it comes from their boss asking them to open a link. But it actually links to a malicious website that surreptitiously downloads the virus onto their computer.


Downloading a bad program or app, and visiting a website that is displaying malicious adverts can also result in an infected device. The best way to protect yourself is to be suspicious of unsolicited emails and always type out web addresses yourself rather than clicking on links. Another key defence is antivirus programs that can scan files before they are downloaded, block secret installations and look for malware that may already be on a computer. Cyber security companies have developed sophisticated defences against the cyber attack, including machines that fight back when they spot hackers in a system.


Impact India


The government today said there was no serious impact in the country due to a global ransomware cyber attack, except for a few isolated incidents in Kerala and Andhra Pradesh. IT Minister Ravi Shankar Prasad said the systems run by the National Informatics Centre were secured and running smoothly. “There is no major impact in India unlike other countries. We are keeping a close watch. As per the information received so far, there have been isolated incidents in limited areas in Kerala and Andhra Pradesh,” Prasad told.


What to do if you're a victim - should you pay the ransom?


Victims are advised to never pay the ransom as it encourages the attackers. Even if victims do pay there is also no guarantee that all files will be returned to them in tact. Instead, the best thing to do is restore all files from a back up. If this isn't possible, there are some tools that can decrypt and recover some information.

How much do hackers demand, and why in Bitcoin?


Ransomware often demands between 0.3 and 1 Bitcoins (RS 33318.49 - 111015.68 ), but can demand a payment denominated in dollars but made via Bitcoin.

The digital currency is popular among cybercriminals because it is decentralised, unregulated and practically impossible to trace. Although it may seem like a small amount to charge, the ransomware attacks are often widely distributed, so the ransom payments can stack up.



Previous
Next Post »

Go through This Also

Related Posts Plugin for WordPress, Blogger...