May 15: A computer malware known WannaCry also known as WannaCrypt, WanaCrypt0r 2.0, Wanna Decryptor is a ransomware program targeting the Microsoft Windows operating system has affected worldwide systems since Friday, 12 May 2017. The program is said to have spread to over 150 countries till date and the breach seemed to have slowed down. However, there have been fresh reports of the attack in Asia and Europe on Monday.
India is less likely to have been affected by this cyber crime and Speaking at India TV conclave “Samvaad”, Minister of Electronics and Information Technology Ravi Shankar Prasad, said, “We have been strengthening our cyber security and I can proudly say that the recent cyber-attack had nearly zero per cent impact in India.”
In a nutshell the malicious program is said to have used a flaw in Microsoft’s software, discovered by the National Security Agency and leaked by hackers, to spread rapidly across networks locking away files.
A security expert managed to stop the attack by triggering a “kill switch” on Saturday but it has continued to wreak havoc.
Ransomware, which demands payment after launching a cyber attack, has become a rising trend among hackers looking for a quick payout.
What is ransomware?
Ransomware is a kind of cyber attack that involves hackers taking control of a computer system and blocking access to it until a ransom is paid.
For cyber criminals to gain access to the system they need to download a type of malicious software onto a device within the network. This is often done by getting a victim to click on a link or download it by mistake.
Once the software is on a victim’s computer the hackers can launch an attack that locks all files it can find within a network. This tends to be a gradual process with files being encrypted one after another.
Large companies with sophisticated security systems are able to spot this occurring and can isolate documents to minimise damage. Individuals might not be so lucky and could end up losing access to all of their information.
Cyber criminals often demand payment in return for unlocking the files. This is normally in the form of bitcoin, the online cryptocurrency.
What is Wanna Decryptor?
Wanna Decryptor, also known as WannaCry or wcry, is a specific ransomware program that locks all the data on a computer system and leaves the user with only two files: instructions on what to do next and the Wanna Decryptor program itself.
When the software is opened it tells computer users that their files have been encryted, and gives them a few days to pay up, warning that their files will otherwise be deleted. It demands payment in Bitcoin, gives instructions on how to buy it, and provides a Bitcoin address to send it to.
Most computer security companies have ransomware decryption tools that can bypass the software.
It was used in a major cyber attack that affected organisations across the world including the NHS and Telefonica in Spain.
A young cyber expert managed to stop the spread of the attack by accidentally triggering a “kill switch” when he bought a web domain for less than £10.
When the WannaCry program infects a new computer it contacts the web address. It is programmed to terminate itself if it manages to get through. When the 22-year-old researcher bought the domain the ransomware could connect and was therefore stopped.
How to protect yourself against ransomware attacks?
The best protection against ransomware attacks is to have all files backed up in a completely separate system. This means that if you suffer an attack you won’t lost any information to the hackers.
It is difficult to prevent determined hackers from launching a ransomware attack, but exercising caution can help. Cyber attackers need to download the malicious software onto a computer, phone or other connected device.
The most common ways of installing the virus are through compromised emails and websites.
For example, hackers could send an employee a phishing email that looks like it comes from their boss asking them to open a link. But it actually links to a malicious website that surreptitiously downloads the virus onto their computer.
Downloading a bad program or app, and visiting a website that is displaying malicious adverts can also result in an infected device.
The best way to protect yourself is to be suspicious of unsolicited emails and always type out web addresses yourself rather than clicking on links. Another key defence is antivirus programs that can scan files before they are downloaded, block secret installations and look for malware that may already be on a computer.
Cyber security companies have developed sophisticated defences against the cyber attack, including machines that fight back when they spot hackers in a system.
For more in-depth information on how to protect yourself read: WannaCry cyberattack: Here is how to protect your computer, and more.
What to do if you’re a victim – should you pay the ransom?
Victims are advised to never pay the ransom as it encourages the attackers. Even if victims do pay there is also no guarantee that all files will be returned to them intact.
Instead, the best thing to do is restore all files from a back-up. If this isn’t possible, there are some tools that can decrypt and recover some information.
How much do hackers demand, and why in Bitcoin?
Ransomware often demands between 0.3 and 1 Bitcoins (£400 – 1,375), but can demand a payment denominated in dollars but made via Bitcoin.
The digital currency is popular among cybercriminals because it is decentralised, unregulated and practically impossible to trace.
Although it may seem like a small amount to charge, the ransomware attacks are often widely distributed, so the ransom payments can stack up.
TNT News with inputs from www.telegraph.co.uk, BBC and The Hindu
Image source: BBC