{"id":36643,"date":"2019-10-02T21:16:29","date_gmt":"2019-10-02T13:16:29","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=36643"},"modified":"2019-10-03T15:26:49","modified_gmt":"2019-10-03T07:26:49","slug":"sophos-tracks-evolution-of-wannacry","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/10\/02\/sophos-tracks-evolution-of-wannacry\/","title":{"rendered":"Sophos tracks evolution of WannaCry"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos published WannaCry Aftershock, a report on what happened to the infamous WannaCry malware, following the worldwide attack that began on May 12, 2017. <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The research by SophosLabs shows that the WannaCry threat remains rampant, with millions of infection attempts stopped every month, and that while the original malware has not been updated, many thousands of short-lived variants are in the wild.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The\ncontinued existence of the WannaCry threat is largely due to the ability of these\nnew variants to bypass the \u2018kill switch.\u2019&nbsp;\nHowever, when Sophos researchers analyzed and executed a number of\nvariant samples, they found that their ability to encrypt data was neutralized\nas a result of code corruption.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because\nof the way in which WannaCry infects new victims \u2013 checking to see if a computer\nis already infected and, if so moving on to another target \u2013 infection by an\ninert version of the malware effectively protects the device from being infected\nwith the active strain. In short, new variants of the malware act as an\naccidental vaccine, offering still unpatched and vulnerable computers a sort of\nimmunity from subsequent attack by the same malware. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However,\nthe very fact that these computers could be infected in the first place\nsuggests the patch against the main exploit used in the WannaCry attacks has\nnot been installed \u2013 a patch that was released more than two years ago.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The original\nWannaCry malware was detected just 40 times and since then SophosLabs researchers\nhave identified 12,480 variants of the original code. Closer inspection of more\nthan 2,700 samples (accounting for 98 percent of the detections) revealed they\nhad all evolved to bypass the \u2018kill switch\u2019 \u2013 a specific URL that, if the\nmalware connects to it, automatically ends the infection process \u2013 and all had\na corrupted ransomware component and were unable to encrypt data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In August\n2019, Sophos telemetry detected 4.3 million instances of WannaCry. The number\nof different variants observed was 6,963. Of these, 5,555 or 80 percent \u2013 were\nnew files.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos\nresearchers have also traced the first appearance of today\u2019s most widespread\ncorrupted variant back to just two days after the original attack:\nMay 14, 2017, when it was uploaded to VirusTotal, but had not yet been seen in\nthe wild.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe WannaCry outbreak of 2017 changed the threat\nlandscape forever. Our research highlights how many unpatched computers are\nstill out there, and if you haven\u2019t installed updates that were released more\nthan two years ago \u2013 how many other patches have you missed? In this case, some\nvictims have been lucky because variants of the malware immunized them against newer\nversions. But no organization should rely on this. Instead, standard practice\nshould be a policy of installing patches whenever they are issued, and a robust\nsecurity solution in place that covers all endpoints, networks and systems,\u201d\nsaid Peter Mackenzie, security specialist at Sophos and lead author of the\nresearch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How to protect against WannaCry malware and ransomware in general:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Check that you have a full inventory of all devices connected\nto your network and that they are all up to date in terms of their security\nsoftware<\/li><li>Always install the latest patches as soon as they are\nreleased on all the devices on your network<\/li><li>Verify if your\ncomputers are patched against the EternalBlue exploit used in WannaCry by following\nthese instructions: <a href=\"https:\/\/sophos.com\/kb\/132107\">How to Verify if a\nMachine is Vulnerable to EternalBlue &#8211; MS17-010<\/a><\/li><li>Keep regular backups of your most\nimportant and current data on an offline storage device as the best way to\navoid having to pay a ransom when affected by ransomware&nbsp;<\/li><li>There is no silver bullet to security, and a\nlayered security model is the best practice all businesses need to implement<\/li><li>For example, Sophos <a href=\"https:\/\/www.sophos.com\/en-us\/products\/intercept-x.aspx\">Intercept X <\/a>&nbsp;employs a comprehensive defense-in-depth approach\nto endpoint protection, combining multiple leading next-gen techniques to\ndeliver malware detection, exploit protection and built-in endpoint detection\nand response (EDR) <\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The research by SophosLabs shows that the WannaCry threat remains rampant, with millions of infection attempts stopped every month, and that while the original malware has not been updated, many thousands of short-lived variants are in the wild.<\/p>\n","protected":false},"author":6,"featured_media":33149,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[103,54,206,5288],"class_list":["post-36643","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-malware","tag-security","tag-sophos","tag-wannacry"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36643","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=36643"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36643\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/33149"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=36643"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=36643"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=36643"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}