Think You’re Safe From The “NHS Attack” in UK? Think Again

A ransomware attack has been the topic of the day – with many posting about the NHS (National Health Service) in the UK being targeted.

Well, new information suggests this is a globalwide attack. According to Tech Crunch, the attack seems to be based on leaked NSA hacking tools, and unpatched Windows systems worldwide are getting hit, with thousands affected in Russia alone.

Known as WannaCry, Avast has seen over 75,000 cases of the ransomware in the wild. The program locks files and demands a ransom of $300 in bitcoin for decryption key for the data. Kaspersky noted a number around 45,000 as of yesterday afternoon, with vast majority hits in Russia, Ukraine, India and Taiwan. However, the BBC reported infections in 99 countries, including the UK, US, China, Russia, Spain, Italy and Taiwan.

BBC wrote “A number of Spanish firms – including telecoms giant Telefonica, power firm Iberdrola and utility provider Gas Natural – suffered from the outbreak. There were reports that staff at the firms were told to turn off their computers.”

“Portugal Telecom, delivery company FedEx, a Swedish local authority and Megafon, the second largest mobile phone network in Russia, also said they had been affected.”

The ransomware’s code makes it pretty clear that it’s taking advantage of an exploit called EternalBlue, published in April by the Shadow Brokers but Microsoft has patched that falw back in March. Although, as with many systems,

A bitcoin wallet reportedly used by the ransomers shows numerous incoming transactions of between 0.15 and 0.3 BTC, worth around $250-$500, so it seems some victims have started to pay up, rather than attempt to extricate their data safely or do a full wipe and rollback. Although there has been no reports of confirmation on whether the decryption key was given or withheld by the attackers.

While most malware and ransomware tricks humans into clicking links or attachments, WannaCry can move on its own. Once WannaCry is inside an organisation it will hunt down vulnerable machines and infect them too.

Some security researchers have pointed out that the infections seem to be deployed via a worm – a program that spreads by itself between computers. Many organisations are being infected precisely because it’s on the network.

Look, we know it’s a pain but please, keep your computers updated.

ArsTechnica has a very detailed piece about the details of the worm itself, if you’re interested.

Share this post:

Comment what you think!