
Hit by WannaCry? Well, looks like the French have a solution. If your computer meets certain criteria that is.
The solution, named wanakiwi, allows you to get back your files without paying a ransom. It only works only if computers had not been rebooted since becoming infected and if victims applied the fix before WannaCry carried out its threat to lock their files permanently.
With reports of victims not getting the decryption key even after paying – this might be a viable solution for those that were hit.
A loose-knit team of security researchers scattered across the globe said they had collaborated to develop a workaround to unlock the encryption key for files hit in the global attack, which several independent security researchers have confirmed.
The group includes Paris based security expert at Quark Labs, Adrien Guinet; Dubai based internationally known hacker, Matthieu Suiche; and Paris based Benjamin Delpy, who helped out in his spare time, outside his day job at the Banque de France. “We knew we must go fast because, as time passes, there is less chance to recover,” Delpy said after a second sleepless night of work this week allowed him to release a workable way to decrypt WannaCry.
Guinet published the theoretical technique for decrypting WannaCry files, which Delpy, also in Paris, figured out how to turn into a practical tool to salvage files. Suiche provided advice and testing to ensure the fix worked across all various versions of Windows.
His blog post links to a Delpy’s “wanakiwi” decryption tool which is based on Guinet’s original concept. His idea involves extracting the keys to WannaCry encryption codes using prime numbers rather than attempting to break the endless string of digits behind the malicious software’s full encryption key.
“This is not a perfect solution,” Suiche said. “But this is so far the only workable solution to help enterprises to recover their files if they have been infected and have no back-ups” which allow users to restore data without paying black-mailers.
WannaCry, which started it’s rounds last Friday and has infected more than 300,000 computers in 150 countries, threatens to lock out victims who have not paid a sum of $300 to $600 within one week of infection.
As of Wednesday, half of all internet addresses corrupted globally by WannaCry were located in China and Russia, with 30 and 20 percent of infections, respectively, according to data supplied by threat intelligence firm Kryptos Logic. By contrast, the United States accounts for 7 percent of WannaCry infections while Britain, France and Germany each represent just 2 percent of worldwide attacks, Kryptos said.
Europol said on Twitter that its European Cybercrime Centre had tested the team’s new tool and said it was “found to recover data in some circumstances”.
“wanakiwi from Benjamin Delpy (@gentilkiwi) works for both Windows XP (x86 confirmed) and Windows 7 (x86 confirmed). This would imply it works for every version of Windows from XP to 7, including Windows 2003 (x86 confirmed), Vista and 2008 and 2008 R2.” Suiche wrote in a blog post.
Delpy told Reuters that so far, banking, energy and some government intelligence agencies from several European countries and India had contacted him regarding the fix.
So far only 309 transactions worth around $94,000 appear to have been paid into WannaCry blackmail accounts by Friday, a week after the attack began.



