Efforts From US And UK Halt ‘WannaCry’ Ransomware Attack, But Warn It’s Not Over

DETROIT (CBSDetroit) – The WannaCry ransomware computer attack hitting many countries on Friday was halted for a time thanks to efforts on both sides of the pond.

A Michigan based cyber security engineer and a 22-year-old from the United Kingdom on holiday from his job at a ‘private intel threat firm’ both played a role in halting the ransomware WannaCry attacks that hit across the globe on Friday.

Darien Huss works for the cyber security firm Proofpoint and discovered the “kill switch” in the malware used in the extortion scheme.

“I just want to stress to people that they take updating their systems more seriously and that they follow a strict backup policy,” says Huss.

He says that many computers were infected with the malware because patches that were released two months ago were not applied or they were still operating on Legacy systems (such as Windows XP) which were not given patches.

Huss says given the media coverage the attacks receive, he wouldn’t be surprised if there’s another similar attack in the near future.

While on the other side of the pond, a 22-year-old on holiday from his job at a ‘private intel threat firm’ Kryptos Logic — is also credited with cyber heroics. According to BusinessInsider.com, Marcus Hutchins helped to slow down the attack when he “registered a garbled domain name hidden in the malware to track the virus, unintentionally halting it.”

An ’emergency stop’ was found after Hutchins searched for a weakness in the hack software and found a reference to a website address that nobody owned.

He purchased it, knowing this was a regular way to track a computer infection, but had not expected it to actually halt the spread of the ransomware says the Daily Mail.

The ransomware attacks began Friday and hit 150 countries — infecting 200,000 machines and that list is expected to grow.

The malware, once activated on a computer, encrypts the files so they are no longer accessible — the attackers demanding (a ransom of) 300 bitcoins in order to release your files.

Some of the organizations affected include FedEx, the UK’s National Health Service, automaker Renault in France, and China’s National Petroleum Corporation.

While Microsoft issued a repair for those systems, including Windows XP on Friday but the malware had already done considerable damage.

Experts weighing in on both sides of the pond saying that we should be on the defensive; Former FBI Agent in Metro Detroit, Bill Kowalski, says the global ransomware attack could grow much larger when people return to work this week.

Kowalski says home computers likely won’t be targeted because most people wouldn’t pay the $300 ransom, but instead just wipe their computers clean and start over.

Comments

Leave a Reply

Please log in using one of these methods to post your comment:

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

More From CBS Detroit

Best Places To See Indie Rock In DetroitIt's called Detroit Rock City for a reason.
Guide: Best Barbecue In Metro DetroitSometimes, nothing hits the spot like good barbecue.

Watch & Listen LIVE