News

Ransomware Outbreak Targeting Windows SMB Flaw

A large ransomware outbreak affecting some Windows systems is in effect today, with a report from the SANS Institute's Internet Storm Center estimating 45,000 attacks in 74 countries.

The ransomware is identified as "WannaCry" and is targeting a Windows Server Message Block (SMB) flaw that was addressed with Microsoft's March MS17-010 "critical" security bulletin release. The Internet Storm Center also identified this flaw as "ETERNALBLUE." Apparently, that's a reference to one of the code names used for a group of hacking tools purportedly collected by the U.S. National Security and then subsequently leaked by a group calling itself "The Shadow Brokers."

The ransomware has hit hospitals in the United Kingdom and Telefonica in Spain, according to the Internet Storm Center. It's affecting National Health Services computers in England and Scotland, according a report by The Guardian.

The ransomware, which encrypts a computer's files, is said to present a demand for $300 in Bitcoins to unlock them, along with a threat to double the price.

A Motherboard story suggested that the UK's National Health Service may have been hit because it continues to run the unsupported Windows XP operating system across thousands of machines. However, MS17-010 is a patch for newer operating systems as well, such as Windows 7 and Windows 8.1, plus Windows Server 2008, Windows Server 2012 and even Windows Server 2016.

The WannaCry ransomware exploits a remote code execution flaw in SMB version 2, according to a Kaspersky Lab post. While Microsoft issued MS17-010 to patch the flaw, "it appears that many organizations have not yet installed the patch," Kaspersky Lab indicated. Most of the attacks are happening in Russia, according to the organization. The security firm recommended installing MS17-010, "which closes the affected SMB Server vulnerability used in this attack," among other measures.

When asked about the flaw, Microsoft responded today by e-mail, saying that its March update addressed the issue and consumers running Windows Defender and Windows Update would be protected, per a spokesperson:

Today our engineers added detection and protection against new malicious software known as Ransom:Win32.WannaCrypt. In March, we provided a security update which provides additional protections against this potential attack. Those who are running our free antivirus software and have Windows Update enabled, are protected. We are working with customers to provide additional assistance.

Such an outbreak of malware, affecting public institutions, is the kind of scenario found in the novel, "Zero Day." Its author, Mark Russinovich, chief technology officer at Microsoft, acknowledged the similarity today, saying, "Yes, it's a scenario from Zero Day," in a Twitter post.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • Microsoft and SAP Enhance Partnership with Teams Integration

    Microsoft and SAP this week described continuing partnership efforts on Microsoft Azure, while also planning a Microsoft Teams integration with SAP's enterprise resource planning product and other solutions.

  • Blue Squares Graphic

    Microsoft Previews Azure IoT Edge for Linux on Windows

    Microsoft announced a preview of Azure IoT Edge for Linux on Windows, which lets organizations tap Linux virtual machine processes that also work with Windows- and Azure-based processes and services.

  • How To Automate Tasks in Azure SQL Database

    Knowing how to automate tasks in the cloud will make you a more productive DBA. Here are the key concepts to understand about cloud scripting and a rundown of the best tools for automating code in Azure.

  • Microsoft Open License To End Next Year for Government and Education Groups

    Microsoft's "Open License program" will end on Jan. 1, 2022, and not just for commercial customers, but also for government, education and nonprofit organizations.

comments powered by Disqus