WannaCry – New Variants Detected
21–30 of 164 posts
Re: WannaCry – New Variants Detected
#22Earlier quoted context omitted.
From what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a mass phishing campaign. See: https://arstechnica.com/security/2017/05/an-nsa-derived-rans...
The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.
Re: WannaCry – New Variants Detected
#23Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.
They never would. It's just a naive test to see if the software is running in a VM. Researchers usually resolve all DNS queries inside their test VMs.
Re: WannaCry – New Variants Detected
#24Just wait until this hits the files of a Russian mob who then take some Americans hostage and fly to China and end up entangled in an islamic terrorist plot. 'Cause then we're in for a very long and drawn out story involving MI6, the CIA, Canadian smuggling routes, and Christian Isolationist 2nd Amendment fanatics.
Re: WannaCry – New Variants Detected
#25Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.
The sweet spot for an attack is welll below the level where you wake up national LE, especially in such a public way.
Remember when LulzSec was hacking everything in sight with daily press coverage. If I remember correctly all but one were arrested in under 1 year.
Re: WannaCry – New Variants Detected
#26If they attach this to a new exploit, instead of an old one that targets Windows XP, there's going to be a real problem.
Re: WannaCry – New Variants Detected
#27Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.
This is what happens when spambot skiddies accidentally acquire a treasure-trove of NSA tools via a C2 server they have pwned. They failed to sell ('broker') them as nobody was stupid enough to touch them, they failed to blackmail with them (omg what a bad move), then they failed to weaponise their own gear with them (wcry 1.0 in February), and even though wcry 2.0 is widespread and very disruptive, really they faile…
Re: WannaCry – New Variants Detected
#28Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.
The reason is there is no good press to be gotten by announcing they caught these people...all that does is draw attention to the fact they were breached/bamboozled/whatever in the first place. In their eyes, this story and any public interest cannot die quickly enough.
Re: WannaCry – New Variants Detected
#29These systems would be better of security wise if they would use the latest open source operating system including the embedded code. The damage this will cause to embedded systems is distasteful.
In the case of WannaCrypt0r, the vulnerability had already been fixed by Microsoft but those who were hit hadn't patched because as discussed elsewhere applying patches may break things so some postpone or ignore it. Same thing could have happened to a system running Linux.
Re: WannaCry – New Variants Detected
#30Earlier quoted context omitted.
Do you seriously expect criminals are dumb enough to leave any useful information there?
Do you seriously expect most criminals are intelligent?
The meth dealer two houses down who serves people out his front window probably isn't thinking straight. What we're dealing with here is a different category of thinking.