A display panel with a ransomware error is seen at the main railway station in Chemnitz, Germany, on Friday. (AP Photo)

A display panel with a ransomware error is seen at the main railway station in Chemnitz, Germany, on Friday. (AP Photo)

‘Perfect storm’ helped huge ransomware attack succeed

By Anick Jesdanun, Associated Press

NEW YORK — The cyberextortion attack hitting dozens of countries spread quickly and widely thanks to an unusual confluence of factors: a known and highly dangerous security hole in Microsoft Windows, tardy users who didn’t apply Microsoft’s March software fix, and a software design that allowed the malware to spread quickly once inside university, business and government networks.

Not to mention the fact that those responsible were able to borrow weaponized software code apparently created by the U.S. National Security Agency to launch the attack in the first place.

A malware tracking map showed “WannaCry” infections popping up around the world. Britain canceled or delayed treatments for thousands of patients, even people with cancer. Train systems were hit in Germany and Russia, and phone companies in Madrid and Moscow. Renault’s futuristic assembly line in Slovenia, where rows of robots weld car bodies together, was stopped cold.

In Brazil, the social security system had to disconnect its computers and cancel public access. The state-owned oil company Petrobras and Brazil’s Foreign Ministry also disconnected computers as a precautionary measure, and court systems went down, too.

Other criminals may be tempted to mimic the success of Friday’s “ransomware ” attack, which locks up computers and hold people’s files for ransom. Experts say it will be difficult for them to replicate the conditions that allowed the so-called WannaCry ransomware to proliferate across the globe.

But we’re still likely to be living with less virulent variants of WannaCry for some time. And that’s for a simple reason: Individuals and organizations alike are fundamentally terrible about keeping their computers up-to-date with security fixes.

The worm turns … and turns

One of the first “attacks” on the internet came in 1988, when a graduate student named Robert Morris Jr. released a self-replicating and self-propagating program known as a “worm” onto the then-nascent internet. That program spread much more quickly than expected, soon choking and crashing machines across the internet.

The Morris worm wasn’t malicious, but other nastier variants followed — at first for annoyance, later for criminal purposes, such as stealing passwords. But these worm attacks became harder to pull off as computer owners and software makers shored up their defenses.

So criminals turned to targeted attacks instead to stay below the radar. With ransomware, criminals typically trick individuals into opening an email attachment containing malicious software. Once installed, the malware just locks up that computer without spreading to other machines.

The hackers behind WannaCry took things a step further by creating a ransomware worm, allowing them to demand ransom payments not just from individual but from entire organizations — maybe even thousands of organizations.

The perfect storm

Once inside an organization, WannaCry uses a Windows vulnerability purportedly identified by the NSA and later leaked to the internet. Although Microsoft released fixes in March, the attackers counted on many organizations not getting around to applying those fixes. Sure enough, WannaCry found plenty of targets.

Since security professionals typically focus on building walls to block hackers from entering, security tends to be less rigorous inside the network. WannaCry exploited common techniques employees use to share files via a central server.

“Malware that penetrates the perimeter and then spreads inside the network tends to be quite successful,” said Johannes Ullrich, director of the Internet Storm Center at the SANS Institute.

Persistent infections

“When any technique is shown to be effective, there are almost always copycats,” said Steve Grobman, chief technology officer of McAfee, a security company in Santa Clara, California. But that’s complicated, because hackers need to find security flaws that are unknown, widespread and relatively easy to exploit.

In this case, he said, the NSA apparently handed the WannaCry makers a blueprint — pre-written code for exploiting the flaw, allowing the attackers to essentially cut and paste that code into their own malware.

Mikko Hypponen, chief research officer at the Helsinki-based cybersecurity company F-Secure, said ransomware attacks like WannaCry are “not going to be the norm.” But they could still linger as low-grade infections that flare up from time to time.

For instance, the Conficker virus, which first appeared in 2008 and can disable system security features, also spreads through vulnerabilities in internal file sharing. As makers of anti-virus software release updates to block it, hackers deploy new variants to evade detection.

Conficker was more of a pest and didn’t do major damage. WannaCry, on the other hand, threatens to permanently lock away user files if the computer owner doesn’t pay a ransom, which starts at $300 but goes up after two hours.

The damage might have been temporarily contained. An unidentified young cybersecurity researcher claimed to help halt WannaCry’s spread by activating a so-called “kill switch.” Other experts found his claim credible. But attackers can, and probably will, simply develop a variant to bypass this countermeasure.

Fighting back

The attack is likely to prompt more organizations to apply the security fixes that would prevent the malware from spreading automatically. “Talk about a wake-up call,” Hypponen said.

Companies are often slow to apply these fixes, called patches, because of worries that any software change could break some other program, possibly shutting down critical operations.

“Whenever there is a new patch, there is a risk in applying the patch and a risk in not applying the patch,” Grobman said. “Part of what an organization needs to understand and assess is what those two risks are.”

Friday’s attack might prompt companies to reassess the balance. And while other attackers might use the same flaw, such attacks will be steadily less successful as organizations patch it.

Microsoft took the unusual step late Friday of making free patches available for older Windows systems, such as Windows XP from 2001. Before, Microsoft had made such fixes available only to mostly larger organizations that pay extra for extended support, yet millions of individuals and smaller businesses still had such systems.

But there will be other vulnerabilities to come, and not all of them will have fixes for older systems. And those fixes will do nothing for newer systems if they aren’t installed.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Family searches for answers in 1982 Gold Bar cold case murder

David DeDesrochers’ children spent years searching for him before learning he’d been murdered. Now, they want answers.

A SoundTransit Link train pulls into the Mountlake Terrace station as U.S. Representative Rick Larsen talks about the T&I Committee’s work on the surface reauthorization bill on Wednesday, April 16, 2025 in Mountlake Terrace, Washington. (Olivia Vanni / The Herald)
Larsen talks federal funding for Snohomish County transit projects

U.S. Rep. Rick Larsen (D-Everett) spoke with Snohomish County leaders to hear their priorities for an upcoming transit bill.

Irene Pfister, left, holds a sign reading “Justice for Jonathan” next to another protester with a sign that says “Major Crimes Needs to Investigate,” during a call to action Saturday, April 12, 2025, in Arlington. (Aspen Anderson / The Herald)
Arlington community rallies, a family waits for news on missing man

Family and neighbors say more can be done in the search for Jonathan Hoang. The sheriff’s office says all leads are being pursued.

Mary Ann Karber, 101, spins the wheel during Wheel of Forunte at Washington Oakes on Tuesday, April 1, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Lunch and Wheel of Fortune with some Everett swinging seniors

She’s 101 and he’s 76. At Washington Oakes, fun and friendship are on the menu.

Northshore School District Administrative building. (Northshore School District)
Lawsuit against Northshore School District reaches $500,000 settlement

A family alleged a teacher repeatedly restrained and isolated their child and barred them from observing the classroom.

Jury awards $3.25M in dog bite verdict against Mountlake Terrace

Mountlake Terrace dog was euthanized after 2022 incident involving fellow officer.

Everett City Council on Wednesday, March 19 in Everett, Washington. (Will Geschke / The Herald)
Everett council to vote on budget amendment

The amendment sets aside dollars for new employees in some areas, makes spending cuts in others and allocates money for work on the city’s stadium project.

Bryson Fico, left, unloaded box of books from his car with the help of Custody Officer Jason Morton as a donation to the Marysville Jail on Saturday, April 5, 2025 in Marysville, Washington. (Olivia Vanni / The Herald)
Books behind bars: A personal mission for change

Bryson Fico’s project provides inmates with tools for escape, learning and second chances.

Signs in support of and opposition of the Proposition 1 annexation into RFA are visible along 100th Avenue West on Thursday, April 3, 2025 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds voters approve measure to annex into South County Fire

Proposition 1 passed with 63% of the vote. For the city of Edmonds, it’s a step in addressing its fiscal crisis.

Lynnwood councilor Joshua Binda speaks during a Lynnwood City Council meeting on Wednesday, Nov. 20, 2024. (Olivia Vanni / The Herald)
County auditor dismisses challenge to Lynnwood Council VP’s residency

The auditor found a challenge to Josh Binda’s voter registration didn’t have enough evidence to prove he doesn’t live at his listed address.

Hundreds attend Snohomish County Prayer Breakfast on Good Friday

The third annual event featured music, prayers and an address from Gary Chupik, a former pastor and currently a performance coach for major corporations and athletes.

A newly installed traffic camera along 100th Avenue West on Monday, April 14, 2025 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds red-light camera program underway

The city sent 215 warning letters from April 10-17. Starting May 7, violators will receive a $145 citation.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.