Researcher Finds Kill Switch for new variant of WannaCry Ransomware

phaZed

Well-Known Member
Reaction score
3,155
Location
Richmond, VA
https://www.hackread.com/wannacry-ransomware-variant-kill-switch/

Internet users worldwide are now familiar with the WannaCry or WanaCrypt0r ransomware attack and how cybercriminals used it to infect cyber infrastructure of banking giants, hospitals, tech firms and sensitive installation in more than 90 countries.

The users may also know that a British security researcher MalwareTechBlog accidentally discovered the kill switch of WanaCry by registering a domain (iuqerfsodp9ifjaposdfjhgosurij faewrwergwea [dot] com) for just $10.69. The domain registry slowed down the attacks but didn’t stop them entirely.

Soon after, a security researcher from France going by the handle of @benkow_ on Twitter discovered a new variant WanaCrypt0r 2.0 and sent it to Matthieu Suiche for an in-depth analysis who is also an IT security researcher.

Upon analyzing, Suiche successfully discovered its kill switch which was another domain (ifferfsodp9ifjaposdfjhgosurij faewrwergwea [dot] com). According to Suiche’s blog post, he then successfully registered the domain to halt the new and growing wave of cyber attacks through WannaCry ransomware.
 
  • Like
Reactions: GTP
As I understand it, there are now variants of this that do not have any "kill switch" embedded. Seems like it would be a lot harder to stop those, just keep your machine up to date and practice good backup behaviors.
 
Back
Top