WannaCry ransomware could still wreak havoc if there’s an internet outage

(Image credit: Pixabay (no attribution needed))

Remember WannaCry, the annoying piece of ransomware that spread quickly and especially disrupted hospitals in the UK before being contained? Well, as it turns out, there are potentially hundreds of thousands of PCs that are still infected with WannaCry.

Ransomware is a type of malware that encrypts a user's files and holds the data hostage until a ransom is paid, often times in Bitcoin. In many cases, there is a time limit imposed, after which the user's files get permanently deleted.

WannaCry is a specific piece of ransomware that made headlines in 2017 because of how quickly it was able to spread, and the damage it caused—hospitals in the UK had to shut down some of their non-emergency services as they dealt with the outbreak. The ransomware also went by a few other similar names, including WannaCryptor, WannaCrypt, and Wanna Decryptor.

The accidental discovery of a so-called kill switch stopped WannaCry from spreading within a few days of its discovery, as Wired explained at the time. A malware expert who goes by the name MalwareTech worked to reverse engineer WannaCry, and in the process he discovered that its programmers coded the ransomware to ping a specific URL.

Curious, he registered the domain for $10.69. In the process, he effectively shut down WannaCry—it turned out that WannaCry would only spread if the URL in question is unregistered and inactive. Once it became active, WannaCry stopped trying to infect additional PCs.

The registration of the domain effectively neutralized WannaCry, but didn't get rid of it altogether. Jamie Hankins, head of security and threat intelligence researcher at Kryptos Logic, explained in a recent Twitter thread WannaCry infections continue to ping the aforementioned domain, which is now hosted by Cloudflare.

"In the last 24 hours we saw 2,713,752 beacons from 220,648 unique SrcIPs to the kill switch from 184 different countries," Hankins says.

The numbers balloon if looking at the past week, in which Hankins says there have been over 17 million pings from almost 640,000 unique IP addresses across 194 countries.

Hankins disclaims that the numbers are likely not 100 percent accurate because of the difficulty in tracking and collecting this kind of data, but even if it's in the ballpark, it's somewhat concerning.

"The fact that so many computers are still infected with this malware is a major problem. All you need is an internet outage to occur and for the kill switch domain to no longer be accessible for the ransomware to kick in," Bleeping Computer explains.

To prevent this from happening, Kryptos Logic built a free service called TellTale that enables organizations to monitor their range of IP addresses for known infections, including "WannaCry and a range of other potential threats."

It's not clear how many organizations have taken advantage of the service, but given the data, it seems like something companies should look into doing.

Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Hardware
A woman wearing a VR headset with dramatic, colourful lighting across the background
'World’s smallest LEDs' could lead to accurately lit screens with 127,000 pixels per inch and much more immersive VR
The NES themed 8BitDo Retro mechanical gaming keyboard on a blue background
I love the 8BitDo Retro C64 keyboard but I'd pick its cheaper NES-themed model near its lowest price ever during Amazon's Big Spring Sale
The snazzy red and black HyperX Cloud Alpha wireless headphones float in a teal void. The microphone is attached to the headset.
The best wireless gaming headset is now even better in the Amazon Big Spring Sale, boasting a more than $50 discount
A chip being held up in an Intel fab
Intel is reportedly 'working to finalize commitments from Nvidia' as a foundry partner, suggesting gaming potential for the 18A node
Amazon box
Don't panic! The 'Do Not Send Voice Recordings' option Amazon just removed was only used by 0.03% of customers and they can still have it
Digital generated image of people surrounded by interactive transparent and glowing panels with data. Visualising smart technology, blockchain and artificial intelligence
Now I shall demand the cookies! Proposed new browsing agreement turns the tables and lets users dictate terms to websites
Latest in News
An Enshrouded player in a recreation of Erebor from The Lord of the Rings
Kings under the Mountain! 33 Enshrouded players spent 10,000 hours to recreate this iconic location from The Lord of the Rings
A mech awakens.
Mecha Break developer is considering unlocking all mechs following open beta feedback
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
A long bendy arm stealing money from people in a subway car
'You're a very long arm. You steal things. It's a comedy game,' explains developer of comedy game where you steal things with a very long arm
The heroes are attacked by monsters
Pillars of Eternity is getting turn-based combat to mark its 10th anniversary, and that means PC Gamer editors will soon be arguing about combat mechanics again
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened