A new perspective on attacker behavior.Explore the intelligence EARLY ACCESS
Home

DECEPTIONSTRIKE / RESOURCES

What is WannaCry Ransomware

What is WannaCry Ransomware? What is WannaCry Ransomware? WannaCry is a type of ransomware that first emerged in May 2017. It spread rapidly across the globe, infecting hundreds of thousands of computers in more than 150

What is WannaCry Ransomware?

What is WannaCry Ransomware?

WannaCry is a type of ransomware that first emerged in May 2017. It spread rapidly across the globe, infecting hundreds of thousands of computers in more than 150 countries. The ransomware exploited a vulnerability in Microsoft Windows operating systems that had been discovered by the United States National Security Agency (NSA) and subsequently leaked by a group of hackers known as the Shadow Brokers.

Once a computer was infected with WannaCry, the ransomware would encrypt the user’s files and demand payment in exchange for the decryption key. The ransom amount varied between $300 and $600, and the payment was typically demanded in the form of Bitcoin. Failure to pay the ransom within a certain time frame would result in the files being permanently encrypted.

The WannaCry ransomware attack was one of the largest and most damaging cyberattacks in history, causing widespread disruption and financial losses across multiple industries and organizations, including hospitals, government agencies, and businesses of all sizes. The attack served as a wake-up call for many organizations, highlighting the importance of keeping software up to date and implementing robust cybersecurity measures to prevent future attacks.

How Deception Strike Has Detected this new WannaCry Variant?

Deception technology platforms are designed to detect and prevent cyber attacks by creating a virtual environment of decoy systems, files, and credentials that mimic those of real systems, files, and users. These decoys are designed to attract attackers and divert them away from actual systems and data, allowing security teams to detect and respond to attacks in real-time.

In the case of WannaCry ransomware, a deception technology platform can detect the attack by creating decoy systems that appear vulnerable to the same Windows vulnerability that the ransomware exploits. This can include creating virtual machines with unpatched versions of Windows, which would appear to be vulnerable to the EternalBlue exploit that WannaCry uses to propagate.

If an attacker attempts to exploit one of these decoy systems, the deception technology platform can trigger an alert, notifying security teams of the attempted attack and providing details about the attacker’s tactics, techniques, and procedures (TTPs). This information can be used to quickly identify and respond to the attack, preventing it from spreading to other systems and minimizing the damage.

In addition to detecting and preventing attacks, deception technology platforms can also be used to gather threat intelligence and insights about attacker behavior, helping organizations improve their overall security posture and better protect against future attacks.

How Deception Strike Has Detected this new WannaCry Variant?

Deception technology platforms are designed to detect and prevent cyber attacks by creating a virtual environment of decoy systems, files, and credentials that mimic those of real systems, files, and users. These decoys are designed to attract attackers and divert them away from actual systems and data, allowing security teams to detect and respond to attacks in real-time.

In the case of WannaCry ransomware, a deception technology platform can detect the attack by creating decoy systems that appear vulnerable to the same Windows vulnerability that the ransomware exploits. This can include creating virtual machines with unpatched versions of Windows, which would appear to be vulnerable to the EternalBlue exploit that WannaCry uses to propagate.

If an attacker attempts to exploit one of these decoy systems, the deception technology platform can trigger an alert, notifying security teams of the attempted attack and providing details about the attacker’s tactics, techniques, and procedures (TTPs). This information can be used to quickly identify and respond to the attack, preventing it from spreading to other systems and minimizing the damage.

In addition to detecting and preventing attacks, deception technology platforms can also be used to gather threat intelligence and insights about attacker behavior, helping organizations improve their overall security posture and better protect against future attacks.

Get your intel directly from the experts.

We are sharing all the latest and greatest cybersecurity knowledge in our webcasts, events, demos and more–come join us.

MAKE THE FIRST MOVE

Give attackers somewhere
else to go.

See what a deception-led approach can reveal about your environment.