All You Need to Know About the Ransomware | Antivirus Software
A large cyberattack with the WannaCry ransomware swept thousands of devices running the Windows operating system in about a hundred countries around the world, and the virus attack began last Friday evening to spread to the United States and South America, then Europe and Russia, which were the countries that suffered the most from the cyber attack. Affected countries included the United Kingdom, India, China, Italy, Egypt, and Oman.
What is WannaCry ransomware?
Ransomware is a type of virus that infects computers, and then prevents the user from accessing the operating system or encrypts all data stored on the computer, and asks the user for a "ransom" or special request, often paying a specified amount of money ($ 300 in the Last attack) vs. decrypting files or allowing back access to the operating system.
How did the last attack start?
The virus appeared on the Internet on April 14th, through a group calling itself "Shadow Brokers", which is the same group that announced the last year 2016 the acquisition of tools and vulnerabilities from the US National Security Agency (NSA), which the agency uses to penetrate users' devices, and it was among these Vulnerabilities A security vulnerability that allows attackers to infect devices with the WannaCry virus, but there is no assurance that the group was responsible for the latest attack.
On his Twitter account, Edward Snowden criticized the US National Security Agency for holding it responsible for the recent security attack on many institutions and people in many countries around the world and said that if the agency had announced the loophole upon reaching it, it would have been blocked and many hospitals would not have been subjected to such. This attack.
The most prominent parties that were attacked
Russia was the country most affected by the large cyber-attack so that more than 1,000 computers in the Russian Interior Ministry were infected with the virus and lost access to data. According to the company, "Kaspersky", which specializes in information security, about 50 thousand devices have been infected with the virus around the world in about 100 countries. Egypt was among the 20 countries most attacked.
The Spanish telecommunications company, Telefónica, was one of the most prominent parties that suffered from the attack, and the attack also hit the largest health care system in the United Kingdom, the NHS , which prevented many employees in dozens of hospitals from using work computers, which prompted these hospitals to transfer patients to other hospitals because they could not be treated. It is the most dangerous aspect of a cyber attack, due to its potential impact on patients' lives.
Sultan Qaboos University announced that it had detected attempts to attack the WannaCry virus on the university's computers, and said that specialists are working to solve the problem.
A Los Angeles hospital paid $ 17,000 last year to hackers who managed to infect the devices with the ransomware virus, shutting down employees' devices, including doctors and nursing staff, for several days.
The WannaCry attack came to an abrupt halt after-hours thanks to an information security researcher from the United Kingdom, who refused to reveal his identity and only posted tweets on Twitter in the name of malwaretechblog.
The researcher told the Guardian today that he took a look at the code for the WannaCry ransomware virus and found by chance that it was using a long "domain" in launching the attack, which made him quickly register this domain and start monitoring it, and then the ability to obtain the (IP) address of people Those who were injured in the attack and cooperate with the official authorities in helping them. And the domain registration stopped the spread of the attack, as the party responsible for the malware had prepared the code for it so that if the domain was registered and became available, the attack would stop, but the security researcher who discovered the domain and registered it warned of the attack again.
How to avoid infection with the virus?
Update your Windows operating system to the latest version. Microsoft released an update last March that plugged vulnerability hackers were using to infect devices with the WannaCry virus. (The update can be downloaded and installed from the Microsoft website )
Beware of visiting insecure or untrusted websites.
Beware of clicking malicious links in emails and on Facebook, Twitter, and other social networks.
- Never click on any link that you do not trust on a webpage or that you receive via Facebook or messaging applications such as WhatsApp and other applications.
- If you received a message from your friend with a link, ask him before you open the link to be sure.
Use an anti-virus program and keep it up to date.
Back up your files regularly.
Beware of fraudulent emails that use names similar to popular services, such as PayPal instead of PayPal, or use popular service names without commas or with an extra character.
- Some information security experts advise to turn off the SMB feature in Windows, by going to the Control Panel and then Add / Remove Programs or Programs in Windows 10 and from the side menu choose to Turn Windows Features ON / OFF, a new window will appear, remove the sign Correct from the small square in front of the SMB option as in the previous image. Antivirus Software safe your pc.

Comments
Post a Comment