Two 20-something cyber experts helped bring down the widespread ransomware attack that infiltrated networks at hospitals,Watch Midhunter banks, and government agencies in multiple countries.
A 22-year-old British researcher unintentionally found the so-called "kill switch" that authors of the malicious software left in the code. Later, he teamed up with a 28-year-old engineer in western Michigan to ultimately halt the infections, the Associated Press reported.
SEE ALSO: NSA tools at center of ransomware attacks hitting UK hospitalsThe unprecedented outbreak, which began last Friday, locked up computers and extorted users for large Bitcoin payments in nations as diverse as the U.S., Russia, Ukraine, Brazil, Spain, and India. It also hit the U.K.'s National Health Service, affecting computers in hospitals and doctors' offices.
Britain's National Cyber Security Center and others praised the 22-year-old researcher -- identified only as MalwareTech -- for killing the software, which reportedly blocked U.K. hospital schedules, patient files, and phone and email systems from access and rerouted emergency room patients.
MalwareTech belongs to a large global community of cybersecurity buffs who, working independently or for security companies, constantly monitor for attacks and collaborate to stop them. It's fairly common for members to use aliases for privacy or to protect themselves from retaliatory attacks.
The young researcher explained in a blog post on Saturday how he "accidentally" stopped the global cyberattack
He said he returned from lunch with a friend on Friday and learned that a ransomeware attack had crippled Britain's health system. A fellow researcher called Kafeine soon gave him a sample of the malicious software.
The malware, known as WannaCry or WannaCrypt, exploits a vulnerability in Microsoft Windows that was reportedly developed and used by the U.S. National Security Agency. Hackers in the group Shadow Brokers later leaked the exploit online.
This Tweet is currently unavailable. It might be loading or has been removed.
In his analysis, MalwareTech noticed a hidden, unregistered web address in the code. He quickly registered the inexpensive domain to see if it would help him track or stop the software.
Meanwhile, across the pond in Michigan, Darien Huss was doing his own research. The engineer, who works for the cybersecurity firm Proofpoint, said he noticed the malware authors had included a kill switch. He took a screenshot of his finding and posted it on Twitter.
Huss and MalwareTech were soon communicating about their findings. By registering the domain name and redirecting attacks to his server, MalwareTech had apparently activated the kill switch, which halted the ransomware's infections.
The duo's actions may have saved companies and governments millions of dollars and slowed the outbreak before more U.S. computers were affected.
This Tweet is currently unavailable. It might be loading or has been removed.
Huss praised his partner in non-crime for the discovery and said the security industry as a whole "should be considered heroes," the AP reported. But he said he's worried the authors of the malware could release a new and improved version without a kill switch, or that copycats could unleash similar attacks.
"I think it is concerning that we could definitely see a similar attack occur, maybe in the next 24 to 48 hours or maybe in the next week or two," Huss told the AP. "It could be very possible."
Security experts said the perpetrators of this attack remain unknown. The malicious software was identified in more than 70 experts, though Russia was hit the hardest.
European cybercrime experts are "working closely with affected countries' cybercrime units and key industry partners to mitigate the threat and assist victims," Europol, the European Union's police agency, said on Saturday in a statement.
"The recent attack is at an unprecedented level and will require a complex international investigation to identify the culprits," Europol said.
Associated Press contributed reporting to this story.
Topics Cybersecurity Windows
This Netflix hack shows you the first show you ever bingedModels are posing in Hobby Lobby photoshootsAn interview with '2 Dope Queens' Phoebe Robinson on #MeToo in comedyFormer Uber CEO Travis Kalanick keeps his cool during selfApple is rejecting apps from the App Store for using emojiDisney says ESPN Plus streaming service coming spring 2018Winter Olympics include a Guinness World Record set by Intel’s dronesSnapchat now has 187 million daily active usersApple files DMCA takedown after iBoot source code hits GitHubThis is what happens when women ask their crushes out for Valentine's DayThe 'Black Panther' soundtrack just dropped: Listen'Stranger Things 3' reveals episode countShortly after SpaceX launch, Reddit has wallpapers of Starman in TeslaStar Wars hires 'Game of Thrones' writers and the jokes are just fireDrake just paid for a bunch of people's groceries so, uh, they can thank him nowModels are posing in Hobby Lobby photoshootsWhat LGBTQ Olympians can expect to find in South KoreaDetroit quickly reverses ban on Airbnb after backlashQuentin Tarantino apologizes to Samantha Geimer for Roman Polanski remarksShortly after SpaceX launch, Reddit has wallpapers of Starman in Tesla Bumble launches new features to help you date during quarantine How it feels to be ghosted during the coronavirus pandemic WWE to merge with UFC parent company Endeavor. What we know. 'Animal Crossing' fans recreate iconic album covers with K.K. Slider People are dunking on an old Steve Mnuchin video about the $1,200 stimulus checks Do not inject yourself with bleach to cure coronavirus, holy crap Twitter replaces logo with doge as Musk seeks Dogecoin lawsuit dismissal Pornhub parody Scrubhub features videos about washing your dirty, dirty hands What it's like to be polyamorous during the coronavirus quarantine How to spot a fake Twitter profile 'Tetris' review: This video game How to make a Negroni with Stanley Tucci, a highly soothing video Twitter's newly How to break off a toxic friendship 'Gossip Girl' is back in this delightfully broken quarantine meme Wordle today: Here's the answer, hints for April 1 Twitter now lets businesses handle their employees' blue ticks, for a hefty price Stop comparing coronavirus to other deadly viruses 'Paddington 3' is officially happening Oil prices are negative and nobody is really sure what that means
2.324s , 10137.765625 kb
Copyright © 2025 Powered by 【Watch Midhunter】,Openness Information Network