May 22, 2017 By Douglas Bonderud 3 min read

The WannaCry ransomware remains a critical threat even after the discovery of a kill switch. Fraudsters are still looking for a workaround, while previously infected devices are reaching the end of their countdown — should they pay up or attempt to find another way out?

As noted by SecurityWeek, there are now reports that Microsoft withheld a critical patch that could have slowed the spread of this infection and limited its overall impact. While it’s tempting to throw stones at the technology giant, the outcome is symptomatic of the much larger problem of unpatched operating systems that offer easy access for malware-makers.

Patching Problems

Back in March, Microsoft detected a vulnerability in Windows code that paved the way for ransomware such as WannaCry. At the time, the company distributed a free security update for Windows 10 devices to patch the hole and limit the threat. But there was no such update for Windows XP, and users were forced to pay between $200 and $400 if they wanted the update. After the attack began, Microsoft released the patch for free and included all older versions. Understandably, backlash is now brewing online.

But that isn’t the whole story. Support for XP ended three years ago after 12 years of full support from the company. Businesses knew the risk of continuing to use unsupported software, and in so doing assumed the responsibility for either patching their own systems or paying for custom support.

It’s also worth noting that the number of XP devices infected by WannaCry is “insignificant” — 98 percent of all affected Windows computers were running Windows 7, according to The Verge. And guess what? Windows 7 was part of the free March upgrade.

The Bigger Picture

For XP devices that have already been infected, CNET reported that a new fix called WannaKey might help. So long as the computer hasn’t been rebooted, the tool can scan for prime numbers used to create encryption and decryption keys and then unlock the device.

Another tool, WanaKiwi, does the same for Windows 7 computers. But even as security teams are cleaning up current infections and building decryption tools, Wired reported that cybercriminals are still trying to disable the kill switch to get the ransomware back on track.

Kryptos Logic cybersecurity analyst Marcus Hutchins discovered that WannaCry attempts to connect with a specified web domain. If successful, it indicates the presence of a security sandbox and forces the malware to go dormant. Hutchins registered the domain in the ransomware’s code, making it believe that every new infection was actually a security testing environment, and stalling the entire attack effort.

Now fraudsters are trying to take this domain offline by flooding it with junk traffic using a Mirai botnet. If successful, rebooted machines carrying the infection will begin spreading it anew.

WannaCry Woes Continue

So what does all this mean for businesses worried about the WannaCry ransomware and looking for ways to defend against the next big threat? It’s not enough to wait around hoping that OS vendors will offer a patch for free or provide automatic security updates.

While it may be cost-efficient to run older OSs and limit the need to deploy new software and integrate new functions, this shifts the onus from software-makers to in-house IT. Patching becomes paramount and the problem of device owners, not developers.

Many tears have been shed over WannaCry, and there are more to come as this plays out. Sure, it’s tempting to berate Microsoft for holding back a patch, but that misses the message and leaves companies vulnerable for the next ransomware rollout.

In short, the older the OS, the bigger the risk; patch first and patch fast to avoid the biggest problems with new ransomware risks.

Join the IBM webinar series: Orchestrate Your Security Defenses to Avoid Ransomware Attacks

More from

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today