WannaCry, start to finish: a leaked spy tool, an unapplied patch and a $10.69 off switch
On May 12, 2017, a piece of ransomware reached more than 200,000 computers in about 150 countries in a single afternoon, and the fix that would have stopped it had been sitting on Microsoft's website for 2 months.[2][11] This long read follows WannaCry from a leaked spy agency tool to England's hospitals, the accidental off switch, the arrest nobody expected, the attribution to North Korea, and the one control that would have kept it out.
The stolen spy tool behind WannaCry
WannaCry's engine was not written by the people who released it. It rode on a flaw in the Windows file-sharing service, the part of the operating system that lets office computers swap documents and reach shared printers. The flaw let an attacker take control of a vulnerable machine across a network without anyone clicking anything. According to widespread reporting, the exploit for it had been built by the U.S. National Security Agency, which has never publicly commented on it.[7]
On March 14, 2017, Microsoft published a security bulletin rated critical that fixed the flaw in every supported version of Windows.[2] A month later, on April 14, a group calling itself the Shadow Brokers posted a batch of hacking tools online, including the exploit for this flaw. Microsoft said at the time that the leaked exploits had already been patched.[3] That was true for anyone who had installed the March update. For everyone else, a weapon that had been secret was now free to download.
In England, NHS Digital, the health service's technology body, issued critical alerts in March and April urging organizations to install the update. The government had told trusts back in 2014 to move off Windows XP, a system Microsoft no longer supported, by April 2015.[1] Many had not finished either job when May arrived.
Someone then attached the leaked exploit to ransomware, software that scrambles files and demands payment to unscramble them. The result was a worm, meaning a program that copies itself from machine to machine with no human help. Each infected computer locked its owner's files, displayed a ransom note asking for bitcoin, and went looking for the next vulnerable neighbor on the network and on the internet.[11] There was no email to delete and no link to avoid. One unpatched computer with file sharing exposed was enough.
How WannaCry hit England's hospitals
The worm began spreading on Friday, May 12, 2017.[1] Within hours it had reached companies across Europe and beyond. Spain's largest telephone company told staff to shut down their computers, carmaker Renault halted production at some plants in France, Nissan's factory in Sunderland in northern England was hit, and ransom notes appeared on departure boards at German rail stations.[4]
England's National Health Service took the worst of it. The National Audit Office, the government's spending watchdog, later found that at least 81 of the 236 hospital trusts in England were affected, about a third of the total, along with 603 primary care and other NHS organizations, including 595 family doctor practices.[1] Five emergency departments, in London, Essex, Hertfordshire, Hampshire and Cumbria, had to send some patients elsewhere. The audit office could identify 6,912 cancelled appointments directly and estimated the true figure at more than 19,000.[1]
The common thread was plain. Every NHS organization the audit office examined had been infected through Windows systems that were either missing the March update or too old to receive it.[1] Nobody in the NHS paid the ransom, and the audit office found no evidence that patient data had been taken.[1] The worm was not after records. It simply locked whatever it reached, and in a hospital what it reached were the systems used to book scans, read results and move patients.
The $10.69 kill switch
That same afternoon a 22-year-old malware researcher working from his home in England was picking apart a sample of the worm. He noticed that before it did anything, each copy tried to contact a long, nonsense web address that nobody owned. He registered the address for $10.69, a routine habit he used to watch what malware was doing.[5] It turned out to be an off switch. Once the address answered, new copies of the worm that could reach it stopped instead of encrypting files.[5][10]
The audit office credited that registration, which took effect between May 12 and May 15, with halting the attack and preventing much wider disruption.[1] It was not a cure. Machines already locked stayed locked, and a copy running on a network cut off from the internet could not see the answer. Between May 15 and mid-September, 92 NHS organizations, including 21 trusts, were still found contacting the address, a sign the worm was sitting on their machines.[1]
Microsoft also took an unusual step. On May 13 it released an emergency fix for Windows XP and other systems it had long since stopped supporting, so that organizations still running them had some protection.[6] Microsoft's president used the moment to criticize governments for keeping software flaws secret instead of reporting them, comparing the leak to the theft of military weapons.[7]
The ransom, the bill and the researcher's arrest
For an attack that spanned the globe, the ransom haul was small. The 3 bitcoin wallets named in the ransom note took in roughly $140,000 in total, and in early August 2017 they were emptied in a series of withdrawals.[8] The design of the payment system made it hard for the attackers to tell who had paid, which is one reason paying was never a reliable way to get files back.
The real cost landed on the victims. In October 2018 the Department of Health and Social Care estimated that WannaCry cost the NHS about 92 million pounds: about 19 million in lost output while services were disrupted and about 73 million in IT repair and support afterward. Officials called it a broad estimate.[14]
The researcher's story took a turn of its own. In early August 2017, after attending security conferences in Las Vegas, he was arrested by the FBI on charges that had nothing to do with WannaCry. Prosecutors said that years earlier he had helped create and sell banking malware that stole login details.[9] In April 2019 he pleaded guilty to 2 counts.[15] On July 26, 2019, a federal judge in Wisconsin sentenced him to time served and 1 year of supervised release, and said his role in stopping WannaCry weighed heavily against the harm of the malware he admitted writing.[10]
How WannaCry was traced to North Korea
On December 19, 2017, the British government said it was highly likely that a North Korean group was behind WannaCry, and the White House publicly attributed the attack to North Korea the same week.[12][13]
On September 6, 2018, the Justice Department charged a North Korean computer programmer who, prosecutors say, worked for a government front company and belonged to a team behind a string of attacks, including WannaCry, the 2014 attack on Sony Pictures and the $81 million theft from Bangladesh Bank in 2016.[11] Investigators linked the cases through shared code and shared infrastructure, such as the same accounts and servers turning up in more than one operation.[11] The defendant has not been brought to a U.S. court, and the charges remain allegations.
The attribution did not change what the NHS had learned about itself. The audit office noted that before the attack there was no formal process for checking whether local NHS bodies had actually acted on critical security alerts.[1] The warnings had gone out. Nobody was tracking whether they landed.
What would have stopped the worm
Put the sequence side by side. The flaw was public and fixed in March. The exploit was public in April. The worm arrived in May. At every step, a machine that had installed the March update was safe from this particular attack, and a machine running an unsupported system that could not be updated was a standing invitation.[1][2]
The worm also moved as far as it did because the file-sharing service was reachable from places it never needed to be reached from: from the open internet, and between computers inside a network that had no reason to talk to each other. Closing that door at the edge of the network, and limiting it inside, would have slowed the spread even where patching lagged.[1]
WannaCry was stopped by luck and a $10.69 web address. It could have been stopped weeks earlier by a routine update that had already been written, tested and published.
Timeline
| Date | What happened |
|---|---|
| Apr 2015 | Deadline NHS trusts had been given to move off Windows XP.[1] |
| Mar 14, 2017 | Microsoft publishes a critical fix for the Windows file-sharing flaw.[2] |
| Mar–Apr 2017 | NHS Digital issues critical alerts urging the update.[1] |
| Apr 14, 2017 | The Shadow Brokers leak the exploit online.[3] |
| May 12, 2017 | WannaCry begins spreading; at least 81 NHS trusts are hit.[1] |
| May 12–15, 2017 | A researcher's registered web address acts as a kill switch.[1][5] |
| May 13, 2017 | Microsoft releases an emergency patch for Windows XP.[6] |
| Aug 2017 | Ransom wallets emptied; the researcher is arrested in Las Vegas on unrelated charges.[8][9] |
| Dec 19, 2017 | UK and U.S. governments attribute WannaCry to North Korea.[12][13] |
| Sep 6, 2018 | Justice Department charges a North Korean programmer.[11] |
| Oct 2018 | Health department puts the NHS cost at about 92 million pounds.[14] |
| Jul 26, 2019 | The researcher is sentenced to supervised release, no further prison.[10] |
The missing control
The missing control: install critical security updates within days, take systems too old to update off the network, and block the file-sharing service at the network edge. Any one of those would have kept WannaCry out of most of the machines it locked.[1][2]
- Turn on automatic updates everywhere. Set every Windows PC, laptop and server to install security updates on its own, and check monthly that none has quietly stopped.
- Set a deadline for critical patches. When a vendor labels an update critical, give it a firm window, such as 7 days, and have someone confirm in writing that it is done.
- Retire or isolate unsupported systems. List every device running software its maker no longer updates. Replace it, or unplug it from the main network if it runs a machine you cannot replace yet.
- Close file sharing to the internet. Ask your IT provider to confirm that the router or firewall blocks outside access to Windows file sharing, and that remote staff reach files through a secure connection instead.
- Keep offline backups and test them. Store a recent copy of key files somewhere ransomware cannot reach, and practice restoring it so a locked screen is an inconvenience, not a shutdown.
What it means now
WannaCry is remembered for its lucky ending, but the lesson is in its beginning. The flaw was known, the fix was free, and the warnings had been sent. The gap was between a warning and a finished job, and nobody was measuring it.
Most small businesses will never be targeted by a spy agency's leaked tools. They do not need to be. Worms and ransomware crews scan the whole internet for the same unpatched doors, and they do not check who owns the building. An update installed this week is still the cheapest security there is.
How WannaCry hit the NHS: the fix existed 2 months before the attack: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- National Audit Office: Investigation: WannaCry cyber attack and the NHS
- Microsoft: Microsoft Security Bulletin MS17-010 - Critical
- SecurityWeek: Microsoft says latest Shadow Brokers exploits already patched
- Times of Israel: Organizations hit by unprecedented global cyberattack
- KSL: 22-year-old credited for accidentally stopping WannaCry from spreading
- Engadget: Microsoft patches Windows XP to fight WannaCrypt attacks
- NPR (via Central Florida Public Media): WannaCry ransomware: Microsoft calls out NSA for stockpiling vulnerabilities
- Fortune: WannaCry ransom bitcoin wallets emptied
- TechCrunch: Marcus Hutchins arrested by FBI
- Krebs on Security: No jail time for WannaCry hero
- U.S. Department of Justice: North Korean regime-backed programmer charged with conspiracy to conduct multiple cyber attacks
- GOV.UK: Foreign Office minister condemns North Korean actor for WannaCry attacks
- Government Executive: North Korea was behind the WannaCry cyberattacks, says White House
- Computer Weekly: Cost of WannaCry attack to NHS set at 92m pounds
- Engadget: MalwareTech security researcher pleads guilty