The WannaCry ransomware campaign wasn’t the first to use the EternalBlue and DoublePulsar exploits. ESET has revealed that they were first used at the end of April when hackers Monero cryptocurrency mining software.
The massive campaign that spread the WannaCry (aka WannaCryptor) ransomware wasn’t the only recent large-scale infection misusing the EternalBlue and DoublePulsar exploits, leaked by Shadow Brokers. The same mechanism was misused by black-hats as early as the end of April, when they opted for the off-the-shelf Monero cryptocurrency mining software, instead of the encrypting payload.
This campaign detected as Win32/CoinMiner.AFR and Win32/CoinMiner.AFU started only a few days after the NSA tools leaked online. ESET had network detections for the vulnerability deployed on April 25th – three days before the first attack attempts by these miners for Monero cryptocurrency.
The biggest uptick was recorded only hours before the mining ransomware’s global outbreak, on May 10th. On that day, mining malware detections increased from hundreds of detections per day to thousands. We have seen such attempts in as many as 118 countries, with Russia, Taiwan and Ukraine topping the list.
However, the mining software consumed system resources so intensely that in some cases it rendered the infected machines unresponsive.
Interestingly the CoinMiner attacks also blocked the 445 port used by the EternalBlue exploit to get into the machine, essentially closing the door to any subsequent infection using the same vector – including WannaCry. If the miners hadn’t taken this precaution, the number of WannaCry infections could have been even greater than reported.
So how bad was the WannaCry attack?
According to ESET telemetry, since Friday, the machines of more than 14.000 users who have enabled ESET LiveGrid, has reported as many as 66.000 WannaCry attack attempts on their devices.
These attacks mainly targeted Russian computers, with over 30.000 attacks, followed by Ukraine and Taiwan, where in both cases they were close to the 8.000 mark.
The chaos that ensued after WannaCry’s global outbreak seems to have motivated other black-hats to scale up their efforts too. We have seen a significant increase in the number of malicious emails sent out by the notorious Nemucod operators, spreading another ransomware.
Also, WannaCry fakes have emerged. These try to ride the wave of its fame by using the same GUI and layout. However, the encrypting capability was missing in all seen instances.
What should you do to stay safe?
- Since the EternalBlue exploit uses a vulnerability in Windows that has been already patched by Microsoft, the first thing would be to verify the completion of the update and the patch to your operating system.
- Use a reliable security solution that utilises multiple layers to protect you from similar threats in the future.
- It is best practice to keep backups on a remote hard disk or location that will not be hit in case of a network infection.
- We recommend that users do not pay ransoms – be it a case of the true WannaCry or any other ransomware. There have been no reported cases where pursuing such a step would lead to decryption. On the contrary, there have been multiple stories documenting the opposite – no decryptor or key being sent after the payment was made. Also, there seems to be no way for the attackers to match the payment to the specific victim who sent it to one of the shared BitCoin wallets.
Smash hits the Nintendo Switch
Super Smash Bros. delivers what the fans wanted in the latest “Ultimate” instalment, writes BRYAN TURNER.
Super Smash Bros. Ultimate, the latest addition to the popular Nintendo Smash series, has landed on the Nintendo Switch with a bang, selling 5-million copies in the first week of its release. The game has been long-anticipated since the console’s release, as many fans consider
It features 74 playable fighters, 108 stages, almost 1300 Spirit characters to collect while playing, and a single-player Adventure mode that took about three days (or 28 hours) of gameplay to complete. The game offers far more gameplay than its predecessors, making it the Smash game that gives its players the best bang for their buck.
For those new to the game, the goal is to fight opponents and build up their damage score (draining their health) to knock them off the stage eventually. This makes the game seem chaotic, as many players jump around the platforms as if they were on quicksand, in order to avoid being hit by the other players.
It also services two kinds of players: the competitive and the casual.
Competitive players can be matched on the online service by skill ranking to enjoy playing with similarly high-skilled opponents. This is especially important in e-sports training for the game, and for players wanting to master combos against other human players. The casual gamer is also catered for, with eight-player chaos and button-mashing to see who comes out luckiest. This segment is also important for those wanting to learn how to play.
Training mode is also a place to go for those learning to play. It offers “CPU” players that are graded by intensity to train as a single player to learn a character’s moves, combos and general fighting style. More challenging CPU players can also be used by competitive players to train when there isn’t a Wi-Fi connection available.
Direct Play features in this game, allowing two players with two Switch consoles to play against each other over a direct connection – no Wi-Fi needed. This is especially useful to those who want to have a social gaming element on the go, similar to that of the cable connector of the Gameboy.
Click here to read Bryan Turner review of Super Smash Bros. Ultimate.
Win Funko Fortnite in Vinyl
Gadget and Gammatek have nine Funko Fortnite figurines to give away.
A Funko Pop figurine based on a character set is indicative of reaching the heights of pop culture. It is no surprise, then, that the world’s biggest online game, Fortnite, has its own line of Funko Pop figurines. The Funkos are modeled on the characters in game, including Drift, Ragnarok, Dark Vanguard, Volar, Tracera Ops, and Sparkle Specialist.
Now, local Funko distributor Gammatek has released the Fortnite figurines in South Africa. To celebrate, Gadget and Gammatek are giving away a set of three Funko Fortnite figurines to each of three readers (9 figurines in total). To enter,
You can put the tweet in your own words, but entries must have the competition’s hashtag (#FunkoFortnite) and mention @GadgetZA to be considered valid.
Click here to select the Funko Fortnite character you want to tweet.