[Infowarrior] - Apparent NSA tools behind massive hospital ransomware attacks around the world

Richard Forno rforno at infowarrior.org
Fri May 12 13:30:26 CDT 2017


Apparent NSA tools behind massive hospital ransomware attacks around the world

By Eric Geller

05/12/17 02:07 PM EDT

http://www.politico.com/story/2017/05/12/nsa-hacking-tools-hospital-ransomware-attacks-wannacryptor-238328

Leaked alleged NSA hacking tools appear to be behind a massive ransomware campaign disrupting hospitals and companies across Europe.

In Spain, the country's Computer Emergency Readiness Team said that the ransomware is a modified version of the WannaCryptor toolkit. The malware was included in an online April dump from a group calling itself the Shadow Brokers, which released what they said were NSA tools. Experts have said the leaked tools appear legitimate.

Spain’s CERT said the ransomware that is spreading “infects the machine by encrypting all its files" and allows the attackers to remotely control the network. The malware is also then "distributed to other Windows machines in that same network,” Spain’s CERT said.

The Spanish organization pointed to a Microsoft security update from March offering a fix for the flaw.

Security researchers generally assume that the NSA secretly notified Microsoft about this and other code flaws once it discovered that they had been stolen.

Britain’s National Health Service confirmed that the ransomware was a WannaCry variant called WannaCryptor.

The WannaCryptor ransomware has crippled hospitals and other companies in the United Kingdom, Spain, Russia and many other countries, and researchers say it has reached the U.S.

The cyberattack has forced at least two London hospitals to stop admitting new patients with serious medical conditions, according to a British health reporter.


More information about the Infowarrior mailing list