时间:2025-10-08 00:15:04 来源:网络整理编辑:綜合
When it comes to online currency, lulz just might outvalue Bitcoin. A unknown group of hackers is wo
When it comes to online currency, lulz just might outvalue Bitcoin.
A unknown group of hackers is working behind the scenes to restart the ransomware WannaCry, and one security expert believes the culprits this time around aren't who you think.
And neither is their motivation.
SEE ALSO:It won't be easy for WannaCry hackers to get their cashContrary to what you might expect, it appears not to be the initial group responsible for WannaCry now working to startle the ransomware monster awake from its slumber. Rather, we may have some internet randos to thank.
Why? The leading theory, proposed by security researcher Marcus Hutchins, suggests it's all about shits and giggles.
WannaCry rushed onto the international scene on May 12, infecting and encrypting hundreds of thousands of computer systems running unpatched Windows operating systems. The ransomware demanded that victims pay around $300 in the cryptocurrency Bitcoin to their attackers if they ever wanted to see their files again.
"Yeah, it's most likely scriptkiddies doing it for lulz."
Some paid up, but computers stayed encrypted.
And while the damage was bad — England's National Health Service was hit particularly hard — it could have been a lot worse. The ransomware -- which utilized a stolen NSA exploit called EternalBlue -- stopped spreading when Hutchins registered a mysterious domain he discovered in the malware code and sinkholed it.
Hutchins explained the process on his blog, noting that "a sinkhole is a server designed to capture malicious traffic and prevent control of infected computers by the criminals who infected them."
The ransomware, it seems, was designed to contact Hutchins' domain before it spread to the next victim. Hutchins' registration of that domain created a kind of kill switch — effectively telling WannaCry to stop spreading.
As long as that domain, and one other discovered and sinkholed by a different researcher, remain up and active the ransomware won't spread. Which brings us back to our lulz-pirates.
Hutchins has observed an intentional distributed denial of service attack aimed at his domain with the apparent goal of knocking it offline. Wiredreports that the traffic appears to be coming courtesy of the Mirai botnet — the same botnet, comprised of IoT devices like wireless security cameras, that brought down parts of the internet in the fall of 2016.
Tweet may have been deleted
Why would anyone do this? Could the initial WannaCry developers simply want more computers infected with the hope of making more money? Probably not.
As Hutchins confirmed via Twitter direct message, the initial attackers can't appear to even keep up with the volume of decryption requests they've already received.
"[The] decryption system is stupid and completely unscalable," he observed.
In other words, infecting more computers won't exactly translate to more Bitcoin in their wallets. That leaves another possibility: someone just looking to mess with people.
"Yeah, it's most likely scriptkiddies doing it for lulz," Hutchins further speculated — using a term that refers to relatively low-skilled hackers.
So there you have it. If someone manages to knock Hutchins' sinkhole offline, allowing WannaCry to spread further in the process, you'll likely have some random prankster with a messed up sense of humor to thank.
But don't stress about it too much. "The DDoS is unlikely to be successful," reassures Hutchins.
Phew. Now if only Hutchins could solve our other internet security problems.
TopicsCybersecurity
Nate Parker is finally thinking about the woman who accused him of rape2025-10-07 23:48
歸來!莫伊塞斯曬隔離酒店視頻:我已回到中國2025-10-07 23:25
U23國足主帥:對亞運會有信心 超齡球員已入隊適應2025-10-07 23:14
真升降機 !富勒姆時隔一賽季重返英超 近5年3升2降2025-10-07 23:11
Mall builds real2025-10-07 22:56
廣州隊遭全麵壓製 !全場僅1腳射門 控球率不足三成2025-10-07 22:47
京媒:5球不敵浦和 泰山青年軍上了一堂生動的技術課2025-10-07 22:41
亞洲杯+亞冠官方 :於大寶生日快樂 不可多得的鋒衛搖擺人2025-10-07 22:08
What brands need to know about virtual reality2025-10-07 21:48
浙江隊主帥 :不用擔心球隊備戰情況 新賽季會全力以赴2025-10-07 21:35
Major earthquake and multiple aftershocks rock central Italy2025-10-08 00:14
日媒曝海港前鋒洛佩斯或加盟廣島三箭 新援到隊後位置尷尬2025-10-08 00:03
朗尼克確認曼聯半數主力缺戰利物浦 B費遇車禍無礙2025-10-07 23:55
蔚山主帥參加賽前發布會 :還沒有決定對陣廣州隊的首發2025-10-07 23:44
Is Samsung's Galaxy Note7 really the best phone?2025-10-07 23:32
粵媒評中超隊亞冠表現 :慘敗不可怕 怕的是無意義的慘敗2025-10-07 23:32
朗尼克談曼聯引援:打造強隊不難 但瞎搞永遠不行2025-10-07 22:16
薑祥佑 :我能勝任很多位置 在韓國人氣也不差2025-10-07 22:13
Two astronauts just installed a new parking spot on the International Space Station2025-10-07 22:07
英媒專欄吹爆渣叔:夥伴、羈絆 一起踏上四冠之旅2025-10-07 21:33