WannaCry Ransomware Protection

Protect your business against the WannaCry ransomware worm.

What is WannaCry Ransomware?

WannaCry (also known as WannaCrypt, WanaCrypt0r 2.0, or WannaDecryptor) is a ransomware variant that emerged in a massive outbreak on Friday, May 12 2017, spreading to infect over 200,000 computers across 150 countries in a matter of days. Like typical crypto-ransomware, WannaCry encrypts victims’ files and demands a ransom in exchange for a decryption key. However, WannaCry is unique in its ability to self-propagate without relying on traditional malware attack vectors like phishing emails or drive-by downloads.

How Does WannaCry Spread?

WannaCry self-propagates by exploiting a critical severity non-zero-day vulnerability in various Microsoft operating systems known as MS17-010 (CVE-2017-0144), which enables remote code execution against Microsoft Server Message Block 1.0 (SMBv1). Once it infects a machine, WannaCry behaves like a worm, scanning networks for vulnerable systems with port 445 open to further spread.

How to Protect Against WannaCry Ransomware

Patch all software, particularly any systems containing the MS17-010 vulnerability – Microsoft has released a patch for vulnerable legacy systems including Windows XP and Windows 2003
Disable SMBv1
Back up critical data to a secure, offline location
Educate employees on what to do if they are infected

