Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 9 min read

From One Computer to a Global Epidemic: How WannaCry Spread Across Networks

May 12, 2017 First, one computer stopped working. Then a few more. Within hours, the same thing was happening in organizations around the world. In British hospitals, a red ransom note appeared on computer screens. Sy

From One Computer to a Global Epidemic: How WannaCry Spread Across Networks

WannaCry article cover

May 12, 2017

First, one computer stopped working. Then a few more. Within hours, the same thing was happening in organizations around the world.

In British hospitals, a red ransom note appeared on computer screens. Systems that had been used to care for patients that morning suddenly became unavailable. Some appointments and operations were cancelled; in other places, patients had to be redirected to other emergency departments. Staff at some facilities switched to paper records and phone calls because their usual computer systems no longer worked. But hospitals were only part of what was happening.

Several Renault plants in France halted production to prevent the infection from spreading further. Nissan facilities in the UK experienced problems. The attack affected Deutsche Bahn in Germany, Spain’s TelefΓ³nica, the US-based FedEx, Russian government organizations, and many other companies and institutions. All of this happened on the same day.

The same message appeared on computers everywhere. Files had been encrypted, and payment in Bitcoin was demanded to restore them. A countdown timer appeared on the screen: first, the time remaining before the ransom increased, and then a deadline after which the attackers threatened to destroy the decryption keys.

WannaCry ransom note

For someone staring at this screen, the situation looked simple enough: the computer was locked, the files were inaccessible, and someone was demanding money. But something else was far more frightening...

While employees were trying to restore their systems, infected computers were already searching for their next targets. WannaCry could spread without emails, downloaded files, or any action from the user. That feature allowed it to reach far beyond individual computers.

Within the first 24 hours, WannaCry had affected more than 230,000 computers in at least 150 countries.

How did the malware find other computers?

How did it know where to direct its attempts to infect them?

And how did an infection that started on one computer reach the networks of organizations around the world in just a few hours?

That is what we are going to explore.

A vulnerability that was already known

To understand how WannaCry could infect computers without user interaction, we need to go back a few months.

In March 2017, Microsoft released security update MS17-010. It fixed vulnerabilities in SMBv1, a Windows protocol that allows computers to share files and communicate with other devices over a network. One of these vulnerabilities would later play a key role in WannaCry’s spread. But the release of the update did not bring this story to an end.

In April 2017, the Shadow Brokers group published a collection of tools associated with the US National Security Agency (NSA). Among them was EternalBlue, an exploit that took advantage of an SMB vulnerability to execute code remotely on a vulnerable system. In other words, a tool for exploiting the vulnerability was now publicly available. It could be used by people other than those for whom it had originally been developed.

EternalBlue and SMB vulnerability illustration

Only one step remained before WannaCry: combine a way to infect systems remotely with a program that encrypts files and demands a ransom. And that is exactly what happened.

On May 12, 2017, WannaCry began spreading on a massive scale. It used EternalBlue to attack vulnerable Windows systems, then encrypted files on successfully infected machines and demanded payment to restore them. The remote-infection mechanism and the ransomware had been combined into a single piece of malware. Meanwhile, the patch for the exploited vulnerability had been available for almost two months before the attack.

But the availability of an update did not mean it had been installed on every computer. In large organizations, updating thousands of machines can require compatibility testing, approvals, and careful planning. Older systems might also remain in service without the necessary fixes. As a result, WannaCry exploited a vulnerability for which a patch already existed, while many computers remained vulnerable.

EternalBlue explains how WannaCry attacked a vulnerable system, but not how it found new targets.

To understand that, let’s look at how its spreading mechanism worked.

How WannaCry spread across networks

WannaCry did not have a list of computers it needed to infect. It searched for them itself, in two directions at once: inside the local network and beyond it. This mechanism allowed a single infected machine to become the starting point for a much larger attack.

Two directions of discovery

After launching, WannaCry identified the computer’s network interfaces and determined which subnets it was connected to. It then began checking addresses within those networks. At the same time, another part of the malware generated random public IPv4 addresses and attempted to find machines accessible from the internet.

According to Mandiant, the WannaCry sample examined by researchers used separate execution threads for these tasks: one handled the local network, while others scanned random internet addresses. The variant described by the researchers used 128 threads for external scanning. This allowed it to check many addresses in parallel instead of waiting for each attempt to finish before starting the next.

The difference between these two directions matters. On a local network, the malware could determine the address range connected to the infected computer. On the internet, it did not know in advance where vulnerable machines were, so it tried randomly generated public addresses.

For each address, WannaCry attempted to connect to TCP port 445. If the connection succeeded, it moved on to an SMB exploitation attempt. If it failed, that address did not lead to an infection. But even a successful connection was only the beginning. The accessible SMB service might belong to a computer on which the vulnerability had already been patched. In that case, this attack path would not work.

Network connection graph from Mandiant's technical analysis

Network-connection graph from Mandiant’s technical analysis

Network-connection graph from Mandiant’s technical analysis.

What happened after a successful attack

If the exploit succeeded, code was executed on the remote system, allowing the malware to be delivered to and launched on the target machine. In their technical analysis of WannaCry, researchers identified a mechanism that used components built into the sample to deliver an executable file to the target. After that, the newly infected computer could continue spreading the malware on its own.

It is important to distinguish between two events. First, WannaCry finds a computer it can reach. Second, it successfully exploits a vulnerability and runs code on that machine. Success is not guaranteed: many of the addresses it checks will not necessarily result in new infections.

But if the second stage succeeded, a new source of infection appeared. That computer would now scan addresses and attempt to infect other systems.

Why the infection could grow so quickly

Imagine not one long chain in which each computer has to wait for the previous one to finish. Infected machines worked in parallel. While one was checking available addresses, another could already be attacking a target, and a third could be searching for the next one.

This does not mean that the number of infections necessarily doubled every second. The outcome depended on whether machines were reachable, how quickly they responded, whether they were vulnerable, and whether exploitation succeeded. But each newly infected node could potentially add another source of scanning.

How WannaCry reached other organizations and countries

External scanning did not require the malware to know which country a target was in. It generated a public IPv4 address and attempted to connect to it. If the address belonged to a reachable system with SMB exposed and the vulnerability still unpatched, that machine could become the next victim.

Self-propagation diagram

Packets travelled through ordinary internet routing. Intermediate routers forwarded traffic according to their routing tables; from an IP packet alone, they could not determine that the connection was being used to spread WannaCry. Firewalls, NAT, and other restrictions could, however, make a target system unreachable from the outside.

The infection did not jump between countries as a separate process. A computer on one network found a reachable machine on another, infected it, and that machine continued searching for more targets. The next system could be in another organization, city, or country.

Geographical distance was not, by itself, an obstacle. What mattered was whether a network path to the target existed and whether the malware could exploit a vulnerable service on the other end.

The combination of two scanning directions, parallel attempts, and automatic propagation made WannaCry more than just ransomware: it was a network worm. It did not depend on how many users manually launched an infected file. Once a computer was successfully infected, it could become part of the ongoing spread.

How an unregistered domain helped stop the attack

On May 12, 2017, security researcher Marcus Hutchins was analyzing a WannaCry sample when he noticed an unusual detail: the malware’s code contained a long domain name that no one had registered at the time.

Usually, a domain embedded in malware might point to a server with which the program communicates. But this case was different. WannaCry checked whether the domain was reachable before continuing its execution. If the address did not respond, the malware continued running. If the domain could be reached, it stopped.

Marcus Hutchins

Marcus Hutchins.

Hutchins registered the domain. It cost around ten dollars. He was not trying to stop a global attack with a single action; initially, he wanted to understand what the address did and how it was connected to the malware. But after he registered the domain, it became clear that the check worked like a switch: new executions of this version of WannaCry that received a response from the domain would not continue with infection and encryption. Cloudflare and WIRED describe the discovery and its impact.

However, this did not mean the threat had disappeared. The mechanism worked only if an infected computer could reach the relevant domain. If access to it was blocked or otherwise unavailable, the malware could continue running. In addition, registering the domain did not decrypt files on computers that had already been affected, nor did it remove malware that was already on a system. Later, variants of WannaCry appeared with modified or missing checks, so one domain could not solve the problem permanently.

The epidemic is over. Or is it?

Some WannaCry victims still had a chance to recover their files without the attackers’ key. Researchers found that, under certain conditions, data needed to recover the key could remain in a computer’s RAM. The WannaKey tool was based on this principle. But it had a serious limitation: when a computer was shut down or rebooted, the contents of RAM disappeared. The necessary data could be lost, making it impossible to recover the key this way. The tool worked only under specific conditions, so it was not a solution for most victims.

Another option remained: paying the ransom. The screen showed an amount, along with the hope of getting documents, photos, and work files back. But no one could guarantee that the victim would receive a working key after transferring the money. According to public data, the attackers received around 52 bitcoins, worth approximately $140,000 at the time. Compared with the damage WannaCry caused to organizations around the world, that was a relatively small amount. The attackers also used just three addresses to collect payments, and reliably linking each transfer to a particular victim was difficult.

In the end, many organizations had to restore their systems and deal with the aftermath of the infection. Registering the domain helped stop the spread of the original version of WannaCry, but it could not undo what had already happened: it did not decrypt files or clean computers that had already been infected.

I believe this story matters to more than just information security specialists. WannaCry showed how a vulnerability that already had a patch, combined with automatic propagation, could have consequences for organizations around the world. It is not just the story of one piece of malware; it is an example of how a technical detail inside a program can affect the operation of entire systems.

But the story did not end that day. A year and a half after the attack, researchers were still recording requests to the WannaCry domain. This does not mean that every recorded IP address corresponded to a separate infected computer, but it shows that traces of the attack were still appearing on the network.

Now imagine that you have long since forgotten about WannaCry, while somewhere on a network, a computer is still running with a copy of it on board, repeatedly checking whether the domain is reachable.

And who knows how many such copies remain on devices that no one has thought about in years?

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.