WannaCry ransomware could still wreak havoc if there’s an internet outage

(Image credit: Pixabay (no attribution needed))

Remember WannaCry, the annoying piece of ransomware that spread quickly and especially disrupted hospitals in the UK before being contained? Well, as it turns out, there are potentially hundreds of thousands of PCs that are still infected with WannaCry.

Ransomware is a type of malware that encrypts a user's files and holds the data hostage until a ransom is paid, often times in Bitcoin. In many cases, there is a time limit imposed, after which the user's files get permanently deleted.

WannaCry is a specific piece of ransomware that made headlines in 2017 because of how quickly it was able to spread, and the damage it caused—hospitals in the UK had to shut down some of their non-emergency services as they dealt with the outbreak. The ransomware also went by a few other similar names, including WannaCryptor, WannaCrypt, and Wanna Decryptor.

The accidental discovery of a so-called kill switch stopped WannaCry from spreading within a few days of its discovery, as Wired explained at the time. A malware expert who goes by the name MalwareTech worked to reverse engineer WannaCry, and in the process he discovered that its programmers coded the ransomware to ping a specific URL.

Curious, he registered the domain for $10.69. In the process, he effectively shut down WannaCry—it turned out that WannaCry would only spread if the URL in question is unregistered and inactive. Once it became active, WannaCry stopped trying to infect additional PCs.

The registration of the domain effectively neutralized WannaCry, but didn't get rid of it altogether. Jamie Hankins, head of security and threat intelligence researcher at Kryptos Logic, explained in a recent Twitter thread WannaCry infections continue to ping the aforementioned domain, which is now hosted by Cloudflare.

"In the last 24 hours we saw 2,713,752 beacons from 220,648 unique SrcIPs to the kill switch from 184 different countries," Hankins says.

The numbers balloon if looking at the past week, in which Hankins says there have been over 17 million pings from almost 640,000 unique IP addresses across 194 countries.

Hankins disclaims that the numbers are likely not 100 percent accurate because of the difficulty in tracking and collecting this kind of data, but even if it's in the ballpark, it's somewhat concerning.

"The fact that so many computers are still infected with this malware is a major problem. All you need is an internet outage to occur and for the kill switch domain to no longer be accessible for the ransomware to kick in," Bleeping Computer explains.

To prevent this from happening, Kryptos Logic built a free service called TellTale that enables organizations to monitor their range of IP addresses for known infections, including "WannaCry and a range of other potential threats."

It's not clear how many organizations have taken advantage of the service, but given the data, it seems like something companies should look into doing.

Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Hardware
MSI RTX 5070 Ti Gaming Trio OC Plus graphics card under a red light
This MSI Afterburner file unlocks 36 Gbps RTX 50-series memory overclocks for, y'know, the few people that actually own a card
A Steam Deck with SteamOS running in desktop mode.
A new and improved desktop experience just landed on Steam Deck and SteamOS is readying 'support for non-Steam Deck handhelds'
The Cherry Xtrfy K4V2 TKL gaming keyboard on top of a mouse pad depicting a nebula. The keyboard is grey with red accent keys, a grey braided wire, and the bright RGB lights switched on.
Cherry Xtrfy K4V2 TKL review
A "sensor-actuator–coupled gustatory interface chemically connecting virtual and real environments for remote tasting," or essentially a virtual reality tongue in an artificial mouth
Would you like to taste fish soup in VR? Me neither, but this electronic tongue does it anyway
Razer DeathAdder V3 Pro gaming mouse on a blue background
The DeathAdder V3 Pro is currently so cheap it's put the usually more affordable HyperSpeed version out of a job
MSI RTX 5090 Suprim SOC graphics card on a grey background with a gradient
MSI RTX 5090 Suprim SOC review
Latest in News
Image for
Rise of the Ronin's PC troubles continue as players report disappearing saves on Steam
Former Treyarch studio co-head and Black Ops 3 director is heading up a new first-party PlayStation studio
Metro Exodus
'I want to raise this glass to our fans, to our community': 4A Games celebrates Metro 2033's 15th anniversary and hints at next Metro game
Assassin's Creed Shadows promo image
Ubisoft reportedly has an anti-harassment plan in place for Assassin's Creed Shadows developers
Avowed Kai holding out his hand toward camera while explaining something to the player.
Avowed's new patch just gave you 6 more talent points to muck around with, along with a heap of fixes and improvements
In-game recreation of iconic Indiana Jones stealing the idol in Indiana Jones and the Great Circle
Silent Hill 2 remake and Indiana Jones are at historically low prices this Steam Spring Sale—so long as you don't buy them directly from Steam