416-296-0055

NetwynNetwyn

  • Home
  • About
  • Services
  • Blog
  • Contact Us

WannaCry Ransomware: Dangerous Strain called “Eternal Rocks” discovered by Researchers

Tuesday, 23 May 2017 / Published in Blog

WannaCry Ransomware: Dangerous Strain called “Eternal Rocks” discovered by Researchers

Just as the reverberations from the WannaCry ransomware outbreak earlier this month have started to slow, a new strain has already cropped up. On Sunday, researchers confirmed the new strain of malware called “EternalRocks”.

 

Already determined to be more dangerous than WannaCry and tougher to fight.

 

According to researchers, this worm that combines 4 NSA exploits, including the same vulnerability that helped WannaCry spread to computers.

 

EternalRockWannaCry

Earlier this month, the WannaCry ransomware attack plagued hospitals, schools, and offices around the world. It spread to more than 250,000. With the use of two NSA exploits released by Shadow Brokers, Eternal Blue and Double Pulsar. A few days later, researchers discovered Adylkuzz, using the same exploits, created botnets to mine from cryptocurrency.

 

And now, there’s EternalRocks. Miroslav Stampar, a cybersecurity expert for Croatia’s CERT, captured a sample of the worm in a Windows 7 honeypot that he runs.

 

 

EnteralRocks2EternalRocks

The majority of the tools used an exploit with the standard file sharing technology used on PC’s called Microsoft Windows Server Message Block. This is how WannaCry spread undetected and so quickly. Microsoft patched these vulnerabilities in March, however there are many systems still at risk.

 

 

 

 

Unlike Wannacry – which alerts victims that there computers have been infected – EternalRocks remains hidden and quiet. Once in a computer, it downloads Tor’s private browser and sends a signal to the worm’s hidden servers.

 

For, 24 hours, EternalRocks does nothing, just waits.  

 

But after a day, the server responds and starts downloading and self-replicating.

 

What does that mean, exactly?

 

EternalRocks stays a day ahead of security experts.

 

“By delaying the communications the bad actors are attempting to be more stealthy,” Michael Patterson, CEO of security firm Plixer, said. “The race to detect and stop all malware was lost years ago.”

 

It even names itself WannaCry in an attempt to hide from security researchers, Stampar said. Like variants of WannaCry, EternalRocks also doesn’t have a kill-switch, so it can’t be as easily blocked off.

 

For the time being, EternalRocks remains dormant as it continues to spread and infect more computers. Stampar warns that the malware can be weaponized at any time, in the same fashion that WannaCry’s ransomware struck all at once.

 

To learn more about how you can protect your business from cyberattacks, contact Netwyn today.

  • Tweet

What you can read next

Fraud Blitz: Amazon Third-Party Sellers hit by Hackers
Best Social Engineering Attacks of All Time: Why Technology alone can’t keep you safe
Google’s Trips might just be the best traveling companion

Recent Posts

  • Google Jamboard

    The Google Jamboard is a tool developed by Goog...
  • Google Drive is making it easier to backup all your files

    If you don’t have an offsite cloud storage plan...
  • Google’s teaching kids how to fight trolls and hackers with Interland

    “Google is launching an educational progr...
  • Website Design Fails that your Business Is Probably Making

    Creating a new website or redesigning your exis...
  • Google I/O 2017: Live blog, Live steam and What to Expect

    Google I/O is Google’s annual developer confere...

Useful Links

  • Home
  • About
  • Services
  • Blog
  • Contact Us

Services

  • Website Design & Development
  • WordPress Website Development
  • eCommerce Website
  • Search Engine Optimization
  • Shopify Website Development
  • CMS Website Development
  • Responsive Web Design
  • Logo Design
  • Office space

FOLLOW

  • Our Blog
  • Facebook
  • Twitter
  • LinkedIn

Contact Us

10 Thornmount Drive
Toronto, Ontario
M1B 3J4, Canada

+1 416-296-0055

© 2018 Netwyn

TOP