The ransomware spreads using a set of exploits and uses the RSA-2048 encryption, which means that decryption will be next to impossible unless the coders have made a mistake. The ransomware demands a fee of $300 to decrypt or make the encrypted files readable or accessible again. A similar ransomware called WeCry was discovered back in February this year that asked victims for 0.1 in bitcoin to unlock their files and computer programs.
The ransomware also goes by the following names:
- "Wanna Crypt0r"
- "Wanna DeCrypt0r"
What is a ransomware?
Ransomware is a sophisticated piece of malware that blocks the victim’s access to his/her files or computers. The malware does this by encrypting or making all the files on the victims’ computers unreadable and then ask for money to decrypt or make the files readable again.
How does it work?
When a computer is infected, the ransomware typically contacts a central server for the information it needs to activate and then begins encrypting files on the infected computer with that information. Once all the files are encrypted, it posts a message (see below) asking for payment to decrypt the files – and threatens to destroy the information if it doesn’t get paid, often with a timer attached to put pressure on the victims to pay up quickly.
The Messages Displayed by the Wana Drypt0r 2.0 or Wana Drypt0r 2.0 Ransomware
How does it spread?
Most ransomware is spread using malicious Word documents, PDFs and other files normally sent via email, or through a secondary infection on computers already affected by viruses that offer a back door for further attacks.
What else can I do?
Consumers and businesses alike should be sure their systems and software are updated with all current patches in order to stop the spread of infection. Remember, once the ransomware has encrypted your files there is not a lot that can be done than to restore your files from a backup after removing the ransomware from your computer. Therefore, if your files are not backed up, they could be gone for good. This is why backing up of your files are very important.
Also, security researchers may be able to hack the encryption caused by the ransomware and create a tool to decrypt or make the encrypted files accessible again. But such situations are rare.
Click here to learn more about Ransomware and how to protect yourself against it.