Virus Alert - "Wana Crypt0r" or "Wana DeCrypt0r" Ransomware Attacks Shutting Down Computer Systems Worldwide
Would you share this Article with others?
The ransomware spreads using a set of exploits and uses the RSA-2048 encryption, which means that decryption will be next to impossible unless the coders have made a mistake. The ransomware demands a fee of $300 to decrypt or make the encrypted files readable or accessible again. A similar ransomware called WeCry was discovered back in February this year that asked victims for 0.1 in bitcoin to unlock their files and computer programs.
The ransomware also goes by the following names:
- "Wanna Crypt0r"
- "Wanna DeCrypt0r"
What is a ransomware?
Ransomware is a sophisticated piece of malware that blocks the victim’s access to his/her files or computers. The malware does this by encrypting or making all the files on the victims’ computers unreadable and then ask for money to decrypt or make the files readable again.
How does it work?
When a computer is infected, the ransomware typically contacts a central server for the information it needs to activate and then begins encrypting files on the infected computer with that information. Once all the files are encrypted, it posts a message (see below) asking for payment to decrypt the files – and threatens to destroy the information if it doesn’t get paid, often with a timer attached to put pressure on the victims to pay up quickly.
The Messages Displayed by the Wana Drypt0r 2.0 or Wana Drypt0r 2.0 Ransomware
How does it spread?
Most ransomware is spread using malicious Word documents, PDFs and other files normally sent via email, or through a secondary infection on computers already affected by viruses that offer a back door for further attacks.
What else can I do?
Consumers and businesses alike should be sure their systems and software are updated with all current patches in order to stop the spread of infection. Remember, once the ransomware has encrypted your files there is not a lot that can be done than to restore your files from a backup after removing the ransomware from your computer. Therefore, if your files are not backed up, they could be gone for good. This is why backing up of your files are very important.
Also, security researchers may be able to hack the encryption caused by the ransomware and create a tool to decrypt or make the encrypted files accessible again. But such situations are rare.
Click here to learn more about Ransomware and how to protect yourself against it.
Note: Some of the names, addresses, email addresses, telephone numbers or other information in samples on this website may have been impersonated or spoofed.
Please share what you know or ask a question about this article by leaving a comment below. Check the comment section below for additional information, if there is any. Remember to forward suspicious, malicious, or phishing email messages to us at the following email address: firstname.lastname@example.org. And, report missing persons, scams, untrustworthy, or fraudulent websites to us. Tell us why you consider the websites untrustworthy or fraudulent. Also, to quickly find answers to your questions, use our search engine.
You can help maintain Online Threat Alerts (OTA) by paying a service fee. Click here to make payment.
Comments, Questions, Answers, or Reviews
To help protect your privacy, please do not post or remove, your full name, telephone number, email address, username, password, account number, credit card information, home address or other sensitive information in or from your comments, questions, or reviews. Also, remember to keep comments, reviews, answers respectful.
Show More Comments (1)
Write Your Comment, Question, Answer, or Review
Write your comment, question, answer, or review in the box below to share what you know or to get answers. NB: We will use your IP address to display your approximate location to other users.