What is WannaCrypt Ransomware?
WannaCrypt Ransomware,
also known by the names WannaCry, WanaCrypt0r or Wcrypt is a ransomware
which targets Windows operating systems. Discovered on May 12, 2017, WannaCrypt was used in a large Cyber-attack and has since infected more than 230,000 Windows PCs in 190 countries.
How
does WannaCrypt ransomware get into your computer?
As evident from its
worldwide attacks, WannaCrypt first gains access to the computer system
via an email attachment and thereafter can spread rapidly through your LAN network. The ransomware can encrypt your systems hard disk and attempts to exploit the SMB vulnerability to spread to random computers on the Internet via TCP port and between computers on the same network.
The best thing you can do it to avoid clicking on any attachments sent
to you via email, even if they appear to be legitimate!
Although
the first wave of this ransomware was stopped, we are already seeing new
variations of it hitting computers around the world. Be sure your systems are consistently backing up. If you are unsure, contact your assigned IES agent.
Lastly, if you
see the message below - or a similar one - it’s already too late for
you. IMMEDIATELY SHUT DOWN YOUR COMPUTER and call IES at 781-816-9437.
We want to alert you to a very
urgent threat to the data on your network called Cryptowall / Cryptolocker.
You should immediately advise your staff to not open ANY files that are sent to you through e-mail. This new virus/trojan arrives as an
e-mail that contains a zip, doc, xls, or pdf file that pretends to be an invoice, purchase
order, bill, complaint, UPS or USPS shipment or other business
communication. If you receive such a message, you should verify with the
sender that they did in fact send this message prior to opening the attachment.
This threat is specifically designed to defeat firewalls, anti-virus and
anti-malware software. There is presently no known way to block these
threats. If you open such an attachment, you won't even know you have
been infected until you attempt to access data on your network. Once
infected, your critical data is inaccessible and current recovery steps are
time consuming and expensive. We cannot stress the severity of this
threat enough.
We are actively monitoring this situation and working with our security
partners to implement updates as soon as they are available. In
the meantime, we recommend that you and your team adopt a very conservative
posture toward this threat by not opening any e-mail attachments you have not
personally verified. We expect this threat to remain active for the
foreseeable future.
If you have any questions or concerns related to this, please do not hesitate
to contact our office.
IES, Inc.
781-816-9437
www.iesAdvisors.com