Who so "wants to cry"?

45
On the eve it was announced that the virus attack, which put dozens of countries in the world, began to disappear. It's about the attack when using the encryption virus (aka extortioner virus) WannaCry, aimed not only at private user computers, but also networks of various companies and government ministries and departments. In Russia, WannaCry attacked computer networks of the Ministry of Health, the Ministry of Internal Affairs, MegaFon, Sberbank, Rostelecom, and other government agencies and institutions.

Let's talk in more detail about the damage done to one or another country and the security / insecurity of modern networks from such and other cyber attacks.



So, the WannaCry virus began 12 massive blows in May. Distribution activity is exponentially. The countries of the European Union, the USA, Canada, the Russian Federation, China, Japan, South Korea, Australia, India, Saudi Arabia, Turkey, Iran, Israel, and a number of Latin American countries were under attack. WannaCry even got to Iceland and Mongolia.

Who so "wants to cry"?


According to the latest data, the virus attack either bypassed or barely affected such countries as Turkmenistan, Kazakhstan, Afghanistan, Tajikistan, Papua New Guinea, North Korea and a number of African states such as Somalia, Chad, Mali, Botswana, etc. For rare exceptions in the list are countries in which the Internet is extremely underdeveloped, plus - a small number of computers and systems based on operating systems from the American company Microsoft. In general, the virus made its way to where there is, what to profit. Separate countries from such a list are still ignored.

The attacks were: the British healthcare system (a virus hit computers in nearly fifty British hospitals, and they were unable to perform electronic patient registration and remote consulting), the largest German railway operator Deutsche Bahn, the Spanish communication company Telefonica, US banks and cellular operators, Turkish companies tourism sector and many others.

It should be recalled that the May version of the encryption virus is a modification of the virus that has already managed to do a lot of dirty work on the Internet in the winter. To be fair, then the activity of the extortion coder was an order of magnitude lower. But, as you know, everything flows, everything changes, the virus has changed, having “expanded” so that a few countries did not come under its blow.

By the way, immediately after the virus got into the network, former US intelligence officer Edward Snowden announced that the virus-cipher virus had left the US National Security Agency laboratory at the time. In other words, they created a destructive computer program that gains access to personal computers and mobile devices, precisely in the depths of the special services of the United States.

The first thoughts about who launched WannaCry into the network were noted by representatives of the American and British political elites. And these considerations in the light of the latest hysteria associated with the ubiquitous Russian hackers have not gone further than the regular statements about the "guilt of Russia". They accused Russia again, despite the fact that Russia was among the countries that the virus attacked most actively and methodically. However, a couple of days have passed since the activation of the encryption virus, and a new version is being discussed in Western media. Moreover, this version, apparently, appeared after the West had carefully studied the map of “strikes” inflicted by WannaCry. Seeing that the virus did not damage the DPRK, they decided to hang all the "viral" dogs on Pyongyang and allegedly on some hacker group affiliated with Pyongyang. Even the name was reported - Lazarus Group, which was previously accused of attacks on the Sony network in 2014, as well as on the National Bank of Bangladesh, which last year lost approximately 80 million dollars after the hacker strike.

The virus affected computers and systems based on Windows OS, which did not pass through the updates. The largest number of such computers is in Russia and India (from all large countries with a large number of personal computers). This is exactly what experts at F-Secure, an anti-virus software company, claim. Representatives of the company say that the computers that run on Windows XP OS suffered the most damage from the virus. This system was no longer serviced by Microsoft some time ago, and no updates for it have been released for a long time. In connection with the activation of a virus that strikes non-upgraded operating systems, Microsoft was forced to urgently release several so-called patches (additions to make changes to certain system files) even for Ex-Pi.

However, it was not this that stopped the spread of the virus, but the work of British IT specialists; at least that's what is stated in news agency reports. One of them conducts online activities under the nickname of his microblog @MalvareTechBlog. He said that he had found some email address in the virus code (here is its full view: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com), to which the virus is constantly addressed. Next, @MalvareTechBlog and a colleague named Darian Hass registered the site with the same address name. This led to a significant decrease in the activity of the virus, which, according to these British, may soon recover due to the change of addresses of the circulation of virus components by cybercriminals.

What attracts attention? Despite the tremendous hype raised by "antivirus" companies and the Western media, the real economic damage from WannaCry is not as significant as one would expect. It turns out that extorting the banner that appears from the screen of an infected PC, from 300 to 600 dollars, the attackers were able to “get hold of” about 50 thousand dollars. As theft, it seems to be a considerable amount, but clearly not in the case when it comes to infecting computers almost all over the world.

This suggests that in fact those who launched WannaCry set themselves a slightly different task than dislodging funds from users. It’s too small for a hacker group that the West stubbornly connects with North Korea. Unless, of course, you convince yourself that in this way Kim III was trying to make money on a new service jacket for himself and on a supply of solyary for a ballistic missile wheeled tractor ...

It is important that the computer managed to spread to 150 states of the world and at the same time actively tried to “knock” on the PC of large companies, ministries and departments. In some places, they say, I got through ... Against this background, the dramatically increased number of user requests for MS Windows updates, as well as the equally dramatic increase in the number of downloads of antivirus programs and purchases of keys to them, attracts attention. If cybercriminals earned, as they say, 50 thousand dollars on gullible users, how much did Microsoft earn with anti-virus advocates? .. This information is not made public. Maybe with the intention that users suddenly wondered who it all was more profitable.
Our news channels

Subscribe and stay up to date with the latest news and the most important events of the day.

45 comments
Information
Dear reader, to leave comments on the publication, you must sign in.
  1. +8
    17 May 2017 05: 58
    The countries of the European Union, the USA, Canada, the Russian Federation, China, Japan, South Korea, Australia, India, Saudi Arabia, Turkey, Iran, Israel...

    Something tells me that in the latter case, the virus should still remain ...
    1. +3
      17 May 2017 08: 53
      Where is our answer and investigation? Nevertheless, they know who is to blame, even the Head of Miscrosoft blamed the CIA and the NSA for the global cyber attack, AND WHY ARE WE SILENT ???
      1. 0
        17 May 2017 09: 36
        Of course everyone knows. everyone is so smart. By the way, EVERYONE knows that the Russians intervened in the elections
    2. +2
      17 May 2017 10: 10
      The virus hit the software where employees at work do cool, and they rummage through the networks for fun.
      1. 0
        17 May 2017 11: 41
        In this case, there was no trojan
      2. 0
        19 May 2017 14: 58
        Quote: siberalt
        The virus hit the software where employees at work do cool, and they rummage through the networks for fun.

        There is no longer a virus, but the whole computer has spread:
        ... It is important that the computer managed to spread to 150 countries of the world ...
        wassat

        The author re-reads what he writes? Campaign - no. tongue
    3. The comment was deleted.
  2. +9
    17 May 2017 06: 21
    Yes, Billy is to blame, 100%. After XP, Microsoft released only frank shit to the market, many users around the world continued to use the "pig" until the last days. That's Uncle Gates and stimulated them to update the system. He also earned money on this. 50 thousand green - too small? So the chicken pecking at the grain. “Somewhere a shilling, and somewhere a pound. Billy became a crook, a crook and a rogue”
    1. +1
      17 May 2017 09: 38
      Piggy is a dumb obsolete system that does not work on modern equipment without patches.
      1. +4
        17 May 2017 09: 47
        but how much new virus does not work on pigs
        1. 0
          17 May 2017 10: 10
          Computers with pigs have suffered the most
          1. +1
            17 May 2017 10: 15
            corporate networks may have suffered, but at my home piggy is worth and do not care
            and no need to update antivirus
            1. 0
              17 May 2017 17: 10
              And how, on a new hardware still manages to put it without troubles with drivers ???
              1. 0
                17 May 2017 17: 12
                I’m not putting the coolest iron and there’s no problem
                troubles with the new software, which all asks for the window of the latest version and the explorer 10th. And I have the 6th explorer without a chance to upset ...
                1. 0
                  18 May 2017 16: 39
                  Quote: yehat
                  And I have the 6th explorer without a chance to upset ...
                  Oh my God. Monsieur knows a lot about perversions. Why not use third-party browsers like Opera or Firefox ?!
                  1. 0
                    18 May 2017 16: 44
                    you can use it, but
                    many programs need a stupid version of the explorer during installation
      2. +4
        17 May 2017 10: 36
        Quote: Kenneth
        Piggy is a dumb obsolete system that does not work on modern equipment without patches.

        XP - 32-bit; there were 64-bit corporate ones that were never brought to mind.
        Win 7 is a good OS, but by means of "information war" is omitted by "updates" to a fully spyware program ...
        Win 8 - sharpened for touch control with its "tiled" structure, for tablets in general ...
        Microsoft's latest "masterpiece" - Win 10! yes - a masterpiece ... it’s difficult to “kill”, it’s supposedly paid around, but there are a lot of chips and bells and whistles: you agree with them, and - up! - you get it almost for nothing, or even for nothing, and even with bonuses ... Doesn’t it suggest any thoughts? In addition, you won’t be updated in 10-ke, you will refuse some functions (feedback and control, geo-positioning, still there some things ... I forgot already ...) so the buns will break off! ... Question: who controls whom - are you a system, or is it you? Even Edge (browser) - just change the shell, and he himself - no, no! Rummaged in the functions of this Edge - it looks like a prog-spy, although it’s fast and nimble and indestructible ... like a real agent 007 is supposed to be!
        -----------------------
        ... which is typical - about once every 2,5 months - with the prohibition of updates! - in my Win 7, well, it doesn’t “crash” ... but the OS stops working! Dug in the reasons - some kind of third-party program crawls into the motherboard's BIOS (!!!) and cuts off the appeal to the page file! reset to factory settings (contact closure cmos) fixes everything! I strongly suspect that they are “politely” pushing me to Win 10 ...
        1. +1
          17 May 2017 11: 39
          Better 7 so far nothing has been done. For work
        2. +2
          17 May 2017 12: 38
          Put 7-ku, a pirate assembly from Oleg Gorsky, works like a clock.
          1. 0
            17 May 2017 17: 12
            I also use the OVGorskiy builds, both 7th and 10th. No problem.
      3. +3
        17 May 2017 17: 38
        at one time, the computer that controlled all the space systems will now not even open the page in Word .. I mean that the functionality of the programs has not changed much, they just stupidly overgrown with unnecessary in most surroundings, which devours resources.
        1. +1
          18 May 2017 16: 49
          I work actively with 1s-koy. here's how it can be programmed that only the header of the invoice document (without deciphering the contents) is processed in 8.3 in about 1500 lines
          for comparison, in 7-ke the code of approximately lines in 150-200 does the same.
          this is how programming develops everywhere. Programs grow wildly in size because programmers with terabytes of available resources have completely lost their shame.
          But I remember the times when the 15KB program was considered large.
    2. +2
      18 May 2017 00: 12
      Here is Uncle Gates and stimulated them to upgrade the system

      Turn on the brain.
      Why does a bill stimulate a system update? Some expenses the system has long been removed from maintenance.
      Well, about 50 thousand, I generally am silent. Probably for you, 80 billion is a number so unimaginable that you do not understand that it would be a loss at least for an hour to earn 50 thousand to beat. Got it, no?
      But Microsoft has considerable losses, linux is not affected by this virus, it is very possible that someone will leave Windows.
      1. 0
        18 May 2017 16: 40
        Windows as it was 90% of the market and will remain in the near future precisely due to the user-friendly interface and a wide variety of software. On Linux, without knowledge of console commands, there is nothing to do.
        1. 0
          23 May 2017 16: 48
          Who said? My wife doesn't know NOT ONE TEAM, however, nothing prevents to use linukh.
  3. 0
    17 May 2017 06: 51
    I didn’t install the update ..... I just missed the connection through the android, because the virus does not touch “andreyku”
    1. +2
      17 May 2017 10: 39
      Quote: Marmalade
      I didn’t install the update ..... I just missed the connection through the android, because the virus does not touch “andreyku”

      ... continue to be just as naive!
      Is there a smartphone? ... try disabling the "intrusive service" ... Unpleasantly surprised!
      1. 0
        17 May 2017 20: 10
        naivete naivety..but no one canceled brains and straight arms .. yes and this Android virus does not take !!!!
      2. +2
        18 May 2017 00: 15
        I don’t understand what you mean, this android virus does not infect
        In general, viruses that use buffer overflows in any OS component cannot, by definition, be multi-platform.
  4. +2
    17 May 2017 07: 33
    how much did Microsoft earn with anti-virus defenders? ..

    But this is really a question. For some reason, I was always sure that those who fight the viruses create them. Business and nothing more. But today it’s also a weapon. with mass destruction.
    1. +2
      17 May 2017 10: 15
      Kaspersky already fell into scandals when viruses came out of his laboratory, which they then treated
    2. +2
      17 May 2017 10: 48
      Quote: rotmistr60
      how much did Microsoft earn with anti-virus defenders? ..

      But this is really a question. For some reason, I was always sure that those who fight the viruses create them. Business and nothing more. But today it’s also a weapon. with mass destruction.

      So one day I got caught and "died" Panda ... for a long time they apologized, compensated and all that ... It seems, they earned again ...
      Similarly - with MacAfee, I almost got to prison; to "save" - ​​they "sewed" some obscene behavior there ... aggression ... or "attack" on the maid like StossCan ... like that!
  5. +2
    17 May 2017 09: 07
    Another thing surprises me. Today, even Swiss banks cannot hide the information, and to find out who went 50 thousand dollars such an insoluble problem? Apparently not, and the point here is definitely not extortionists.
    1. +1
      17 May 2017 09: 39
      Google bitcoin
  6. +1
    17 May 2017 09: 14
    Look at the root. Although I tested the vulnerability to WanaCry - Linux systems here, so far to no avail.
    1. +2
      18 May 2017 00: 17
      I checked the vulnerability to WanaCry here

      What for? Linuh cannot have this vulnerability ...
  7. +2
    17 May 2017 10: 46
    Cry, do not cry, but in order to use the Windows OS and Intel and AMD products, you will have to remain a colony and be transparent to the NSA.
    1. 0
      17 May 2017 17: 14
      Quote: iouris
      Windows OS and Intel and AMD products
      Well, what to do if nothing is better in terms of price / quality in the world is not developed.
  8. 0
    17 May 2017 13: 53
    Good to all. You can look at the problem from the other side. A certain group of universal people decided to kick everyone else on the topic “Think with your head and update on time, since we use such systems”, even the name WannaCry can be voiced as “Hug and cry”. And cue ball - this is a nice bonus for the labors. Just IMHO.
  9. 0
    17 May 2017 14: 57
    As for Israel, they suffered quite a bit. In our hospital, for example, the “seven” stands. I don’t know what the system administrator was doing there, but they turned off the Internet for several hours, the in-hospital lokalka worked properly. After a few hours, the Internet appeared, so I didn’t really feel it.
  10. 0
    17 May 2017 16: 36
    To whom it is profitable, leave a mark for subsequent espionage. The biggest trouble is that Microsoft crawled into Linux.
  11. 0
    17 May 2017 17: 39
    Windows updates are free, so talking about some benefit is weird. Antivirus companies are also not in favor, because WannaCry, taking advantage of the vulnerability, directly connected to the computer, without visiting sites and other things, bypassing all antiviruses. In this situation, everyone was stupid, except for the owners of Mac OS. If you look for a "cat", then this is Apple.

    With regards to money. Who counted? Not a single person in a serious office would ever think to scream that they had been hacked and user data could fall into third hands. They paid for the quiet and were silent.

    They talk about relations with North Korea, not only in the West, but also at Kaspersky Lab. Yes, and do not joke that in North Korea there is no Internet and computers. This group receives funding from the DPRK, and it can be located geographically, anywhere.
    1. 0
      17 May 2017 19: 39
      Kaspersky’s laboratory has already come across such “little things” and even this is one of the few Russian companies that are actively selling their product in the West, and not feeling bad. Therefore, they are lured and know their business, and most likely, for the sake of "common success," they can calmly go to any conspiracy.
      And based on the fact that the whole world is now intimidated by "Russian hackers" to arrange a similar provocation for Microsoft under the guise ... why not ... They don’t dump the OS, namely the files that users store ... Now, if they are the OS failed - then you can think about Apple and even Koreans, but here something is not purely real ...
      1. 0
        17 May 2017 21: 48
        They sell their products in the West, because the product is competitive, no? Name at least one domestic company with software that is in leadership positions and has advantages over foreign models? At the expense of scandals, never heard of.


        OS is not dependent on crashes or just coding, it still suffers. And at once you will not tell, that is worse. Just lose the OS, which can be restored, or all the data that can not be decoded. Anyway, the reputation suffers.
      2. +2
        18 May 2017 00: 19
        Kaspersky Lab has already come across such tricks

        Come on, am I missing something?
        Throw a reference ....
        1. 0
          18 May 2017 21: 33
          Google help, they wrote about this for a long time

"Right Sector" (banned in Russia), "Ukrainian Insurgent Army" (UPA) (banned in Russia), ISIS (banned in Russia), "Jabhat Fatah al-Sham" formerly "Jabhat al-Nusra" (banned in Russia) , Taliban (banned in Russia), Al-Qaeda (banned in Russia), Anti-Corruption Foundation (banned in Russia), Navalny Headquarters (banned in Russia), Facebook (banned in Russia), Instagram (banned in Russia), Meta (banned in Russia), Misanthropic Division (banned in Russia), Azov (banned in Russia), Muslim Brotherhood (banned in Russia), Aum Shinrikyo (banned in Russia), AUE (banned in Russia), UNA-UNSO (banned in Russia), Mejlis of the Crimean Tatar people (banned in Russia), Legion “Freedom of Russia” (armed formation, recognized as terrorist in the Russian Federation and banned), Kirill Budanov (included to the Rosfinmonitoring list of terrorists and extremists)

“Non-profit organizations, unregistered public associations or individuals performing the functions of a foreign agent,” as well as media outlets performing the functions of a foreign agent: “Medusa”; "Voice of America"; "Realities"; "Present time"; "Radio Freedom"; Ponomarev Lev; Ponomarev Ilya; Savitskaya; Markelov; Kamalyagin; Apakhonchich; Makarevich; Dud; Gordon; Zhdanov; Medvedev; Fedorov; Mikhail Kasyanov; "Owl"; "Alliance of Doctors"; "RKK" "Levada Center"; "Memorial"; "Voice"; "Person and law"; "Rain"; "Mediazone"; "Deutsche Welle"; QMS "Caucasian Knot"; "Insider"; "New Newspaper"