openPR Logo
Press release

WannaCry might be the tip of the iceberg

06-06-2017 04:18 PM CET | IT, New Media & Software

Press release from: OAK Consulting FZC

Rick Holland, Vice President, Strategy, Digital Shadows

Rick Holland, Vice President, Strategy, Digital Shadows

Comment Article by Rick Holland, Vice President, Strategy, Digital Shadows

The attack on 200,000 plus computers across more than 120 countries around the world by the WannaCry ransomware certainly got the attention of governments, media, consumers and law enforcement. But the actual impact could have been so much worse.

Much ink is still being expended trying to determine who was responsible and what their motives were and many believe this might have been the act of inexperienced hackers who lost control of their creation. Certainly, at the time of writing, none of the ransom has been collected from the bitcoin accounts victims were encouraged to send their money too.

But while WannaCry could have been so much worse in impact, what is clear is that the base exploit code it uses was part of a batch stolen by Shadow Brokers in April 2017 from the US National Security Agency’s (NSA) Equation Group and potentially last month’s attack could be just the tip of the iceberg.

Earlier in May 2017 CERT EU (The EU’s Computer Emergency Response Team) reported on a worm identified in the wild which has reportedly spread using exploit code leaked by Shadow Brokers in a similar fashion to WannaCry. CERT EU referred to this malware as "BlueDoom", but its internal name was reportedly "EternalRocks".

In addition to the EternalBlue Server Message Block (SMB) exploit used by WannaCry, EnternalRocks has reportedly also employed at least three additional exploits leaked by the Shadow Brokers: EternalChampion, EternalRomance and EternalSynergy as part of its propagation process.

All three of these exploits were developed to target SMB remote code execution vulnerabilities in Windows XP, all of which were patched in Microsoft's Apr 2017 MS17-010 release. However, unlike WannaCry, following a successful exploitation and subsequent deployment of the DOUBLEPULSAR backdoor on an infected machine the malware has reportedly not deployed any additional payload.

Why no payload is being deployed is unclear but we can speculate that EternalRocks was likely intended to be used to establish a presence on a large number of machines in order to facilitate the deployment of second-stage payloads sometime later. What that payload might be and what its function is are not clear and it remains to be seen how the actors responsible for developing this worm will exploit their access to infected machines.

What is clear is that this development highlights that the Eternal suite of Equation Group exploits and other technical assets leaked by the Shadow Brokers will almost certainly continue to pose a threat beyond WannaCry. Users and organizations which have not already implemented the relevant Microsoft patches and mitigations on the back of EternalBlue are advised to do so quickly.

Digital Shadows provides insight into an organization’s external digital risks and the threat actors targeting them. The Digital Shadows SearchLight™ service combines scalable data analytics with human analysts to monitor for cyber threats, data leakage, and reputation risks. Digital Shadows continually monitors the Internet across the visible, deep and dark web, as well as other online sources to create an up-to-the minute view of an organization and provide it with tailored threat intelligence. The company is jointly headquartered in London and San Francisco. For more information, visit www.digitalshadows.com.

Conrad Offices, 19th Floor
Sheikh Zayed Rod, Dubai

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release WannaCry might be the tip of the iceberg here

News-ID: 565155 • Views:

More Releases from OAK Consulting FZC

FarEye launches its Delivery Experience Suite – ‘Delight’
Dubai, United Arab Emirates, July 5, 2018: FarEye, a leading global digital logistics platform today announced the launch of its Delivery Experience Suite – ‘Delight’ that helps businesses increase their Delivery Happiness Score – the ultimate measure of customer success. It enables businesses to provide a seamless and personalized experience to the customers. FarEye is a leader in B2C logistics technology and is widely used by global giants like Walmart, DHL,
FarEye expands its footprint in the European market with the launch of its regio …
Dubai, United Arab Emirates, June 24, 2018: FarEye, a leading global digital logistics platform, today announced the opening of its first European office in the heart of London with an aim to expand its business foothold in the region and to serve its customers directly. With a total of 6 corporate offices in India, Dubai and Singapore, FarEye currently serves customers in over 20 countries. FarEye has revolutionized the logistics
Digital Shadows announces its Digital Risk Management Technology Ecosystem
Digital Shadows announces its Digital Risk Management Technology Ecosystem
Dubai, UAE, October 24, 2017 – Digital Shadows, the industry leader in digital risk management, today announced the launch of its Digital Risk Management Technology Ecosystem. Formed from almost a dozen technology companies, with more expected to join in the coming months, they all share a vision for how security analytics and security information and event management (SIEM), product orchestration and automation, risk & compliance, intelligence and network enforcement, must
Ring partners with Al Jammaz to provide smart home security for Saudi Arabia
Riyadh, Saudi Arabia – October 18, 2017: Ring, the leader in smart home security recently announced a partnership agreement with Al Jammaz Distribution, the leading Saudi based Value-Added Distributor, which distributes advanced technology products, solutions and services. This partnership will help Ring foray and expand its reach across the Saudi market offering customers Ring’s innovative home security products and solutions. “Ring believes in keeping homes and communities safe rather than

All 5 Releases


More Releases for Shadow

Shadow X Drone Reviews 2024: Everything You Need To Know About Shadow X Drone. N …
Shadow X Drone Reviews 2024: Everything You Need To Know About Shadow X Drone. New Information About Shadow X Drone 2024 For USA Users. The Shadow X Drone has revolutionized the world of photography and videography, offering enthusiasts and professionals alike an unparalleled tool for capturing breathtaking moments from unique aerial perspectives. With its cutting-edge technology, this drone delivers stunning full HD video quality, allowing users to explore new angles
Lazarus - a white shadow
The eminent Japanese Butoh dancer Tatsumi Hijikata once said: "Butoh is like a corpse that rises to life again and again". With "Lazarus, a white shadow", Munich-based Butoh dancer Stefan Maria Marb seeks a body-poetic approach to death. In this archaic journey of remembrance, Marb stages the resurrection of a loved one and, together with fellow musicians, processes personal moments, gratitude and pain into a touching dance and music performance. Marb learned
"Shadow Acting": A Modern Exploration of Relationships
Lawrence "LAW" Watford presents "Shadow Acting," a captivating drama set against the backdrop of New York City's bustling streets. Departing from traditional narratives, this film delves into the intricate dynamics between genders within the intimate confines of a black box theater. At its core, "Shadow Acting" follows Stella, portrayed by the talented Genia Lear Morgan, an aspiring acting student navigating the challenges of her craft under the tutelage of the demanding
Shadow Banking Market Showing Strong Growth Dynamics
Latest Global Shadow Banking Market Report released by HTF MI evaluating the market risk side analysis, highlighting opportunities, and leveraging strategic and tactical decision-making support. The report provides information on market trends and development, growth drivers, technologies, and the changing investment structure of the Global Shadow Banking Market. Some of the key players profiled in the study are BlackRock (United States), The Vanguard Group (United States), State Street Corporation (United
Shadow X Drone Reviews 2024: An Upgraded Shadow X Drone Available Now.
Shadow X Drone Reviews 2024: An Upgraded Shadow X Drone Available Now. Shadow X Drone stands as a testament to the transformative power of drones in the realm of photography and videography. For seasoned drone enthusiasts, it's a gateway to capturing the world's beauty from previously unattainable angles, offering a perspective that transcends the limitations of conventional cameras. With its unparalleled ability to shoot high-quality videos enriched with unique features, Shadow
The Shadow of Giants
NEWS PROVIDED BY The Shadow of Giants March 31, 2023, 00:00 GMT. Gerald Ciccarone The Shadow of Giants (603) 781-6657 ryce747@yahoo.com We are excited to announce the upcoming release of "THE SHADOW OF GIANTS," a new novel by author Gerald Ciccarone that promises to captivate readers with its unique blend of suspense, drama, and thought-provoking themes. One of the standouts features of this book is the author's writing style and technique. Gerald Ciccarone has a way of crafting