6 ms·
From what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a
by Nacraile 9y ago
From what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a mass phishing campaign.
See: https://arstechnica.com/security/2017/05/an-nsa-derived-ransomware-worm-is-shutting-down-computers-worldwide/ https://arstechnica.com/security/2017/05/an-nsa-derived-rans...
- Nrsolis 9y agoThe initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
- draugadrotten 9y ago> The initial attack vector is via an email attachment. So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.
- arkaine 9y agoThe Jaff waves and the massive amount of threats make it really hard to identify. Wannacrytor may not be found directly attached in the mail, only a downloader for it (like office docs/pdfs/js) might be.
- Nrsolis 9y agoThis might help: http://researchcenter.paloaltonetworks.com/2017/05/palo-alto-networks-protections-wanacrypt0r-attacks/ http://researchcenter.paloaltonetworks.com/2017/05/palo-alto...
- technion 9y agoWe quarantine a few hundred attachments a day containing Word macros. I don't know if any are WannaCry, but nearly all are some form of ransomware. It continues to be a very common attack method and I'd be surprised if it wasn't leveraged again.
- ethbro 9y agoGiven that the primary targets seem to be running unpatched Windows (at least to latest), I'd guess there's a substantial amount of internet-accessible SMB ports. If so, you wouldn't need a very high phish:total infected hosts ratio to explain the numbers. And given that whoever was originally phished didn't know it was an illegitimate email... not betting we'll see many examples of the initial vector.
- nthcolumn 9y agoWhy isn't the internet alive with the email subject line then? The email would be multi-lingual too?
- rickdg 9y agoSpear phishing is now a lot more effective.