Case Study - Ransomware
WannaCry Ransomware Attack
Year – 2017
Estimated Economic Losses – US$4–8 billion
Systems Affected – 200,000+ computers
Type of Attack – Ransomware Attack | Self-Propagating Cryptoworm
Suspected Group / Organization – Associated with the Lazarus Group
Suspected Group / Organization – Associated with the Lazarus Group
Detailed Working
WannaCry exploited a vulnerability in the Windows SMB protocol using the EternalBlue exploit. After compromising a vulnerable system, the ransomware encrypted files, displayed a Bitcoin ransom demand, and automatically scanned the network for other vulnerable systems, allowing it to rapidly spread across organizations worldwide.
Forensic Investigations
Investigators used malware reverse engineering, network traffic analysis, system log examination, and host forensics to study WannaCry’s behavior and propagation. The investigation identified EternalBlue exploitation, suspicious SMB traffic, encrypted files, malware artifacts, and the kill-switch domain, while code analysis and threat intelligence contributed to the attack’s attribution.