https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

From the Industry


Sponsor Content

image

What MSPs Can Learn from WannaCry Ransomware

  • July 28, 2017
WannaCry was so successful because it hit many computers that were connected only to an internal network--not the internet—and thus were erroneously assumed to be safe from ransomware attacks. This should remind MSPs that overlooked or obscure system vulnerabilities can quickly become virulent attack vectors.

It’s highly unlikely that any criminals driving the current ransomware epidemic are familiar with old-time baseball player Wee Willie Keeler, or his famous advice to “hit ‘em where they ain’t,” but the recent success of the WannaCry ransomware cryptoworm suggests some crooks are unwittingly embracing that batting tip. More to the point, it should remind MSPs that overlooked or obscure system vulnerabilities can quickly become virulent attack vectors.

Specifically, WannaCry’s perpetrators did not rely on the traditional (and thus more easily anticipated and blocked) tactic of phishing to spread their infection; instead they “hit ‘em where they ain’t” by employing a network worm approach that exploited file sharing vulnerabilities in the Server Message Block (SMB) protocol in Windows.

The result was the most successful ransomware ever released. The WannaCry attack began on May 12, 2017, and in less than 30 minutes almost a quarter million machines had been infected (see Figure 1):

Figure 1: WannaCry ransomware spread at record-breaking pace.

Within one day, it was reported to have infected more than 2 million computers in over 150 countries. Below is the image that WannaCry victims were confronted by on their screens. (Note that the perpetrators went to the trouble of also changing the user’s desktop background.)

Figure 2: WannaCry victims encountered typical demand for Bitcoin payment.

It’s likely that some of WannaCry’s victims were particularly startled to see this infection, as it’s quite possible that no users had touched the infected machine recently. Because WannaCry victims are infected from other computers on the network internally, or from outside systems that were scanning telnet for SMB running on the machine, any protections against previous ransomware strains that are propagated through the internet were ineffectual.

To its credit, Microsoft patched this vulnerability dating back to fall of 2016. Microsoft was already warning users to disable SMB1, but as these infection rates show, many people did not install the patch.

WannaCry was extremely prolific because it hit so many machines that weren’t considered vulnerable to previous ransomware strains; these computers were only connected to an internal network—but not the internet—and thus were erroneously assumed to be safe from ransomware attacks.

The consequences of that erroneous assumption were devastating:

  • 61 NHS organizations in Great Britain were disrupted, forcing them to turn away patients as their unpatched systems were infected, thus rendering key machines (MRI, X-ray, lasers, blood analyzers, etc.) inoperable.
  • Some Renault automobile factories had to halt production.
  • Telecoms, along with power and gas utility companies, in Spain were hit, with employees being told to just “turn off the computers.”

Thanks to the efforts of U.K. researcher MalwareTech, a “kill switch” hard-coded within WannaCry was discovered, effectively stopping the ransomware in its tracks because there were specific domains in the code that would prevent it from executing if it connected to those domains. Webroot quickly ensured those kill switch domains were categorized and allowed, but obviously this prevention measure didn’t last long, as many variants are now constantly changing the kill switch addresses or just removing them altogether.

The most effective protection measure is to immediately apply the patches that Microsoft has released for all currently supported Windows versions. Within four days of the initial outbreak, security experts said, most organizations had applied those updates and new infections had slowed to a trickle.

Key Takeaway: Secure Every Opening, However Obscure

MSPs know well that keeping up with the seemingly endless stream of patches and updates can be challenging and time-consuming, but the WannaCry saga clearly illustrates the enormous costs that you and your clients could suffer if patches are overlooked. Security vulnerabilities can arise from many sources, both obvious and obscure, and your best defense is to block them all.

Guest blogs such as this one are published monthly and are part of MSPmentor’s annual platinum sponsorship.

 

 

Tags: Agents Cloud Service Providers MSPs VARs/SIs From the Industry Strategy Webroot Sponsor Content

Most Recent


  • Trophy
    Channel Partner Awards: SolarWinds, GoTo, Darktrace, Juniper Networks, IGEL, More
    Schneider Electric, Varonis and more also handed out awards.
  • people chains
    Vernick, Jones Join Upstack Leadership Team, Reject 'Roll-Up' Stereotype
    "The writing is on the wall. The superagent is the evolution of this channel," J.R. Vernick told Channel Futures.
  • Cloud
    Ingram Micro Earns AWS Migration Competency, Helps Partners Migrate Workloads
    The distributor said it will assist partners to “accelerate the customer cloud adoption journey.”
  • Baseball swing
    VMware Partner Connect Now in Full Swing Worldwide
    "This is the complete end state” of VMware’s channel program, per Tracy-Ann Palmer, and will hold for years.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • 5G
    5G: Revolution or Evolution?
  • M&A
    Why All MSPs Need to Understand the M&A Landscape
  • hurricane season
    4 Things MSPs Should Consider When Prepping for Hurricane Season
  • zero-trust
    The Benefits of Zero-Trust Security over VPNs

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Partner Awards: SolarWinds, GoTo, Darktrace, Juniper Networks, IGEL, More

March 21, 2023

Vernick, Jones Join Upstack Leadership Team, Reject ‘Roll-Up’ Stereotype

March 21, 2023

VMware Partner Connect Now in Full Swing Worldwide

March 20, 2023

Industry Perspectives

View all

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

How Hybrid Work Poses Major Cybersecurity Risks

March 1, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

When it comes to cybersecurity 🔒, these 20 leaders represent the future of the channel. Who do you think made the l… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

.@Vonage has introduced two new tools (Vonage Meetings API and Proactive Connect) to help facilitate digital transf… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

Upstack's newest CX leaders say their appointment is a sign of Upstack's agent-friendliness. dlvr.it/SlDvMV https://t.co/srsiKpzJ7K

March 21, 2023
ChannelFutures

With the @awscloud Migration Competency, @IngramMicroInc will help partners to “accelerate the customer cloud adopt… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

.@HPE acquiring @OpsRamp to add capabilities to @HPE_GreenLake. #cloud dlvr.it/SlCFz9

March 20, 2023
ChannelFutures

The relationship between technology advisor (agent) firms, technology service distributors (TSDs) and suppliers is… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@citrix channel marketing exec Tricia Atkinson is joining @Equinix to lead global partner #marketing.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@bizITsolutions announced a partnership with New Charter Technologies. dlvr.it/SlBh09 https://t.co/xpqbQcKC6y

March 20, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X