A 22-year-old UK security researcher has told the BBC how he “accidentally” halted the spread of ransomware affecting hundreds of organisations, including the UK’s NHS.
The man, known online as MalwareTech, was analysing the code behind the ransomware on Friday night when he made his discovery.
He first noticed the software was trying to contact an unusual web address – iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com – but this was not connected to a website, because nobody had registered it.
NHS ‘robust’ after cyber-attack
So, every time the ransomware tried to contact this mysterious website, it failed – and set about doing damage.
So the blogger decided to spend $10.69 (£8) to claim the web address. By owning this web address, he could also access analytical data and get an idea of how widespread the ransomware was.
But he later realised that registering the web address had also stopped the ransomware trying to spread itself.
“It was actually partly accidental,” he told the BBC, after spending the night investigating. “I have not slept a wink.”
Originally it was suggested that whoever created the ransomware had included a “kill switch” – a way of stopping it from spreading, perhaps if things got out of hand.
In this case, the act of registering the mysterious web address would trigger the kill switch.
But the blogger MalwareTech now thinks it was not a kill switch. He thinks it was a way of detecting whether the ransomware was being investigated within a secured, disposable environment that researchers use to inspect viruses. This is known as a “virtual machine”.
“The [ransomware] exits to prevent further analysis,” MalwareTech wrote in a blog post.
“My registration… caused all infections globally to believe they were inside a [virtual machine] and exit…thus we initially unintentionally prevented the spread and further ransoming of computers.”
The researcher has been called an “accidental hero” for slowing the spread of the ransomware.
“I would say that’s correct,” he told the BBC.
Does this mean the ransomware is defeated?
While the registration of the web address appears to have stopped one strain of the malware spreading, it does not mean the ransomware itself has been defeated.
Any files that were scrambled by the ransomware will still be held to ransom.
Security experts have also warned that new variants of the ransomware that ignore the “kill switch” will appear.
“This variant shouldn’t be spreading any further, however there’ll almost certainly be copycats,” said security researcher Troy Hunt in a blog post.
MalwareTech warned: “We have stopped this one, but there will be another one coming and it will not be stoppable by us.
“There’s a lot of money in this, there is no reason for them to stop. It’s not much effort for them to change the code and start over.”