WannaCry ransomware hits automotive industry

Author without image icon
editors
01 August 2017
4 min

Security researchers worldwide sounded a major alarm on Friday 12 May after the ransomware WannaCry was found to be spreading at a breakneck pace. This malicious software takes systems and data on them hostage, then demands a ransom from the owner. Several Renault and Nissan production sites were also affected, forcing a temporary shutdown of production.

Ransomware is a form of malicious software that takes data and systems hostage by encrypting them. In many cases, this malicious software is spread via e-mail as an attachment. If an employee opens this attachment, their system is infected with ransomware. This software encrypts all data on the system and sends the key created in the process to a server owned by cyber criminals. These criminals then demand a ransom from victims who want to regain access to their systems and data.

WannaCry ransomware

The WannaCry ransomware managed to spread considerably faster than is usually the case with ransomware; several tens of thousands of systems were infected in a 12-hour period. This is possible because the attackers exploited a security problem in the Microsoft Windows operating system. The problem is in Server Message Block (SMB), a network protocol used by Windows to enable file exchange between multiple computers. By exploiting this vulnerability, the ransomware was able to spread itself to other systems connected to the corporate network.

Estimates of the number of victims of WannaCry reach 200,000. Not only citizens, but also companies have been affected. For instance, a spokesperson for Renault confirmed to Reuters news agency that the company has been hit by the WannaCry ransomware. To prevent further spread of the computer virus, the company was forced to temporarily halt production at several plants. Production was largely resumed on Monday 15 May. A Nissan spokesperson additionally reported to the BBC that systems at a plant in Sunderland, UK, had been infected by the ransomware. This would not have had a major impact on Nissan's operations, as no production was taking place at the plant at the time of infection.

One-off incident?

Unfortunately, ransomware is a common phenomenon. For instance, figures from security firm Trend Micro show that the number of known types of ransomware increased by a whopping 752 per cent in 2016. It is estimated that ransomware caused around $1 billion in damage to businesses worldwide in 2016. Thus, the WannaCry attack is not a one-off incident and just one example of a ransomware attack. The attack stands out in particular because of the very aggressive way the malicious software managed to spread worldwide.

The fact that WannaCry has managed to penetrate factories may sound strange. However, in reality, many systems in all kinds of industries use the Windows operating system. Since the WannaCry ransomware exploits a security problem in the protocol SMB - which is enabled by default on Windows machines - these systems are also vulnerable to the malicious software. Companies outside the automotive sector have also run into problems. For instance, not only Renault and Nissan were affected by the recent WannaCry outbreak, but also a large number of British hospitals, Dutch company Q-Park, US logistics company FedEx, the Russian Ministry of the Interior and Spanish telecoms provider Telefonica, among others.

How to protect my business

How do I protect my business?

Fortunately, users can guard against such attacks. As mentioned, the WannaCry ransomware exploited a security problem in Windows' SMB protocol. This problem was fixed in March by Microsoft, manufacturer of the Windows operating system, in software update MS17-010. Those who install this update will thereby prevent the ransomware from spreading across their corporate network via the SMB protocol. This does not mean that the ransomware cannot get onto systems, as this is also possible if an employee manually opens the ransomware. However, it does significantly reduce the chances of such malicious software managing to penetrate deep into factories, for example. It is therefore crucial to install updates on all systems present within a company with great regularity.

Unfortunately, in practice, it appears that far from all companies keep systems up-to-date, which gave WannaCry free rein at some organisation. For example, some companies use outdated operating systems, which are no longer supported by the manufacturer. Updates are no longer made for these operating systems, so newly discovered security problems are not fixed. This plays into the hands of cybercriminals.

Why is outdated software still being used?

In many cases, the use of outdated software and operating systems is otherwise easy to explain. For example, some companies use applications that have been custom developed for the organisation, and are only suitable for specific versions of, say, Windows. In practice, this means that systems running these applications cannot be updated with the latest version of the operating system. As a result, companies are forced to keep working with outdated software, with all the associated risks. Unfortunately, updating is the only way to ensure that security problems are closed and prevent incidents such as WannaCry.

In addition, security experts advise companies to back up all systems and data with great regularity. This is because if systems are taken hostage by ransomware, all data is encrypted and files can no longer be opened. Cybercriminals offer the option of paying a ransom to make this data accessible again, but both security researchers and the Dutch police advise against doing so. For instance, payment offers no guarantee that cybercriminals will actually make encrypted files accessible again. Those who have a backup of their data can wipe infected systems completely, reinstall and restore the backup to make hostage data accessible again.

More information on the WannaCry ransomware can be found at security companies FireEye or Symantec.

 

By: Wouter Hoeffnagel