Last week a form of Ransomware swept the globe shutting down systems around the world including the British National Health Service (NHS) as well as numerous factories by automobile manufacturers. Its name is WannaCry, a malicious type of software that required victims to transfer an amount of money (initially $300 in Bitcoin) to the executors of the hack.
However, if you’ve fallen victim to the WannaCry ransomware you might be in some luck as a method of decrypting all of your files has been found. The method is applicable to computers that run Windows XP. It was discovered by a French security researcher from Quarkslab, Adrien Guinet. WannaKey, as the fix is aptly called, works by trying to retrieve the two prime numbers needed to get the encryption keys needed. These prime numbers are not deleted from memory from memory before freeing the associated memory. Unfortunately, it only works on computers running Windows XP.
According to Guinet, WannaKey retrieves the prime numbers needed by “searching for them in the wcry.exe process. This is the process that generates the RSA private key. The main issue is that the CryptDestroyKey and CryptReleaseContext does not erase the prime numbers from memory before freeing the associated memory.”
However, what’s frustrating is that even though a fix has been found, it only applies to devices running Windows XP. Furthermore, there’s an even narrower range of devices that can have the fix applied and its devices that have not been rebooted. That’s right, the common phrase “have you tried turning it off and then on again” may have actually ruined the one chance people currently have for decrypting their files.
As a result, the number of computers that have been affected and which can apply this fix may be in the minority.
Source: The Hacker News
