1. What Was WannaCry?
WannaCry was a type of malicious software called ransomware. It became widely known after a major cyberattack in May 2017.
Ransomware is designed to prevent people from accessing files or computer systems. Attackers may then demand money in exchange for restoring access.
WannaCry mainly affected computers running vulnerable versions of Microsoft Windows.
2. How Did WannaCry Spread?
WannaCry could spread between vulnerable computers on a network. It exploited a weakness in a Windows networking component.
Microsoft had released a security update before the major outbreak, but many computers had not installed the update.
- It could spread between vulnerable computers.
- Unpatched systems were particularly vulnerable.
- It could encrypt files.
- It displayed a ransom demand.
3. What Happened in 2017?
The WannaCry outbreak began spreading rapidly on 12 May 2017.
Organisations around the world were affected. One of the most widely reported impacts was on parts of the UK National Health Service (NHS).
Some healthcare organisations experienced disruption to computer systems and services.
4. How Was WannaCry Disrupted?
During the outbreak, a security researcher discovered that the malware checked a particular internet domain as part of its behaviour.
Registering that domain caused many versions of WannaCry to stop spreading. This became known as a kill switch.
- Identify – researchers studied the malware.
- Investigate – experts analysed its behaviour.
- Respond – organisations protected affected systems.
- Update – vulnerable computers could be patched.
5. What Can We Learn?
- Install security updates promptly.
- Use supported operating systems and software.
- Keep important data backed up.
- Use appropriate security protections.
- Have a plan for responding to cyber incidents.
End of WannaCry section.
1. What Was ILOVEYOU?
ILOVEYOU was a computer worm that spread rapidly around the world in May 2000.
It became known as the "ILOVEYOU virus", although technically it was a worm because it could spread itself from one computer to another.
It was distributed through email using a message with the subject "ILOVEYOU".
2. How Did ILOVEYOU Spread?
ILOVEYOU relied heavily on email and human curiosity.
The email contained an attachment that appeared to be a love letter. Opening the attachment allowed the malicious program to run.
- It was distributed through email.
- The message was designed to attract attention.
- The attachment appeared to be a text file.
- It could send copies of itself to other contacts.
3. What Happened in 2000?
The ILOVEYOU outbreak began on 4 May 2000 and spread extremely quickly across the internet.
Millions of computers were affected. Organisations, businesses and individuals around the world experienced disruption.
The worm could overwrite or damage files and could also spread by sending messages to contacts in an infected computer's address book.
4. How Was It Investigated?
Security experts investigated the malware to understand how it worked and how it was spreading.
- Detect – identify unusual computer activity.
- Investigate – analyse the malware.
- Contain – reduce further spread.
- Recover – restore affected systems where possible.
5. What Can We Learn?
- Be careful with unexpected email attachments.
- Do not open suspicious files or links.
- Keep operating systems and security software updated.
- Use appropriate email security controls.
- Back up important files regularly.
- Learn how to recognise suspicious messages.
End of ILOVEYOU section.
1. What Was Rombertik?
Rombertik was malicious software discovered by cybersecurity researchers in 2015.
It was designed to operate quietly on an infected computer while attempting to steal information from web browsers.
Rombertik was particularly notable because it contained techniques designed to make security analysis and detection more difficult.
2. How Did Rombertik Spread?
Rombertik was associated with malicious email campaigns. Attackers attempted to persuade people to open attachments or interact with malicious content.
This is an example of social engineering, where attackers try to persuade people to perform an action that helps malware reach a computer.
- Malicious messages could target potential victims.
- Attachments could be disguised as legitimate material.
- User interaction could allow malicious software to execute.
- The malware could then attempt to operate on the computer.
3. What Did Rombertik Do?
Rombertik was designed to monitor information being processed by web browsers and could attempt to capture sensitive information.
Malware of this type can be dangerous because people regularly use browsers to access email, websites and online services.
This made it an interesting example for cybersecurity researchers studying how malware attempts to avoid detection.
4. What Made Rombertik Unusual?
One of the most notable features of Rombertik was its use of anti-analysis techniques.
Malware authors sometimes attempt to detect whether their software is being examined in a controlled research environment.
- Detection – the malware could check its environment.
- Analysis resistance – it attempted to make investigation harder.
- Information theft – it could target information handled by browsers.
- Research – cybersecurity experts analysed its behaviour.
5. What Can We Learn?
- Be careful with unexpected emails and attachments.
- Keep operating systems and applications updated.
- Use reputable security software.
- Use strong passwords and appropriate security controls.
- Back up important information regularly.
- Learn how to recognise suspicious online behaviour.
End of Rombertik section.