WannaCry 1 / 5

1. What Was WannaCry?

WannaCry was a type of malicious software called ransomware. It became widely known after a major cyberattack in May 2017.

Ransomware is designed to prevent people from accessing files or computer systems. Attackers may then demand money in exchange for restoring access.

Key fact: WannaCry affected hundreds of thousands of computers in countries around the world.

WannaCry mainly affected computers running vulnerable versions of Microsoft Windows.

2. How Did WannaCry Spread?

WannaCry could spread between vulnerable computers on a network. It exploited a weakness in a Windows networking component.

Microsoft had released a security update before the major outbreak, but many computers had not installed the update.

  • It could spread between vulnerable computers.
  • Unpatched systems were particularly vulnerable.
  • It could encrypt files.
  • It displayed a ransom demand.
Remember: Keeping operating systems and software updated is an important part of cybersecurity.

3. What Happened in 2017?

The WannaCry outbreak began spreading rapidly on 12 May 2017.

Organisations around the world were affected. One of the most widely reported impacts was on parts of the UK National Health Service (NHS).

Some healthcare organisations experienced disruption to computer systems and services.

Why was it serious? Cyberattacks can affect more than computers. They can interrupt important services when organisations depend on their computer systems.

4. How Was WannaCry Disrupted?

During the outbreak, a security researcher discovered that the malware checked a particular internet domain as part of its behaviour.

Registering that domain caused many versions of WannaCry to stop spreading. This became known as a kill switch.

  1. Identify – researchers studied the malware.
  2. Investigate – experts analysed its behaviour.
  3. Respond – organisations protected affected systems.
  4. Update – vulnerable computers could be patched.
Lesson: Security researchers can play an important role in understanding and responding to cyberattacks.

5. What Can We Learn?

  • Install security updates promptly.
  • Use supported operating systems and software.
  • Keep important data backed up.
  • Use appropriate security protections.
  • Have a plan for responding to cyber incidents.
Important: WannaCry was real malicious software. This information is for educational purposes.

End of WannaCry section.

ILOVEYOU 1 / 5

1. What Was ILOVEYOU?

ILOVEYOU was a computer worm that spread rapidly around the world in May 2000.

It became known as the "ILOVEYOU virus", although technically it was a worm because it could spread itself from one computer to another.

It was distributed through email using a message with the subject "ILOVEYOU".

Key fact: ILOVEYOU became one of the most famous malware outbreaks in the early history of the internet.

2. How Did ILOVEYOU Spread?

ILOVEYOU relied heavily on email and human curiosity.

The email contained an attachment that appeared to be a love letter. Opening the attachment allowed the malicious program to run.

  • It was distributed through email.
  • The message was designed to attract attention.
  • The attachment appeared to be a text file.
  • It could send copies of itself to other contacts.
Remember: Unexpected email attachments should be treated carefully, even when they appear to come from someone you know.

3. What Happened in 2000?

The ILOVEYOU outbreak began on 4 May 2000 and spread extremely quickly across the internet.

Millions of computers were affected. Organisations, businesses and individuals around the world experienced disruption.

The worm could overwrite or damage files and could also spread by sending messages to contacts in an infected computer's address book.

Why was it serious? Email was already an important communication method, so rapidly spreading malware could affect large numbers of users.

4. How Was It Investigated?

Security experts investigated the malware to understand how it worked and how it was spreading.

  1. Detect – identify unusual computer activity.
  2. Investigate – analyse the malware.
  3. Contain – reduce further spread.
  4. Recover – restore affected systems where possible.
Cybersecurity lesson: Understanding how malware spreads helps organisations develop better ways to detect and contain future threats.

5. What Can We Learn?

  • Be careful with unexpected email attachments.
  • Do not open suspicious files or links.
  • Keep operating systems and security software updated.
  • Use appropriate email security controls.
  • Back up important files regularly.
  • Learn how to recognise suspicious messages.
Important: ILOVEYOU was real malicious software. This information is for educational purposes.

End of ILOVEYOU section.

Rombertik 1 / 5

1. What Was Rombertik?

Rombertik was malicious software discovered by cybersecurity researchers in 2015.

It was designed to operate quietly on an infected computer while attempting to steal information from web browsers.

Rombertik was particularly notable because it contained techniques designed to make security analysis and detection more difficult.

Key fact: Rombertik was notable for its anti-analysis techniques.

2. How Did Rombertik Spread?

Rombertik was associated with malicious email campaigns. Attackers attempted to persuade people to open attachments or interact with malicious content.

This is an example of social engineering, where attackers try to persuade people to perform an action that helps malware reach a computer.

  • Malicious messages could target potential victims.
  • Attachments could be disguised as legitimate material.
  • User interaction could allow malicious software to execute.
  • The malware could then attempt to operate on the computer.
Remember: An email that looks genuine can still contain malicious content.

3. What Did Rombertik Do?

Rombertik was designed to monitor information being processed by web browsers and could attempt to capture sensitive information.

Malware of this type can be dangerous because people regularly use browsers to access email, websites and online services.

Why was it unusual? Rombertik included mechanisms intended to make analysis more difficult.

This made it an interesting example for cybersecurity researchers studying how malware attempts to avoid detection.

4. What Made Rombertik Unusual?

One of the most notable features of Rombertik was its use of anti-analysis techniques.

Malware authors sometimes attempt to detect whether their software is being examined in a controlled research environment.

  1. Detection – the malware could check its environment.
  2. Analysis resistance – it attempted to make investigation harder.
  3. Information theft – it could target information handled by browsers.
  4. Research – cybersecurity experts analysed its behaviour.
Cybersecurity lesson: Researchers need to understand both what malware does and how it attempts to avoid detection.

5. What Can We Learn?

  • Be careful with unexpected emails and attachments.
  • Keep operating systems and applications updated.
  • Use reputable security software.
  • Use strong passwords and appropriate security controls.
  • Back up important information regularly.
  • Learn how to recognise suspicious online behaviour.
Important: Rombertik was real malicious software. This information is for educational purposes.

End of Rombertik section.