This page was machine-translated and may differ from the original. View original
Ransomware increased by 36% last year; attacks expected to rise in combination with worms.
Symantec warns of large-scale spread of 'WannaCry' ransomware
Exploitation of MS Windows Vulnerabilities Rapidly Spreading Worldwide
'Ransom.Wannacry', which encrypts data files and demands a ransom, is spreading widely worldwide, centered in Europe.
According to a survey by Symantec, which stated that special attention to security is required, the WannaCry ransomware encrypts data files and demands that users pay a ransom of $300 in Bitcoin. It warns that if the ransom is not paid within 3 days, the amount will double, and if it is not paid within 7 days, the encrypted files will be deleted.

WannaCry ransomware encrypts files with extensions such as .3ds, .ai, .asf, .asm, .asp, .avi, .doc, .docx, .gif, .gpg, .hwp, .java, .jpeg, .jpg, .mp3, .mp4, .mpeg, .ost, .pdf, .png, .ppt, .pptx, .psd, .pst, .rar, .raw, .rtf, .swf, .tif, .tiff, .txt, .wav, .wma, .wmv, .zip, and adds the extension .WCRY to the end of the filenames.
WannaCry ransomware is known to spread to other computers by exploiting an SMB remote code execution vulnerability (MS17-010) targeting computers using Microsoft Windows.
It has been found that the reason the WannaCry ransomware is spreading on a large scale, particularly worldwide, is because it exploits known vulnerabilities in Microsoft Windows and possesses the ability to spread autonomously within corporate networks regardless of user activity. Since computers with Windows security updates not up to date are at risk of infection, it is necessary to download the updates.
You must make it a habit to update patches and keep your software up to date.
Meanwhile, according to Symantec’s 22nd Internet Security Threat Report, global ransomware attacks increased by 36% in 2016 compared to the previous year, and more than 100 new ransomware families (a collection of variant malware classified into the same category) were discovered during the year. Additionally, the average amount demanded by ransomware criminals in 2016 was found to be $1,077 (approximately 1.22 million KRW), an increase of about 3.7 times from $294 (approximately 330,000 KRW) in 2015.
"WannaCry is a combination of ransomware and a worm, and since worms pose a higher risk because there is a high possibility of automatic remote infection if patches are not applied," said Yoon Kwang-taek, CTO of Symantec Korea. "As there is a high possibility that attacks combining ransomware and worms will increase in the future, it is necessary to make it a habit to update patches and keep software up to date." "In particular, as ransomware attacks via email are on the rise, it is safer to delete suspicious emails and back up important files in advance," they advised.
Ransomware Prevention Security Guidelines
- Since new ransomware variants appear regularly, you must keep your security software up to date.
- Keep the operating system (OS) and other software up to date.
You must keep your software updated to the latest version because updates include patches for new security vulnerabilities that ransomware attackers can exploit.
Email is one of the major routes of infection, so special caution should be exercised regarding emails containing suspicious links and attachments.
You should be especially careful with emails containing MS Office attachments that prompt you to view content using macros. Unless you are certain that the email is from a trusted source, do not enable the macros and delete the email immediately.
To prepare for ransomware infection, you must back up important data.
Exploitation of MS Windows Vulnerabilities Rapidly Spreading Worldwide
'Ransom.Wannacry', which encrypts data files and demands a ransom, is spreading widely worldwide, centered in Europe.
According to a survey by Symantec, which stated that special attention to security is required, the WannaCry ransomware encrypts data files and demands that users pay a ransom of $300 in Bitcoin. It warns that if the ransom is not paid within 3 days, the amount will double, and if it is not paid within 7 days, the encrypted files will be deleted.
Ransom demand screen displayed on the computer when infected with WannaCry ransomware
WannaCry ransomware encrypts files with extensions such as .3ds, .ai, .asf, .asm, .asp, .avi, .doc, .docx, .gif, .gpg, .hwp, .java, .jpeg, .jpg, .mp3, .mp4, .mpeg, .ost, .pdf, .png, .ppt, .pptx, .psd, .pst, .rar, .raw, .rtf, .swf, .tif, .tiff, .txt, .wav, .wma, .wmv, .zip, and adds the extension .WCRY to the end of the filenames.
WannaCry ransomware is known to spread to other computers by exploiting an SMB remote code execution vulnerability (MS17-010) targeting computers using Microsoft Windows.
It has been found that the reason the WannaCry ransomware is spreading on a large scale, particularly worldwide, is because it exploits known vulnerabilities in Microsoft Windows and possesses the ability to spread autonomously within corporate networks regardless of user activity. Since computers with Windows security updates not up to date are at risk of infection, it is necessary to download the updates.
You must make it a habit to update patches and keep your software up to date.
Meanwhile, according to Symantec’s 22nd Internet Security Threat Report, global ransomware attacks increased by 36% in 2016 compared to the previous year, and more than 100 new ransomware families (a collection of variant malware classified into the same category) were discovered during the year. Additionally, the average amount demanded by ransomware criminals in 2016 was found to be $1,077 (approximately 1.22 million KRW), an increase of about 3.7 times from $294 (approximately 330,000 KRW) in 2015.
"WannaCry is a combination of ransomware and a worm, and since worms pose a higher risk because there is a high possibility of automatic remote infection if patches are not applied," said Yoon Kwang-taek, CTO of Symantec Korea. "As there is a high possibility that attacks combining ransomware and worms will increase in the future, it is necessary to make it a habit to update patches and keep software up to date." "In particular, as ransomware attacks via email are on the rise, it is safer to delete suspicious emails and back up important files in advance," they advised.
Ransomware Prevention Security Guidelines
- Since new ransomware variants appear regularly, you must keep your security software up to date.
- Keep the operating system (OS) and other software up to date.
You must keep your software updated to the latest version because updates include patches for new security vulnerabilities that ransomware attackers can exploit.
Email is one of the major routes of infection, so special caution should be exercised regarding emails containing suspicious links and attachments.
You should be especially careful with emails containing MS Office attachments that prompt you to view content using macros. Unless you are certain that the email is from a trusted source, do not enable the macros and delete the email immediately.
To prepare for ransomware infection, you must back up important data.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














