Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

A strange new kind of ransomware is sweeping the internet

On Tuesday, Windows computers — first in Ukraine, later across Europe and the United States — began to show users a message that looked something like this:

This is called ransomware, a relatively new form of malware that scrambles a victim’s files and then demands a payment to unscramble them.

Attacks like this have become an increasingly common problem online. Last month, thousands of computers were infected with ransomware that experts dubbed WannaCry, causing disruptions for hospitals in the United Kingdom.

Ars Technica’s Dan Goodin describes the carnage the software has caused:

It initially took hold in Ukraine and Russia, but soon it reportedly spread to Poland, Italy, Spain, France, India, and the United States. WPP, the British ad company, said on Twitter that some of its IT systems were hit by a cyber attack. Its website remained unreachable as this post was going live. Law firm DLA Piper posted a handwritten sign in one of its lobbies instructing employees to remove all laptops from docking stations and to keep all computers turned off. AV provider Avast said it detected 12,000 attacks so far. Security company Group-IB said at least 80 companies have been infected so far. Reuters also reported that a computer attack that hit Maersk, a shipping company that handles one in seven of all containers globally, caused outages at all of its computer systems across the world.

The new attack is sophisticated, making several improvements over the techniques used by last month’s WannaCry malware. The software steals credentials from victims’ computers and sends them back to a server controlled by the attackers.

Yet surprisingly, the attackers seem to have taken a lackluster approach to collecting ransom payments. That has caused some experts to doubt that the attackers were actually after money. Rather, they suspect that the hackers were trying to cause mayhem or steal data from selected targets, and that they simply used ransomware to sow confusion about the nature of the attack and who was behind it.

The latest outbreak may have been intended for destruction, not profit

The basic idea behind ransomware is simple: A criminal hacks into your computer, scrambles your files with unbreakable encryption, and then demands that you pay for the encryption key needed to unscramble the files. If you have important files on your computer, you might be willing to pay a lot to avoid losing them.

One of the hardest things about creating ordinary ransomware is the need to get ransom payments back from victims. Ransomware schemes have become a lot more effective since the invention of Bitcoin in 2009. Conventional payment networks like Visa and MasterCard make it difficult to accept payments without revealing your identity. Bitcoin makes that a lot easier. So the past four years have seen a surge in ransomware schemes striking unsuspecting PC users.

But an attack still needs infrastructure to receive and verify payments and then distribute decryption keys to victims — potentially thousands of them. And it needs to do this in a way that can’t be blocked or traced by authorities, which is why ransomware attackers often rely on the anonymous Tor network to communicate with victims.

Yet this week’s ransomware attack takes a surprisingly lackluster approach to this problem. It instructs all victims to send payments to the same Bitcoin address, and then to send information about their payment to the email address wowsmith123456@posteo.net.

But Posteo blocked access to this account, making it impossible for victims to reach the attackers. With no way to get a decryption key, there’s no incentive for victims to pay the ransom.

It’s possible that the perpetrators of this otherwise-sophisticated attack were naive about how to set up its payment system. But it’s also possible that they simply disguised the software as ransomware to camouflage the attack’s real purpose.

See More:

More in Technology

Technology
The case for AI realismThe case for AI realism
Technology

AI isn’t going to be the end of the world — no matter what this documentary sometimes argues.

By Shayna Korol
Politics
OpenAI’s oddly socialist, wildly hypocritical new economic agendaOpenAI’s oddly socialist, wildly hypocritical new economic agenda
Politics

The AI company released a set of highly progressive policy ideas. There’s just one small problem.

By Eric Levitz
Future Perfect
Human bodies aren’t ready to travel to Mars. Space medicine can help.Human bodies aren’t ready to travel to Mars. Space medicine can help.
Future Perfect

Protecting astronauts in space — and maybe even Mars — will help transform health on Earth.

By Shayna Korol
Podcasts
The importance of space toilets, explainedThe importance of space toilets, explained
Podcast
Podcasts

Houston, we have a plumbing problem.

By Peter Balonon-Rosen and Sean Rameswaram
Technology
What happened when they installed ChatGPT on a nuclear supercomputerWhat happened when they installed ChatGPT on a nuclear supercomputer
Technology

How they’re using AI at the lab that created the atom bomb.

By Joshua Keating
Future Perfect
Humanity’s return to the moon is a deeply religious missionHumanity’s return to the moon is a deeply religious mission
Future Perfect

Space barons like Jeff Bezos and Elon Musk don’t seem religious. But their quest to colonize outer space is.

By Sigal Samuel