Skip to Content

WannaCry Has a More Lucrative Cousin That Mines Cryptocurrency for Its Masters

The same exploits that enabled WannaCry to spread globally have been in use in another malware attack since April, making far more money in the process.
Headquarters of the NSA, the agency believed to be behind the creation of the EternalBlue and DoublePulsar exploits.

The same exploits that allowed the WannaCry ransomware attack to spread so quickly have been used to set up an illicit cryptocurrency mining scheme. And it sure was worth it to the hackers.

Late last week, the world was hit by ransomware that locked up computers in hospitals, universities, and private firms, demanding Bitcoin in exchange for files being decrypted. It was able to spread so fast thanks to a Windows flaw weaponized by the U.S. National Security Agency known as EternalBlue, and a back door called DoublePulsar. Sadly, the tools were inadvertently lost and leaked because the NSA considered it wise to stockpile them for future use.

WannaCry was halted by swift work on behalf of dedicated security researchers. But during investigations into the attack, security firm Proofpoint has found that another piece of malware, called Adylkuzz, makes use of the same exploits to spread itself around the word’s insecure Windows devices.

This particular hack has gone unnoticed since April. That’s because unlike WannaCry, which demands attention to get money directly from a user, Adylkuzz simply installs a piece of software and then borrows a PC’s resources. It then sets about mining the little-known cryptocurrency called Monero using your computer. It does so in the background, with users potentially unaware of its presence—though perhaps a little frustrated because their computers are slower than usual.

It makes sense that EternalBlue and DoublePulsar are being used in this way, said Nolen Scaife, a security researcher at the University of Florida. The combination of exploits allows attackers to load just about any type of malware they want onto compromised machines. “It's important to stress that it could be anything—it could be keyloggers, for example,” he told MIT Technology Review. “But what we're seeing is that attackers are using this wherever this makes the most money.”

Interestingly, though, it’s the attack that has until now gone unnoticed that has secured the most loot. WannaCry’s attempt to extort cash in return for unlocking encrypted files has only drummed up $80,000 at the time of writing—probably because Bitcoin, the currency WannaCry’s perpetrators are demanding, is hard to use. Meanwhile one estimate suggests that the Adylkuzz attack could have already raised as much as $1 million.

In some sense, Adylkuzz is less problematic than WannaCry. It’s certainly less overtly destructive. But it does raise a more pressing cause for concern: if it’s been running since April, how many other leaked NSA tools have been used to carry out attacks that have so far gone unnoticed? Stay tuned—there may be more to come.

(Read more: Proofpoint, Reuters, “The WannaCry Ransomware Attack Could’ve Been a Lot Worse,” “Security Experts Agree: The NSA Was Hacked,” “Should the Government Keep Stockpiling Software Bugs?”)

Keep Reading

Most Popular

Large language models can do jaw-dropping things. But nobody knows exactly why.

And that's a problem. Figuring it out is one of the biggest scientific puzzles of our time and a crucial step towards controlling more powerful future models.

The problem with plug-in hybrids? Their drivers.

Plug-in hybrids are often sold as a transition to EVs, but new data from Europe shows we’re still underestimating the emissions they produce.

Google DeepMind’s new generative model makes Super Mario–like games from scratch

Genie learns how to control games by watching hours and hours of video. It could help train next-gen robots too.

How scientists traced a mysterious covid case back to six toilets

When wastewater surveillance turns into a hunt for a single infected individual, the ethics get tricky.

Stay connected

Illustration by Rose Wong

Get the latest updates from
MIT Technology Review

Discover special offers, top stories, upcoming events, and more.

Thank you for submitting your email!

Explore more newsletters

It looks like something went wrong.

We’re having trouble saving your preferences. Try refreshing this page and updating them one more time. If you continue to get this message, reach out to us at customer-service@technologyreview.com with a list of newsletters you’d like to receive.