
The Wannacry virus attacked about 45 thousand computers in 74 countries, Interfax reports with reference to the Kaspersky Lab. According to the company, Russia underwent infection to the greatest extent, according to the company.
In particular, the servers of the Russian Ministry of Internal Affairs were attacked. At about 22:00, the department’s website stopped displaying the information, the screensaver appeared on it: "Dear visitors to the site! Currently, work is underway to improve the Internet site of the Ministry of Internal Affairs of Russia."
An hour later, the official representative of the ministry, Irina Volk, announced the localization of the attack. According to her, thanks to timely, about a thousand infected computers were blocked in a timely manner, which is less than 1 percent. "At the moment, the virus is localized. Technical work is being carried out to destroy and update anti -virus protective equipment," the wolf said.
The media also reported an attack on the internal networks of the Investigative Committee. However, the official representative of the Investigative Committee of Svetlana Petrenko said that all the resources of the department are working as usual.
The computers of Megafon. The director of public relations of the mobile operator, Peter Lidov, confirmed this fact. According to Lidov, the infection did not affect the safety of subscribers, but worsened the quality of their service: the computers affected by the virus were disconnected from the network, and the company's operators could not go into user accounts.
Sberbank also stated that its infrastructure was subjected to viral attacks by hackers, specifying that "the penetrations of viruses into the bank system did not occur." On Saturday, the Russian Railways also reported a viral attack on their IT system. "The virus is currently localized, technical work is underway to destroy and update anti -virus protection," said Russian Railways.
The National Health Service of Great Britain said that computer systems of hospitals throughout the country failed as a result of an attack by robber programs. The virus was struck by the Spanish telecommunication company Telefonica, the Spanish supplier of electricity and natural gas Iberdrola, the American company for the mail and courier services of Fedex, the largest telecommunication services Portugal Portugal Telecom. A large number of infections occurred in Taiwan.
Experts of the EU police service (Europol) believe that the series of cyber attacks using the Wannacry computer virus around the world was held at an "unprecedented level". In Europol, which works with the leadership of countries and companies that suffered from the cyberots, it is necessary to conduct a "comprehensive international investigation to establish the culprits."
The Wannacry virus encrypts user files and changes their expansion. For deciphering data, attackers demand to pay a ransom from 200 to 600 dollars in bitcoins. In case of non -payment, files are deleted. Several dozens of transactions on the wallet indicated by attackers have already been recorded.
Most likely, we are not talking about a focused attack: the virus uses vulnerability in the Windows operating system. In March, the Microsoft Corporation has already corrected this error in new versions of the system, so those computers where the system was not updated was infected.
The distribution of the robber virus was suspended by accident. Safety specialist, leading Twitter @malwareTechblog, found that the virus for some reason appeals to the IUQERFSODP9IFJAPOSDFJHGOSURIJFAWERWERGWEA.com domain, and decided to register it to follow the program activity. However, unexpectedly for a specialist, this led to the stop of the epidemic.
As it turned out, it was laid in the virus code that if the appeal to this domain is successful, then the infection should be stopped. Immediately after registering the domain, tens of thousands of requests received him. This has not helped to infect already, but it gave another to install Windows updating from the virus. However, it is enough for attackers to replace the domain name in the code to continue the attack.