WannaCry-linked Bitcoin wallets emptied


MILAN: The three Bitcoin wallets that are linked to the WannaCry malware, which hit hundreds of thousands of networks using Microsoft Corp’s operating system in 150 countries, were emptied out earlier this morning, analysts have confirmed.

In each of the cases, the tokens have been divided into multiple smaller amounts, and sent off to other, various bitcoin addresses. The wallets contained a total of about 52 BTC, which amount to around US$140,000, explained Rayna Stamboliyska, an independent cyber risk manager in an email. “This morning, between 3.00 and 3.30AM GMT, the three wallets have been emptied and the money split into further ones,” she said.

In May, large-scale ransomware attack dubbed WannaCry spread a malicious software to about 300,000 computers in 150 countries, where access to data was blocked unless a ransom was paid through bitcoin. The UK's National Health Service, FedEx Corp, Nissan Motor Co and Renault were among entities impacted. The fallout for European companies affected in global cyberattacks has proven costly.

Orla Cox, director of security response at Symantec, said there is no way of knowing whether it was the WannaCry attackers, or even law enforcement, that accessed the three Bitcoin addresses. “These addresses may not represent all of the attackers’ earnings as WannaCry can generate unique bitcoin addresses per infection.”

Stamboliyska said the money may have been moved in an effort to obscure its origins, much like laundering. “The whole transaction lot is, however, still fresh, so we digital investigators will need some time to follow these breadcrumbs.”

Indeed, researchers quickly traced the bounty to its next destination.

”We figured out that the authors of WannaCry 2’s ransomware moved bitcoins they got from the last attack to another cryptocurrency called Monero,” said Alberto Ornaghi, a cybersecurity researcher at Milan-based Neutrino, a company specialising in bitcoin intelligence.

The conversion pattern scheme -- using a range of 1 to 1.5 bitcoins for each conversion transaction -- is the same used with WannaCry 1 ransomware and the cryptocurrency conversion service used is called ShapeShift.io, Ornaghi added in a phone interview. 

”Knowing the destination of these bitcoins and the conversion service the WannaCry authors used could allow law enforcement to figure out their real identities,” Ornaghi said. “The conversion is still continuing and we are closely monitoring it.” - Bloomberg


Win a prize this Mother's Day by subscribing to our annual plan now! T&C applies.

Monthly Plan

RM13.90/month

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!

   

Next In Business News

Ringgit opens easier against US$ ahead of OPR decision
FBM KLCI drifts as investors await fresh leads
Trading ideas: Axiata, Mega First, Vstecs, Pharmaniaga, Sarawak Cable, Paragon Globe, CIMB, IHH, Ni Hsin
Thai business group cuts 2024 GDP growth forecast
TotalEnergies mulls moving listing to Wall St
Rig dearth aggravates Indonesia’s declining oil and gas production
Optimistic growth prospects for Focus Point Holdings
Epsom sees more student enrolment from UK
SC: Planners should give sound financial advice
China’s surging industrial loans aren’t going to its factories

Others Also Read