We have seen a number of support cases relating to Wanna-Cry ransomware we strongly recommend all clients implement Sophos intercept-x, call for details: 01226 361100. This threat is being delivered via email (below) should you receive this email please be aware that this is only a spam email and doesn’t offer any direct threat at this time.
Subject: !Wanna-Cry Attantion!
Hello! WannaCry is back! All your devices were cracked with our program deployed on them. We have upgraded operation of our program, so you will not be able to retrieve your data after the attack.
All the information will be encrypted and then erased. Antivirus software will not be able to detect our program, while firewalls will not be capable of protecting you against our one-of-a-kind code.
Should your files be encrypted, you will lose them forever.
Our program also outspreads through the local network, erasing data on all network-connected computers and remote servers, all cloud-stored data, and blocking website operation. We have already deployed our program on your devices.
Deletion of your data will commence on June 22, 2018, at 5:00 – 10:00 PM. All data stored on your computers, servers, and mobile devices will be destroyed. Devices working on any version of Windows, iOS, macOS, Android, and Linux are subject to data erasion.
In order to preclude data demolition, you can pay 0.1 BTC (~$650) to the bitcoin wallet:19JLLxirYpLTDhnbrwNXZBEsRssuxsaes
You must pay timely and notify us about the payment via email until 5:00 PM on June 22, 2018. After payment confirmation, we will send you instructions on how to avoid data erasion and such situations from now forward. Should you try to delete our program yourself, data erasion will commence without any delay.
To pay with bitcoins, please use localbitcoins.com or other similar services, or just google for other means. After payment write to us: firstname.lastname@example.org
What you should do…
- Stay protected with: Sophos Intercept-X
- Make sure you are prepared for future attacks, backup your systems regularly.