A domain name was the off-switch for WannaCry
WannaCry asked one hardcoded domain name for permission before it encrypted anything. Nobody had bought that name yet. It cost about ten dollars, and the sinkhole behind it is still running.
Friday, 12 May 2017.
English hospitals turn patients away. Renault and Telefónica are hit.
At home in England, a 22-year-old researcher runs a sample of a new worm called WannaCry and watches it call out to a domain name no one has claimed.
He buys it. Around ten dollars. Then he points it at a sinkhole, a server of his own that swallows malicious traffic and counts where it came from.
By that afternoon, newly infected machines everywhere stop encrypting.
Whoever registers a domain name decides how the software asking for it behaves, everywhere, at once.
WannaCry asked one question before it encrypted anything: does this domain name resolve? An answer meant quit. Silence meant encrypt. The name was hardcoded, single and unclaimed, so every infected machine on earth got its answer from one registration.
Marcus Hutchins, then working for Kryptos Logic, did not know any of that when he paid. His routine work was buying up the unregistered domain names that malware phones home to, and by his own account he had registered several thousand of them in the preceding year to watch botnets and count victims. This one happened to be the off-switch.
His own reading, published the next day, is that the check was never built as an off-switch. The isolated environments researchers use to run malware safely will answer every DNS query, including queries for names that do not exist. Malware that asks for a nonsense name and gets an answer concludes it is being watched, and exits. The attackers built that trick around one fixed name, the same one on every run.
The attackers left one unregistered name in charge of whether their malware ran.
The registration then had to stay alive, and it has stayed alive for nine years.
In those first days the sinkhole absorbed a Mirai botnet trying to flood it offline, and law enforcement seized two of the servers behind it from a datacentre in France, on the understanding that the domain was spreading WannaCry rather than stopping it. Four days in, Cloudflare took over the hosting. Kryptos Logic still runs the name.
It answered while I was writing this: Sinkholed by Kryptos Logic.
In 2019 Cloudflare said it was still receiving takedown requests for that domain every year, from people who mistook the cure for the infection.
Every unpatched machine still carrying WannaCry is waiting for that one name to go quiet. A missed renewal would do it. So would a transfer dispute, a registry suspension, or a takedown request granted anywhere along the chain without a second look.
Your own systems are full of quieter versions. Update servers, licence checks, telemetry endpoints, the CDN your checkout page pulls a script from. Each of them is a domain name, and your software keeps behaving the way you expect only for as long as somebody keeps that name registered.
I cannot decide whether it is reassuring or absurd that the world’s insurance against a second WannaCry outbreak carries a renewal date.
The people who keep your domain names registered are holding switches that appear on none of your architecture diagrams.
Magyar változat: [zona.hu/a-wannacry-zsarolovirus-leallitogombja-egy-meg-nem-regisztralt-domain-volt/]


