Local IT on high alert after SA PCs hit by global virus

Malware is on the rise. (Duncan Alfreds, Fin24)
Malware is on the rise. (Duncan Alfreds, Fin24)

Johannesburg - A massive, global ransomware attack has hit hundreds of thousands of computers through a Microsoft Windows operating system vulnerability and affected governments, learning institutions and telecommunication, industrial, finance and enterprise industries.

The “WannaCry” virus encrypts users' data on a computer asking the user to pay a ransom of roughly R4 000, for a key which will decrypt their data. 

Carl Middlekoop, senior account manager for Cape Town-based IT company MMC South Africa said that they are on high alert since the widespread attack started over the weekend.

“South Africa is a big target to any in the world. Some of the clients we work with have sensitive information, which in the wrong hands could pose a serious threat,” Middlekoop told Fin24.

“You don’t want the kind of information this attack encrypts to land up in the hands of hackers, with that in mind we are on guard and will isolate any machine that has been infected by the virus and not allow it to spread,” he said.

Local experts have found at least 1 000 computers vulnerable to the virus, with no word on how many computers have been affected.

Once inside the system, the WannaCry virus installs a rootkit, which enables them to download the software to encrypt the data. 

READ: Cyber heists go big as criminals now target banks

The ransom is then requested to be paid into a BitCoin wallet and is believed to increase over time.

Cyber-security company Kaspersky Lab’s researchers confirmed that the company’s protection subsystems detected at least 45 000 infection attempts in 74 countries, most of them in Russia.

Another security software company ESET said that the malware encrypts data on a computer within seconds and then displays a message asking the user to pay a ransom, which is lower than other ransomware seen – but the true cost will be all the time, lost files, and other collateral damage caused by this attack.

The files touched by the attack are encrypted and the attacker is the only source for the key to reverse that – this can have dire consequences, especially in the healthcare sector.  

ESET said that the encrypted patient records, doctors' files and other items may not be able to be usable or accessible unless there is a good backup to restore from. 

So far the culprits are unknown – but it is unlikely that it was one person. 

Read Fin24's top stories trending on Twitter:

Brent Crude
All Share
Top 40
Financial 15
Industrial 25
Resource 10
All JSE data delayed by at least 15 minutes morningstar logo
Company Snapshot
Voting Booth
Please select an option Oops! Something went wrong, please try again later.
I'm not really directly affected
18% - 1904 votes
I am taking a hit, but should be able to recover in the next year
23% - 2509 votes
My finances have been devastated
35% - 3737 votes
It's still too early to know what the full effect will be
25% - 2670 votes