“WCRY” or “Wanna Decryptor” Ransomware

Ref# WannaCry” | Date: May 24th 2017

GNCIRT logo

Cybersecurity Alert: “Wanna Cry” or “Wanna Decryptor” Ransomware

Date: Friday, 12th May, 2017

Time: 18:00 hrs.

Guyana National Cybersecurity Incident Response Team (Guyana National CIRT) confirms that a global ransomware attack is currently in progress.

The self-spreading ransomware, known as “Wanna Cry” or “Wanna Decryptor”, exploits a vulnerability in Microsoft”s Windows operating system. It is believed that this ransomware is spread through phishing emails, malicious adverts on websites, and questionable apps and programs.

Users are advised to be extremely cautious in their online activities.

Do NOT open unsolicited or suspicious emails or links therein

Do NOT open attachments included in unsolicited e-mails

Do NOT click on links to unfamiliar or nefarious websites

Do NOT download applications and programs that have not been verified by an official store

In the event that your computer has been infected with the Wanna Cry ransomware, take the following steps:

Disconnect and quarantine the infected system by removing it from your network

Apply the latest Microsoft patch to all computer systems (please see Microsofts Security Bulletin MS17-010)

For further information and support, please contact Guyana National CIRT at 660-6074, 231-8820 ext. 221 or 222; or info@cirt.gy.

Future updates will be provided as more information becomes available.