spreading itself within networks without relying on human activity to spread it.41 The
attack was indiscriminate rather than targeted, with evidence suggesting a North Korean
connection.42
The initial attacks were hindered by a 22-year-old UK security researcher—going by the name
of MalwareTech for purposes of anonymity—who discovered an apparently unintentional “kill
switch” to the malware.43 However, due to the relative ease of launching cyberattacks, and
the great deal of money at stake, concerns persist that either attacks will be relaunched with
the coded kill switch removed, or that subsequent attackers will learn from lessons from this
experience.44
WannaCry is a weaponization of one of a series of system’s vulnerabilities first identified
by the US National Security Agency (NSA),45 and which were stolen when the NSA was
hacked46 and then leaked to the public in April 2017.47 Of that cache, it is the tool codenamed
“EternalBlue” that appears to have been “the most significant factor” behind the
WannaCry attack.48 Among other things, the attacks have reignited the debate over whether
governments should disclose web or system vulnerabilities of which they become aware.49
The cyberattacks highlight the importance of user awareness. WannaCry appears to
have capitalized upon outdated systems for which patches existed, and even to have
targeted systems and sectors that might tend to run on legacy systems, such as healthcare
and transport. The attacks emphasize that it is incumbent upon users—individual and
institutional—to keep their systems up to date by installing the fixes—so-called “patches”—
that developers, such as Microsoft or Apple, make available as they become aware of system
weaknesses.51 In this instance, the attacks capitalized vulnerabilities in outdated Microsoft
Window software; Microsoft had released security updates to patch this matter in April, and,
responding to the attack, did so again on the day of this attack.52
As ransomware attacks grew by fifty-one percent last year,53 the threat seems unlikely to
abate. “This [problem] is one in which what’s broken is the system by which we fix”, said
Professor Zeynep Tufeki of the University of North Carolina.54
D. Detecting Cybercrime
Detecting cybercrimes is challenging because, first, the victim may have no idea that a crime has
occurred, and, second, cybercriminals are wont to operate behind multiple layers of fake identities
and often operate out of nation-states having either limited cybercrime-fighting capacity, or limited
interested in taking on such a fight.54 It is generally difficult to detect system security breaches
before any visible damage—such as the fraudulent transferring of a victim’s funds—has been done.
Moreover, much of the damage can be done simply by surveilling—for instance, in the collection of
personal information or metadata for use in identity theft. Moreover, even where a breach has been
identified, hackers often hide their identities through the use of various tools. Further difficulties
Page 34 | Chapter 1 | § C. Challenges to Fighting Cybercrime
Table of Contents