Categories: NewsSecurity

Developers of WannaCry Ransomware Arrested by Chinese Police

The WannaCry ransomware attack caused massive damage globally. A lot of computers and entire systems were crippled by this malware over the course of only a few days. It now appears there is a WannaCry variant targeting the Android ecosystem. To our relief, the Chinese police officials have arrested the developers. This goes to show some countries take these issues far more seriously than others.

China Doesn’t Mess Around With Android Malware

One lesson we can learn from the WannaCry ransomware deployment, is how damaging a sophisticated attack can be. Hundreds of thousands of machines were successfully infected by this malware, since it used an NSA-developed exploit kit to infect vulnerable systems. However, it does not appear desktop and laptop computers are the only potential targets for this destructive malware.

There is a version of WannaCry which is designed specifically to target the Android ecosystem. Two men have been arrested due to their alleged involvement in the distribution of SLocker, a powerful Android ransomware. At a glance SLocker looks just like WannaCry, but it works different under the hood. It is not uncommon for developers to rename existing malware if they make minor modifications to the code.

What is more remarkable is that these two developers were arrested in China. Few people would expect China to be home to ransomware developers, but this goes to show the reality is very different. It appears the developers used a clever way of distributing their malware. It was advertised as a free plugin for the Kings of Glory mobile game.

Related Post

We have seen many malware distribution methods over the past few years. Going after mobile gamers is an effective distribution strategy, especially when considering how Kings of Glory is wildly popular in China. Developers targeting people in their home country is not necessarily the best of ideas and usually attracts the attention of law enforcement.

The SLocker ransomware has than 100 victims, which is good considering how effective some ransomwares are. Victims are asked to pay a $6 ransom, which needs to be paid through QQ, Alipay, or WeChat. There is no mention of Bitcoin or any other cryptocurrencies on this Android variant of WannaCry. That is somewhat surprising, but may make sense. In China, WeChat, QQ, and Alipay are incredibly popular, and sending $6 worth of RMB to another person is incredibly easy.

These arrests show ransomware developers in China are under the extreme scrutiny of the law. It only took police officers five weeks to find the culprits and arrest them. During the arrest, they also found several dozen malware samples on confiscated hardware. Their choice for mobile payments may have caused their project to come to an abrupt halt since none of the payment methods were anonymous by any means.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

SkyAI’s Explosive 20x Surge Raises Red Flags As On-Chain Data Points To Possible Market Manipulation

The cryptocurrency market is in the crosshairs once again, an explosive price move in SkyAI…

7 hours ago

Bitget Launches OpenAI Pre-IPO Access As Crypto Exchanges Push Into Tokenized Equity Markets

Bitget officially launched pre-IPO access to OpenAI via its IPO Prime platform which deepens their…

21 hours ago

Tether Expands Open-Source Push With New Developer Grants For AI And Payment Infrastructure

Tether's presence in decentralized tech space is growing due to the launch of its developer…

2 days ago

Huma Finance Exploit Hits Legacy Contracts As Platform Maintains Stability And Accelerates Transition To V2 System

While challenges remain, the decentralized finance sector is moving forward, and Huma Finance's exploit serves…

2 days ago

Chainlink Expands Cross-Chain Reach As Major Protocols And Institutions Deepen Adoption 

Chainlink is continuing its mission to be the most widely integrated infrastructure in crypto, adding…

3 days ago

Sui Network Hit Again: DeepBook Exploit Adds To Growing List As Token Defies Pressure With Bullish Breakout

A vulnerability in one of the core DeFi protocols on Sui Network exposes the ecosystem…

4 days ago