The WannaCry virus, which caused global panic three years ago, has been imitated recently and has begun to spread sporadically in China under the name WannaRen. Users of Windows 7, Windows 10, and even Windows XP systems are inevitably reported to have cases. It can encrypt almost all Windows files and also uses Bitcoin as a blackmail target, causing another wave of commotion. However, recently the author suddenly “surrendered” to the security research unit and proactively provided the decryption key. If you are worried about accidentally winning, you can pay close attention.

The author of WannaRen proactively released the decryption key, and many companies have provided decryption tools.
WannaRen, a rising star that imitates the WannaCry ransomware virus, broke out recently. Its mechanism is to encrypt all files on the infected computer and change its suffix to “.WannaRen”, and force a window to pop up asking the victim to pay 0.05 Bitcoin (approximately NT$10,235) to obtain the decryption key. After research by security personnel, this virus uses entrainment techniques to load the ransomware module wwlib.dll in winword.exe to implement encryption, and spreads laterally through the EternalBlue vulnerability.

Just recently, the author of this virus contacted China’s security research center Huorong and proactively provided a decryption key, which was verified by the security agency to be indeed valid. Therefore, Huorong also quickly released its own WannaRen virus decryption tool. In addition, China’s 360 Security Brain and Qi’anxin Virus Response Center have released their own decryption tools based on this key.
【Tinder WannaRen decryption tool, click here】

Although this key is currently published on the Internet, for netizens who are not technical, Tinder reminds you that in order to avoid the risk of losing money, do not use the decryption tool made by the author to avoid blocking the front door and opening the back door.
Source: KOCPC Chinese