Cybersecurity researcher @MalwareTechBlog accidentally finds kill switch to stop spread of WannaCry malware by registering domain hardcoded into malware
Expert who stopped spread of attack by activating software's ‘kill switch’ says criminals will ‘change the code and start again’
Context & Ripple Effects
Within days of the outbreak, researcher @MalwareTechBlog registered a domain hardcoded into WannaCry, activating a kill switch that halted the ransomware's spread — built on cyberweapons stolen and leaked from the NSA, and netting its operators only around $26K across three Bitcoin addresses by Saturday.
The reprieve was short-lived as a defensive story: within a week attackers were using Mirai-based botnets to DDoS the kill-switch domain itself, trying to knock out the one lever stopping new detonations, and the strain went on infecting TSMC's fabs via unchecked manufacturing-tool software.
First-order effects
- WannaCry's spread stops immediately for any variant still phoning home to the registered domain, but the researcher himself warns criminals will change the code and start again — the fix covers only this build.
Second-order effects
- Attackers respond by targeting the kill-switch infrastructure directly with Mirai botnets, turning a single researcher's domain registration into contested ground; meanwhile thousands of unpatched networks keep the ransomware viable regardless.
Third-order effects
- A defense that hinges on one hardcoded domain shows how fragile single-point mitigations are against wormable ransomware — and two years later WannaCry remains in thousands of networks despite available patches, confirming that patching discipline, not kill switches, decides whether an outbreak ever really ends.
The trend: Ransomware defense is shifting from ad-hoc heroics like hardcoded kill switches toward the harder structural work of patching and hardening, because attackers now counter-attack the countermeasures themselves.