Cybersecurity researcher @MalwareTechBlog accidentally finds kill switch to stop spread of WannaCry malware by registering domain hardcoded into malware
Expert who stopped spread of attack by activating software's ‘kill switch’ says criminals will ‘change the code and start again’
Context & Ripple Effects
The immediate story: @MalwareTechBlog noticed a domain hardcoded into WannaCry, registered it, and triggered a kill switch that halted the worm's spread. The strain was built from cyberweapons developed by the NSA that were stolen and leaked, yet ransom payments to its three hardcoded Bitcoin addresses had reportedly reached only $26K by Saturday — disruption, not profit, was the damage.
What makes this worth tracking is how fragile the fix is. The researcher himself warned criminals would 'change the code and start again', and within days they tried exactly that route indirectly: Mirai-based botnets began DDoS-ing the kill-switch domain to take the brake off. Two years later, WannaCry still sat in thousands of networks despite available patches, and the kill switch alone had counted roughly 60M blocked detonations in a single June.
First-order effects
- Registering the hardcoded domain instantly stops new WannaCry infections worldwide, while the researcher publicly warns the operators can strip out the domain check, recompile, and resume.
- Victims who already paid gained nothing — the three hardcoded Bitcoin addresses held only about $26K by Saturday, confirming decryption was never reliably delivered.
Second-order effects
- Attackers answer with Mirai-based botnets DDoS-ing the kill-switch domain itself, turning a researcher's personal registration into critical infrastructure that must stay online or the worm revives.
- Because the kill switch does nothing for machines already infected, unpatched fleets keep harboring live WannaCry — TSMC's fabs were later shut down for days when unchecked manufacturing-tool software carried it in.
Third-order effects
- Hardcoded chokepoints prove to be both lifesaver and single point of failure: once defenders depend on one domain, attackers treat that domain as a target, pushing the industry toward distributed sinkholing and coordinated takedown infrastructure rather than individual heroics.
- The same fragility shows up in automated defense — researchers later tricked Cylance's AI-based antivirus into classifying WannaCry-like malware as benign — suggesting every defensive mechanism, from hardcoded domains to ML classifiers, becomes an attack surface once it matters.
The trend: Ransomware defense is converging on shared, contestable chokepoints — hardcoded domains, patches, automated detection — which attackers then target directly, making defensive infrastructure itself the battleground.