/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

New tool decrypts WannaCry-infected computers running Windows XP, 7, and 2003, if they have not been rebooted

if you work fast Brad Linder / Liliputing : Do not reboot your PC if you get WannaCry ransomeware - try this instead Matt Suiche / Comae Technologies : WannaCry — Decrypting files with WanaKiwi + Demos Kevin Billings / Tech Times : French May Have Found Last-Minute Solution To WannaCry Ransomware Attacks Paul Wagenseil / Tom's Guide : This New Tool Can Free Files from WannaCry emptywheel : The Legitimacy Problem with NSA's Silence on WannaCry Thomas Fox-Brewster / Forbes : This Tool Could Save You From Paying WannaCry Ransomware Crooks Tweets: Matthieu Suiche / @msuiche : Thanks for validating our results @Europol ! http://twitter.com/... @europol : #Wannacry decrypting files tested by @EC3Europol & found to recover data in some circumstances: https://blog.comae.io/... https://twitter.com/... Matthieu Suiche / @msuiche : Updated blogpost ! I confirm wanakiwi decryption tool for #WannaCry also works with Windows 7 too ! http://blog.comae.io/... Mitch Kapor / @mkapor : Bug in Microsoft crypto API let some users unlock their PC without paying WCry ransom http://arstechnica.com/... Matthieu Suiche / @msuiche : DO NOT REBOOT AND TRY WANAKIWI ASAP #WANNACRY All Info Here: http://blog.comae.io/...

Ars Technica Dan Goodin

Context & Ripple Effects

Matthieu Suiche's WanaKiwi turns a bug in Microsoft's crypto API into a rescue path for WannaCry victims: files encrypted on Windows XP, Windows 7, and Windows Server 2003 can be decrypted without paying — but only before the machine reboots, which is why the tool's release came with urgent do-not-reboot guidance from outlets like Liliputing. Europol's EC3 has validated that recovery works in some infections.

The timing matters because the victim base is concentrated where the tool works: Kaspersky Lab data put roughly 98% of infected machines on Windows 7. It also lands amid Microsoft's scramble over its end-of-life systems, which began with emergency updates for unsupported versions days into the outbreak and stretched into June, when it patched three more flaws affecting unsupported OSes it had initially declined to fix.

First-order effects

  • Victims on unrebooted XP, 7, and Server 2003 machines get a free decryption path, directly undercutting the ransom demand at the moment of maximum payment pressure.

Second-order effects

  • Microsoft is pushed deeper into maintaining code it had retired: the outbreak already forced out-of-band patches for unsupported Windows versions, and each new exploit or decryptor keeps those legacy systems on its security calendar.

Third-order effects

  • If end-of-life software keeps generating both global incidents and working rescues, 'unsupported' stops meaning 'unpatchable,' pressuring vendors toward longer lifecycle commitments and buyers toward faster migration off legacy platforms.

The trend: The WannaCry aftermath is turning end-of-life operating systems from abandoned liabilities into obligations Microsoft must keep patching, one forced update at a time.