{"id":211,"date":"2018-05-05T02:30:33","date_gmt":"2018-05-05T02:30:33","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/"},"modified":"2018-05-05T02:30:33","modified_gmt":"2018-05-05T02:30:33","slug":"hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/","title":{"rendered":"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/59264b857034dc5f91beaef5\/191:100\/pass\/WannaCry_HP-97228717.jpg\" class=\"ff-og-image-inserted\"\/><\/div>\n<p><span class=\"lede\">Over the past<\/span> year, two digital disasters have rocked the internet. The botnet known as Mirai knocked a swath of major sites off the web last September, including Spotify, Reddit, and <em>The<\/em> <em>New York Times<\/em>. And over the past week, the <a href=\"https:\/\/www.wired.com\/2017\/05\/ransomware-meltdown-experts-warned\/\">WannaCry ransomware outbreak<\/a> crippled systems ranging from health care to transportation in 150 countries before an unlikely &#8220;kill-switch&#8221; in its code shut it down.<\/p>\n<p>Now a few devious hackers appear to be trying to combine those two internet plagues: They&#8217;re using their own copycats of the Mirai botnet to attack WannaCry&#8217;s kill-switch. So far, researchers have managed to fight off the attacks. But in the unlikely event that the hackers succeed, the ransomware could once again start spreading unabated.<\/p>\n<h3 class=\"paywall\">Under Siege<\/h3>\n<p class=\"paywall\">Since the WannaCry ransomware worm began to fan out through the internet Friday, security researchers noticed a curious feature. When it infects a computer, it first reaches out to a certain random-looking web address, apparently as part of a check that it&#8217;s not running in a &#8220;sandbox&#8221; environment, which security researchers use to test malware samples safely. If WannaCry connects to a valid server at that specified domain, the ransomware assumes it&#8217;s under scrutiny, and goes dormant.<\/p>\n<div class=\"inset-left-component paywall inset-left-component--article\">\n<ul class=\"inset-left-component--article__list\">\n<li>\n<h4 name=\"inset-left\" class=\"inset-left-component__el\">Ransomware Meets DDOS<\/h4>\n<\/li>\n<li class=\"article-list-item-embed-component__post\" readability=\"23\">\n<div class=\"article-list-item-embed-component__description\" readability=\"32\">\n<p><span>Lily Hay Newman<\/span><\/p>\n<p class=\"article-list-item-embed-component__title\">The Ransomware Meltdown Experts Warned About Is Here<\/p>\n<\/div>\n<\/li>\n<li class=\"article-list-item-embed-component__post\" readability=\"23\">\n<div class=\"article-list-item-embed-component__description\" readability=\"32\">\n<p><span>Lily Hay Newman<\/span><\/p>\n<p class=\"article-list-item-embed-component__title\">How an Accidental \u2018Kill Switch\u2019 Slowed Friday\u2019s Massive Ransomware Attack<\/p>\n<\/div>\n<\/li>\n<li class=\"article-list-item-embed-component__post\" readability=\"23\">\n<div class=\"article-list-item-embed-component__description\" readability=\"32\">\n<p><span>Andy Greenberg<\/span><\/p>\n<p class=\"article-list-item-embed-component__title\">The WannaCry Ransomware Hackers Made Some Real Amateur Mistakes<\/p>\n<\/div>\n<\/li>\n<li class=\"article-list-item-embed-component__post\" readability=\"23\">\n<div class=\"article-list-item-embed-component__description\" readability=\"32\">\n<p><span>Lily Hay Newman<\/span><\/p>\n<p class=\"article-list-item-embed-component__title\">What We Know About Friday\u2019s Massive East Coast Internet Outage<\/p>\n<\/div>\n<\/li>\n<\/ul>\n<\/div>\n<p class=\"paywall\">Marcus Hutchins, a 22-year-old cybersecurity analyst for the security firm Kryptos Logic, spotted that trait last week, and immediately registered the web domain in WannaCry&#8217;s code. In doing so, he effectively neutered the malware, cutting short what would have otherwise been a far worse epidemic, and instantly becoming a <a href=\"https:\/\/www.usnews.com\/news\/world\/articles\/2017-05-15\/computer-expert-who-foiled-cyberattack-says-hes-no-hero\" target=\"_blank\">minor celebrity<\/a> in cybersecurity circles.<\/p>\n<p class=\"paywall\">Since then, hackers have directed armies of zombie devices\u2014webcams, modems, and other gadgets caught up in the expansive Mirai botnet\u2014to funnel junk traffic to the kill-switch web address, also called a &#8220;sinkhole,&#8221; a site security researchers direct malware to in order to contain it. The presumed intention? Knock the domain offline, trigger some of WannaCry&#8217;s dormant infections to reactivate, and end the epidemic&#8217;s nearly week-long lull.<\/p>\n<p class=\"paywall\">&#8220;Pretty much as soon as it went public what had happened, one of the Mirai botnets started on the sinkhole,&#8221; says Marcus Hutchins, the British security researcher who <a href=\"https:\/\/www.wired.com\/2017\/05\/accidental-kill-switch-slowed-fridays-massive-ransomware-attack\/\">registered the WannaCry kill-switch domain<\/a>. Since then, he says, near-daily attacks from that first botnet and others built with the same Mirai malware have steadily ticked up in size and impact.<\/p>\n<p class=\"paywall\">If the DDoS assault did succeed, not all WannaCry infections would immediately reignite. The ransomware stops scanning for new victims 24 hours after installing itself on a computer, says Matt Olney, a security researcher with Cisco&#8217;s Talos team. But anytime one of those infected machines reboots, it starts scanning again. &#8220;The ones that were successfully encrypted are in this zombie state, where they\u2019re waiting to be reactivated if that domain goes away,&#8221; says Olney.<\/p>\n<p class=\"paywall\">Hutchins says he doesn&#8217;t believe the source of the botnet attacks are the original malware authors but, rather, other groups of hackers hoping to kickstart WannaCry again just for the amusement of watching it spread. &#8220;They\u2019ve obviously got no financial incentive. They&#8217;re not the ransomware developers,&#8221; Hutchins says. &#8220;They\u2019re just doing it to cause pain.&#8221;<\/p>\n<h3 class=\"paywall\">Mirai Image<\/h3>\n<p class=\"paywall\">The first DDoS attack, Hutchins says, was so small he barely noticed it. &#8220;It was sort of a love-tap from a botnet,&#8221; he says. But since then, he&#8217;s seen five attacks, trending upward. On Wednesday, Mirai hit the sinkhole domain with its worst flood yet, 20 gigabits per second of traffic. For comparison, that&#8217;s less than a fiftieth of the size of the <a href=\"https:\/\/www.wired.com\/2016\/10\/internet-outage-ddos-dns-dyn\/\">Mirai DDoS that hit the DNS provider Dyn in September<\/a> and knocked major websites offline, but 20 times the gigabit-per-second that DDoS-tracking firm Arbor Networks <a href=\"https:\/\/www.arbornetworks.com\/arbor-networks-releases-global-ddos-attack-data-for-1h-2016\" target=\"_blank\">measured<\/a> as an average attack in 2016.<\/p>\n<p class=\"paywall\">Hutchins says he has no doubt that he and his colleagues at Kryptos Logic can still keep the attackers at bay. They&#8217;ve now enlisted the services of a DDoS mitigation firm that he declines to name\u2014he says identifying it might help the attackers make their attacks more efficient. The service should help absorb any future attacks, and even take over the domain from Kryptos Logic if necessary. But before Hutchins fully engaged that protection service, he says the pressure to keep the sinkhole online and safe from attack was intense. He pulled an all-nighter after registering it to make sure it stayed up, and didn&#8217;t sleep more than three consecutive hours until Tuesday.<\/p>\n<p class=\"paywall\">Even though Hutchins&#8217; domain has protection, it&#8217;s not the only one that&#8217;s key to preventing WannaCry&#8217;s spread. Over the weekend, another variant of the worm appeared, designed to connect to a different web address. Researcher Matt Suiche, the Dubai-based founder of security firm Comae Technologies, quickly registered it to enable a new kill-switch. Suiche says that he&#8217;s also experienced at least one DDoS attack against his domain, but declined to say more, or comment on how he&#8217;s protecting it.<\/p>\n<div class=\"inset-left-component paywall inset-left-component--pullquote\" readability=\"9\">\n<blockquote name=\"inset-left\" class=\"inset-left-component__el\" readability=\"5\">\n<p>&#8216;Now any idiot and their dog can set up a Mirai botnet.&#8217;<\/p>\n<\/blockquote>\n<p name=\"inset-left\" class=\"inset-left-component__el\">Marcus Hutchins, Kryptos Logic<\/p>\n<\/div>\n<p class=\"paywall\">It&#8217;s not clear exactly who&#8217;s behind the sinkhole attacks. But Hutchins says he&#8217;s fairly sure it&#8217;s not the original authors of the WannaCry malware itself. He says the attacks appear to be coming instead from known knockoffs of the original Mirai botnet that began to pop up when <a href=\"https:\/\/www.wired.com\/2016\/12\/botnet-broke-internet-isnt-going-away\/\">Mirai&#8217;s creator released the code<\/a> for the internet-of-things-hijacking tool.<\/p>\n<p class=\"paywall\">&#8220;Now any idiot and their dog can set up a Mirai botnet,&#8221; Hutchins says. He believes the attackers are likely nihilistic, low-skilled hackers using public tools to cause mayhem for their own entertainment.<\/p>\n<p class=\"paywall\">In this case, however, the Mirai attacks are more than a nuisance or a temporary disruption. The WannaCry malware that those attacks seek to reactivate has caused untold thousands of victims to lose data\u2014in some cases, permanently\u2014and even paralyzed life-saving health care systems. That makes the repeated attacks on Hutchins&#8217; sinkhole especially sadistic, perhaps even more so than the creation of the ransomware in the first place, Hutchins argues. &#8220;The initial developers were doing it for money,&#8221; he says. &#8220;These people are doing it just of the fun of hurting people. Which I guess is worse.&#8221;<\/p>\n<p>Read More <a href=\"https:\/\/www.wired.com\/2017\/05\/wannacry-ransomware-ddos-attack\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The &#8220;sinkhole&#8221; domain that&#8217;s held the ransomware in check is coming under repeated denial-of-service attacks. The post Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks appeared first on WIRED. Read More HERE&#8230;<\/p>\n","protected":false},"author":1,"featured_media":212,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[85],"tags":[],"class_list":["post-211","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wired"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-05T02:30:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2292\" \/>\n\t<meta property=\"og:image:height\" content=\"1200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"thadmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thadmin\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"thadmin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/\"},\"author\":{\"name\":\"thadmin\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/b07e00649871a6dd150cd57b33f7db66\"},\"headline\":\"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks\",\"datePublished\":\"2018-05-05T02:30:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/\"},\"wordCount\":1091,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg\",\"articleSection\":[\"Wired\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/\",\"name\":\"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg\",\"datePublished\":\"2018-05-05T02:30:33+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/05\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg\",\"width\":2292,\"height\":1200},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/b07e00649871a6dd150cd57b33f7db66\",\"name\":\"thadmin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/64b2823a5e0933c780cab004122ddae4375b28e7a87014931eaea97478ab540f?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/64b2823a5e0933c780cab004122ddae4375b28e7a87014931eaea97478ab540f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/64b2823a5e0933c780cab004122ddae4375b28e7a87014931eaea97478ab540f?s=96&d=mm&r=g\",\"caption\":\"thadmin\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/thadmin\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-05-05T02:30:33+00:00","og_image":[{"width":2292,"height":1200,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg","type":"image\/jpeg"}],"author":"thadmin","twitter_card":"summary_large_image","twitter_creator":"@thadmin","twitter_site":"@threatshub","twitter_misc":{"Written by":"thadmin","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/"},"author":{"name":"thadmin","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/b07e00649871a6dd150cd57b33f7db66"},"headline":"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks","datePublished":"2018-05-05T02:30:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/"},"wordCount":1091,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg","articleSection":["Wired"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/","url":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/","name":"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg","datePublished":"2018-05-05T02:30:33+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/05\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks.jpg","width":2292,"height":1200},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-trying-to-reignite-wannacry-with-nonstop-botnet-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Hackers Are Trying to Reignite WannaCry With Nonstop Botnet Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/b07e00649871a6dd150cd57b33f7db66","name":"thadmin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/64b2823a5e0933c780cab004122ddae4375b28e7a87014931eaea97478ab540f?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/64b2823a5e0933c780cab004122ddae4375b28e7a87014931eaea97478ab540f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/64b2823a5e0933c780cab004122ddae4375b28e7a87014931eaea97478ab540f?s=96&d=mm&r=g","caption":"thadmin"},"sameAs":["https:\/\/x.com\/thadmin"]}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=211"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/211\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/212"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}