'Wanna' Ransomware Outbreak

What You Need to Know to Stay Protected

Stop Wanna with Intercept X – Try for Free Watch our Wanna Webcast

What is Wanna Ransomware?

A new ransomware attack called 'Wanna' (also known as WannaCry, WCry, WanaCrypt, WanaCrypt0r, or Wanna Decrypt0r) is encrypting files and changing the extensions to: .wnry, .wcry, .wncry and .wncrypt.

For the latest information about how to stay protected,
refer to the Sophos Knowledge Base article.

For additional information on this attack
see the Sophos News blog


How Do I Stay Protected?

1. Update all Windows environments as described in Microsoft Security Bulletin MS17-010.

2. Whitelist any kill switch domains related to this attack. 

3. Update your endpoint software to ensure you have the latest protections for this threat.

4. Ensure you are running advanced ransomware protection such as Intercept X or Sophos Exploit Prevention (EXP).

5. Home users, consider signing up for the Sophos Home Premium beta, which adds advanced protection from ransomware.

How Sophos Protects Against
WannaCry Ransomware

How Sophos Protects Against WannaCry Ransomware

Intercept X Is the Most Advanced
Ransomware Protection Available

The proven CryptoGuard capabilities in Sophos Intercept X block ransomware as soon as it starts trying to encrypt your files, returning data to its original state. Intercept X:

  • Protects endpoints from ransomware attacks
  • Automatically rolls back encrypted file changes with no data loss
  • Stops both local and remote file encryption

Know Your Enemy

Ransomware is a $1 billion business that often evades traditional anti-malware. Learn what you're up against and how to stop it

Read Paper

Stop Ransomware Now

Sophos Intercept X is proven to stop ransomware in its tracks, including all Wanna variants, by blocking the unauthorized encryption of files.

Learn More

  • We deployed Intercept X to more than 5,000 endpoints. Since deploying, it has stopped 400 new ransomware attacks and we’ve had zero ransomware infections.
    Emily Vandewater,
    IT Security Analyst, Flexible Systems
  • Installing Sophos Intercept X alongside existing endpoint protection is simple and effective. We have found that it blocks threats faster and provides comprehensive and straightforward analysis of an attack.
    Bob Appleby,
    Partner, PA, Computer Connections
  • Intercept X has been one of the most seamless deployments and transitions that I have experienced. And the visibility it gives me into what my click-happy users are doing has been without equal.
    Emile Belcourt,
    Technical Engineer, Globelink
  • Sophos is again simplifying what has previously been a complex and difficult process — and that's what makes Intercept X really unique.
    James Miller,
    Managing Director, Foursys