Industry News

Cyberspace Data Governance Expert


Real issues | Mobile news client public opinion analysis report on the "WannaCry Blackmail Worm" incident
  31 May 2017From: Surfilter

I. Background

On May 12th, 2017, the WannaCry Blackmail Worm broke out taking advantage of the MS17-010 vulnerability around the world and infected a large number of computers. After the Blackmail Worm infects the computer, it implants malicious extortion software in the computer. After encrypting a large number of files, it prompts the user to pay Bitcoins worth US$300 (about RMB 2069) to decrypt the files. This Blackmail Worm spread rapidly in a short period of time, and a large number of computers in the United Kingdom, Russia, the whole of Europe and China, especially those with large intranet with weak protection, got infected.




II. Public Opinion Statistics

The mobile news client public opinion monitoring system independently researched and developed by Surfilter can perform real-time monitoring and analysis of more than 60 major mobile news clients nationwide. After the outbreak of the worm incident, Surfilter immediately launched a special monitoring of the related public opinion on mobile news clients and conducted comprehensive statistics and in-depth analysis on the news release status and comments by netizens. The monitoring and analysis staus for the time window from 0:00 on May 12th, 2017 to 24:00 on May 22nd, 2017 is as follows:


2.1 News release volume statistics

From 0:00 on May 12th, 2017 to 24:00 on May 22nd, 2017, there were 4,896 articles related to the WannaCry Blackmail Worm incident released on mobile news clients, and the social attention was very high.



Due to the suddenness of the worm and as the time of the outbreak was on the evening of the 12th Beijing time, there were fewer reports on the worm on the 12th. In the early morning of the 13th, the influence of the WannaCry Blackmail Worm continued to expand, media attention increased sharply, and related public opinion reached its peak on the 15th.


2.2 Active media analysis



As shown in the above figure, the most active news clients for the WannaCry Blackmail Worm incident were UC headlines, Tencent News and Sina News, with 581, 523 and 521 news releases, respectively.


2.3 Comments volume statistics



With the increase in the number of news reports, netizens' attention to the incident continued to rise. It also reached its peak on May 15th, with a single-day comments volume of 270,764. As shown above.



In the monitored news clients, most users expressed their views on this event except in case of some systems that did not permit commenting. Among them, users of Netease News commented the most on the worm incident, the cumulative number of comments reached 851,062, accounting for 83% of comment volume across all news clients.


2.4 Netizen attention hotspot analysis

According to the number of comments, the most of interest and commented news by netizens was as follows:



On May 13: Virus attacks in many universities & colleges and blackmail hackers demand Bitcoin as ransom


The blackmail virus spread across the country. Large amounts of money used to successfully stop the disaster


Tencent Security Anti-Virus Lab Analyzed "Wannacry" Ransomware


On May 14: Beijing Municipal Department issued a notice: it is recommended to immediately destroy the  blackmail virus variant


Ransomware virus has now been modified: Cancel the propagation speed of this Kill Switch or it may change faster

On May 15: How powerful is the blackmail virus? Reporters demonstrate the process of getting infected and restoring the system


How fragile is the blackmail virus engulfing the global US network arsenal?


On May 16: Google, Kaspersky, etc., find that the evil backend manipulator of the blackmail virus may have come from North Korea


On May 17: The blackmail virus has not yet ended, and the manipulator behind it is strong!


On May 18: Media: Who is the mastermind behind the blackmail virus? The waters are deep.  


Microsoft CEO gives a statement on the ransomware virus: angrily rebukes the US intelligence agency


On May 19: Zhou Hongyi comments on the ransomware virus: the online nuclear bomb was used for a very vulgar extortion


On May 20: North Korean officials: It is ridiculous to link large-scale internet attacks with North Korea


May 21: British media: "WannaCry" virus has wiped out the reputation of the US Security Bureau, Microsoft may become the biggest beneficiary


On May 22: Blackmail virus sweeps across the globe: network security protection is imminent


2.5 Topic concentration analysis

Surfilter’s mobile news client analysis conducted keyword extraction and topic cluster analysis through the news reports on this event. It can be seen that media reports mainly focused on the following topics:



Topic 1: Computer ransomware virus breaks out around the world; many university campus networks in China attacked. The number of news releases on this topic was 189, which accounts for 3.86%.


Topic 2: Reporting media: The Beijing Municipal Department issued a notice: it is recommended to immediately resolve the blackmail virus variant. The number of news releases on this topic was 133, which accounts for 2.72%.


Topic 3: British media: "WannaCry" virus has wiped out the reputation of the US Security Bureau, Microsoft may become the biggest beneficiary The number of news releases on this topic was 130, which accounts for 2.66%.


Topic 4: The United Kingdom and the Spain were attacked by hackers on the same day. The hacker wrote a message: Pay the ransom if you want to restore the system. The number of news releases on this topic was 118, which accounts for 2.42%.


Topic 5: Tencent Security Anti-Virus Lab illustrates "WannaCry" blackmail software. The number of news releases on this topic was 106, which accounts for 2.17%.


III. Public opinion comments

Through this special monitoring work, we can see the following characteristics of public opinions in the current news clients:


1. Mobile news clients have become the main business approach of the news media. For a relatively professional news event such as the Blackmail Worm, almost all news media quickly released something through their mobile news clients and received enthusiastic responses from users.


2. Network security issues are deeply rooted in the hearts of the people, netizens not only pay attention to them to a high degree, but they also reflect a certain degree of professionalism. In the field of news communication, network security has gradually evolved from a specialized technical topic to a social topic.


3. Netizens' interest in this Blackmail Worm presents a certain "scenario", that is, the focus at the beginning is mainly on the harm and impact scope. As the worm's diffusion momentum was controlled, the attention of netizens turned to the analysis and conjecture of the identity and motivation of the evil backend manipulator.


This Blackmail Worm incident once again sounded the alarm in network security, reflecting the severe current challenges in network security protection and emergency response work. With further penetration of internet technology into social activities, the threat and harm of internet attacks will become an unbearable burden on contemporary society. Network security has become a key issue related to national security and social life.


Introduction of Surfilter’s mobile news client monitoring system

Surfilter’s mobile news client monitoring system takes "full control, in-depth analysis, comprehensive solution" as the product’s concept, and combines the characteristics of various industries to build a vertically segmented mobile news client public opinion monitoring system. It provides a closed-loop business system, which includes news monitoring, news search, news alert, special analysis, news guidance and process management. It combines various modules holistically and practically, to ensure that the user units can quickly, accurately and comprehensively grasp development trends of related activities in the mobile internet, in order to guide and handle issues on time.


Prev:NO More

Next:NO More

BACK
Related_News