WannaCry, also known as WannaCrypt or Wcry, is a Windows ransomware family notable for worm-like propagation during its 2017 global outbreak. It exploited the SMB vulnerability addressed by Microsoft’s MS17-010 update, enabling autonomous spread across vulnerable systems on local networks and across the internet. The outbreak affected more than 300,000 computers in roughly 150 countries and disrupted organizations including hospitals, factories, and businesses. WannaCry deployed a ransomware component that encrypted victim data and presented ransom demands. Its propagation chain used EternalBlue to compromise susceptible SMB services and could install the DoublePulsar kernel-level backdoor before delivering the ransomware payload. DoublePulsar enabled in-memory remote payload execution and could leave compromised hosts accessible until rebooted, including in variants whose encryption functionality was absent or broken. WannaCry used a modular design separating SMB worm propagation from encryption and user-interface components, and established execution through a Windows service. Earlier variants were also reported to have circulated through cloud-storage-based delivery channels. A kill-switch domain in the principal outbreak sample could halt ransomware execution, although it did not stop already infected systems from continuing propagation attempts; modified variants have been observed with this protection disabled.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The ransomware spread appears to leverage an SMB exploit from the April 2017 Shadow Brokers dump... eSentire highly recommends that MS17-010 patches be deployed immediately... The Microsoft SMB vulnerability is the primary means of the ransomware spreading while inside the network.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | On Friday May 12th, the WannaCry ransomware was distributed using a worm leveraging the EternalBlue SMB exploit. After successful exploitation, it installs the DoublePulsar backdoor and then proceeds to load the ransomware component.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | On Friday May 12th, the WannaCry ransomware was distributed using a worm leveraging the EternalBlue SMB exploit. After successful exploitation, it installs the DoublePulsar backdoor and then proceeds to load the ransomware component.
the ransomware perpetrators used publicly available exploit code for the patched SMB “EternalBlue” vulnerability, CVE-2017-0145, which can be triggered by sending a specially crafted packet to a targeted SMBv1 server. This vulnerability was fixed in security bulletin MS17-010 | Threats like WannaCrypt (also known as WannaCry, WanaCrypt0r, WCrypt, or WCRY) ... used publicly available exploit code for the patched SMB “EternalBlue” vulnerability, CVE-2017-0145.
One example of this is wormable ransomware attacks that take advantage of Windows vulnerabilities to propagate throughout a network. WannaCry ransomware leveraged this method in 2017, and in a recent security advisory, Microsoft warned of a newly disclosed remote desktop services vulnerability that adversaries could use for a similar attack... patches for some vulnerabilities such as Common Vulnerabilities and Exposures (CVE) CVE-2019-0708, or MS17-010, and patches for the remote desktop vulnerability and WannaCry, respectively, are all vital to apply.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As in the case of Wannacry, attribution is very difficult and finding links with previously known malware is challenging.
Five years ago, the WannaCry ransomware cryptoworm targeted computers running Microsoft Windows, encrypting data at organizations around the world.
WannaCry paralysed computers running mostly older versions of Microsoft Windows by encrypting users' computer files and displaying a message demanding anywhere from $US300 to $US600 to release them; failure to pay would leave the data mangled and likely beyond repair.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
The WannaCry attack was a massive ransomware cyberattack... This ransomware leverages an NSA exploit known as EternalBlue... Wincry was the base of the encryption, but two additional exploits, EternalBlue and DoublePulsar, were used by the malware to make it a cryptoworm.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
攻撃者は事前に作成した秘密鍵(Key)を使用してマルウェアを暗号化しておきます。... 対象が標的の場合、マルウェアを復号して攻撃を行います。
ターゲット端末では受信した「launcher.dll」をファイル化することなく、メモリ上で処理し「lsass.exe」にインジェクション(注入)します。
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Based on an analysis in our labs, we have confirmed that the ETERNALBLUE exploit is one of the propagation vectors.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Autonomous ransomware worm that used an SMB exploit to self-propagate across and between networks. The article estimates it spread to approximately 3–16 million computers, although its kill-switch limited encryption to a couple hundred thousand systems.
Ransomware mentioned only as historical context for attention received by NSA Tailored Access Operations; the article does not discuss its behavior beyond identifying it as ransomware that used an NSA-developed exploit.
Ransomware that spread rapidly across connected networks by exploiting an SMB vulnerability, causing widespread global disruption.
Ransomware worm referenced as an example of rapid exploitation following patch availability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.