EternalBlue is a leaked NSA-developed Windows SMBv1 remote code execution exploit associated with CVE-2017-0144 and Microsoft bulletin MS17-010. The content describes it as an exploitation tool or family of zero-day vulnerabilities targeting Windows systems, particularly pre-Windows 10 / pre-Windows 8-era systems, abusing flaws in the SMBv1 implementation in srv.sys to achieve kernel-level code execution without user interaction. It was leaked by The Shadow Brokers on 2017-04-14 in the “Lost in Translation” release and is frequently paired with the DoublePulsar backdoor for post-exploitation and worming.
The exploit is repeatedly described as enabling attackers to break into vulnerable Windows hosts, move laterally across networks, and spread malware automatically in a wormable fashion over SMB, typically via TCP 445 and sometimes 139. Supporting content states that malware and campaigns such as WannaCry/WCry/WanaCry, NotPetya, Bad Rabbit, RobbinHood-related activity, and a staged Blackmoon/KRBanker campaign used EternalBlue, often together with DoublePulsar, to propagate across victim environments. WannaCry is specifically described as using EternalBlue for initial SMB exploitation and DoublePulsar to install and execute the ransomware payload; NotPetya is described as using EternalBlue in combination with Mimikatz for rapid spread.
Technical details directly mentioned in the content include exploitation of SMBv1 transaction handling and a data displacement anomaly detectable in SMB Trans2 Secondary packets, as well as reverse-engineering research tying EternalBlue to a non-paged pool overflow in srv.sys caused by FEA conversion and transaction parsing bugs. The content also notes that EternalBlue traffic can be detected by protocol-aware inspection of SMBv1 packets associated with CVE-2017-0144. High-confidence associations in the content include The Shadow Brokers as the leak source, the NSA/Equation Group as the origin of the capability, and operational use or repurposing by actors including BackdoorDiplomacy, Buckeye/APT3, North Korean operators in WannaCry, and Russian operators in NotPetya. The primary targeted platform is vulnerable Windows systems exposing SMBv1; impacted sectors and victims mentioned across the content include healthcare, government, transportation, logistics, and enterprises worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this article, we provide another example, showcasing how to detect the famous EternalBlue exploitation vector (CVE-2017-0144).
CVE-2017-0143 Vulnerable Products: Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 Associated Malware: Multiple using the EternalSynergy and EternalBlue Exploit Kit Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0143 Vulnerable Products: Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 Associated Malware: Multiple using the EternalSynergy and EternalBlue Exploit Kit
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.
If the DoublePulsar backdoor does not exist, then the SMB worm attempts to compromise the target using the Eternalblue SMBv1 exploit.
"...the Shadow Brokers hacked and disclosed a cache of stockpiled NSA cyber capabilities, including the EternalBlue vulnerability, which was later used in the devastating WannaCry and NotPetya ransomware attacks."
"The NSA-developed Windows exploit EternalBlue was stolen and exposed in 2017, eventually enabling destructive operations like North Korea’s WannaCry attack and Russia-linked NotPetya hacks."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
Around January this year, Microsoft was tipped off ... that the NSA's Eternalblue cyber-weapon, which can compromise pre-Windows 10 systems via an SMBv1 networking bug, had been stolen and was about to leak into the public domain.
Our analysis of the artifacts and network traffic at victim networks indicate that modified versions of the EternalBlue and EternalRomance SMB exploits were used, at least in part, to spread laterally.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A leaked NSA-linked Windows exploit set described as enabling system intrusion, lateral movement, and automatic malware propagation. It later underpinned major destructive attacks.
A leaked NSA-linked exploit family targeting Windows that enabled network compromise, lateral spread, and deployment of self-propagating worms.
SMBv1 remote code execution exploit used by WannaCry for initial access and worm-like propagation by triggering a kernel memory corruption condition via crafted SMB packets.
Leaked NSA exploit later abused broadly by criminals, including in ransomware campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.