WannaCry 2.0 is a ransomware family publicly attributed to North Korean state-sponsored cyber actors and widely associated with Lazarus Group. It emerged in May 2017 and caused a global disruptive outbreak that infected hundreds of thousands of computers across more than 150 countries, affecting hospitals, schools, businesses, and home users. The malware encrypts data on infected systems and presents ransom demands payable in Bitcoin. Public reporting and government attributions characterize the operation as both destructive and extortion-driven, and link it to broader DPRK cyber activity intended to generate revenue and create disruptive effects.
WannaCry 2.0 is notable for its large-scale impact on critical and civilian environments, including severe disruption to healthcare operations. It is part of a broader pattern of DPRK-linked cyber operations spanning espionage, financial theft, extortion, and destructive attacks. Multiple governments, including the United States, Australia, Canada, New Zealand, and the United Kingdom, publicly attributed the WannaCry 2.0 attack to North Korea in December 2017. U.S. government actions and sanctions announcements have further tied the malware to Lazarus Group and the Reconnaissance General Bureau.
At high confidence, WannaCry 2.0’s core behavior is file encryption for ransom-based extortion on Windows systems. The supplied facts do not directly establish a specific delivery mechanism for this malware and therefore no delivery vector is asserted here.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DPRK state-sponsored cyber actors developed the ransomware known as WannaCry 2.0, as well as two prior versions of the ransomware. In May 2017, WannaCry 2.0 ransomware infected hundreds of thousands of computers in hospitals, schools, businesses, and homes in over 150 countries. WannaCry 2.0 ransomware encrypts an infected computer’s data and allows the cyber actors to demand ransom payments in the Bitcoin digital currency.
Ransomware and Cyber-Enabled Extortion : Creation of the destructive WannaCry 2.0 ransomware in May 2017, and the extortion and attempted extortion of victim companies from 2017 through 2020 involving the theft of sensitive data and deployment of other ransomware.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Lazarus Group targets institutions such as government, military, financial, manufacturing, publishing, media, entertainment, and international shipping companies, as well as critical infrastructure, using tactics such as cyber espionage, data theft, monetary heists, and destructive malware operations.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior North Korea-linked ransomware operation used for comparison of ransom demand levels.
Destructive ransomware attributed in the content to North Korean operators, used in ransomware and extortion activity.
Ransomware attributed in the advisory to DPRK state-sponsored cyber actors; it encrypts infected systems’ data and is used to demand Bitcoin ransom payments. The campaign impacted hundreds of thousands of computers globally across more than 150 countries.
Destructive ransomware that affected at least 150 countries, shut down approximately 300,000 computers, and severely disrupted the UK National Health Service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.