EternalRomance is a leaked NSA-developed SMB exploit targeting Microsoft Windows systems. The provided content states that it exploits CVE-2017-0143, an SMB vulnerability addressed by Microsoft in MS17-010, and that later ports expanded support across a broad range of Windows versions from Windows 2000 through Windows 10 and Server 2016 on both 32-bit and 64-bit architectures. It is described as enabling remote code execution with high privileges and as being integrated alongside other NSA SMB tooling such as EternalBlue and EternalSynergy. The exploit was leaked by the Shadow Brokers in 2017 and later adapted into the Metasploit Framework by Sean Dillon of RiskSense. The content also states that EternalRomance was used in major destructive campaigns including NotPetya and Bad Rabbit. In one reported Blackmoon/KRBanker campaign targeting businesses primarily in the United States and Canada, a spreader component dropped Eternalromance-1.4.0.exe into C:\Windows\Temp together with EternalBlue and DoublePulsar-related components for lateral movement. The broader reporting also links EternalRomance to NSA tooling exposure and subsequent reuse by other actors, including Buckeye/APT3 according to Symantec’s assessment of repurposed NSA SMB capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Besides EternalBlue, the NotPetya and Bad Rabbit ransomware outbreaks also utilized the EternalRomance exploit that Dillon has recently ported to target a more broader spectrum of Windows versions.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Our analysis of the artifacts and network traffic at victim networks indicate that modified versions of the EternalBlue and EternalRomance SMB exploits were used, at least in part, to spread laterally.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit dropped by the spreader component as part of the toolkit used for network propagation.
NSA SMB exploit tool referenced as part of the leaked NSA toolkit; used for compromising Windows systems via SMB.
An NSA-developed exploit leaked by Shadow Brokers and subsequently leveraged in major destructive campaigns alongside other leaked exploit tooling.
Leaked NSA SMB exploit ported to support a broader range of Windows versions; used to gain elevated access and explicitly linked to ransomware outbreaks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.