The WannaCry (WanaCrypt0r 2.0) ransomware outbreak encrypted tens of thousands of computers across roughly 99 to 100 countries, disrupting organizations including UK NHS hospitals, Telefónica, and FedEx. The malware demanded a $300 ransom and spread by exploiting a Windows vulnerability tied to offensive tools allegedly used by the NSA and later leaked by the Shadow Brokers. Microsoft had already released fixes for supported Windows versions, but many victims had not applied them, and the scale of the incident prompted the company to take the unusual step of issuing emergency patches for legacy platforms including Windows XP, Windows 8, and Windows Server 2003.
Investigators said the attackers had collected only about $20,000 in bitcoin in the early stages, with payments traced to a small number of monitored wallets, suggesting limited financial returns despite the global disruption. UK officials said they believed the incident was criminal rather than a state attack, while researchers noted that bitcoin's pseudonymous nature could still allow law enforcement to trace funds through exchanges. The outbreak later began to slow after a researcher discovered a kill switch, but the incident highlighted the operational risk posed by delayed patching, exposed legacy systems, and the public release of weaponized exploits.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
Boeing reportedly responded to a WannaCry infection at its Charleston, South Carolina production plant, issuing an internal alert as the malware spread from North Charleston systems. The incident raised concerns about disruption to 777 automated spar assembly tools and possible spread to equipment involved in airplane testing.
The United States and United Kingdom publicly said WannaCry was carried out by North Korean actors, identifying the Lazarus Group and saying it was highly likely backed by the North Korean government. The announcement marked a significant shift from earlier uncertainty over who was responsible for the outbreak.
A National Audit Office report found the NHS was unprepared for the WannaCry attack and said the disruption could have been largely prevented with basic cybersecurity practices, including patching and supported systems. The report documented how the outbreak affected NHS organizations and criticized longstanding IT security weaknesses.
Flashpoint published an analysis of WannaCry's 28 embedded ransom notes and found that most non-English and non-Chinese versions appeared machine-translated, while the English and especially the Chinese notes showed signs of human authorship. The firm said with high confidence that the note authors were fluent in Chinese and familiar with English, and assessed with moderate confidence that the Chinese note may have been the original source text.
South African telecom provider Telkom was reported to have systems crippled by the WannaCry ransomware outbreak. The disclosure added Telkom as a specifically identified victim affected by the global campaign.
Quarkslab researcher Adrien Guinet released Wannakey, a tool intended to recover WannaCry decryption keys from some infected Windows XP machines without paying the ransom. The method relied on key material potentially remaining in memory if the system had not been rebooted, though early reporting said it had limited validation and might not work in all cases.
Australian officials said eight Australian businesses were likely affected by WannaCry, while critical infrastructure, government agencies, and the health system had not been impacted at that stage. Authorities warned the threat was ongoing and urged organizations to apply Microsoft patches rather than pay ransoms.
Researchers reported a new WannaCry variant using a different kill-switch domain and set up a new sinkhole to monitor and help blunt its spread. The finding showed attackers had modified the malware after the initial kill switch was triggered, creating a new technical development in the outbreak.
Researchers including Google’s Neel Mehta, Comae Technologies, and Kaspersky reported code similarities between an early WannaCry sample and malware previously associated with the Lazarus Group. The finding suggested a possible North Korea link, though analysts cautioned that attribution remained unconfirmed at the time.
Timrå Municipality disclosed that around 70 computers had been infected by WannaCry, with officials estimating up to 100 systems could be affected before containment. The incident disrupted some administrative operations, though the municipality said healthcare-related services were not impacted and that it did not pay the ransom.
Indonesian officials confirmed that Dharmais Hospital in Jakarta was affected by the WannaCry outbreak, though reports said there was no major impact on patient care. The disclosure identified a new healthcare victim in Asia tied to the global ransomware campaign.
Reporting said the WannaCry outbreak disrupted systems in China, including police operations, China National Petroleum Corp petrol stations that shifted to cash-only payments, and networks at several universities such as Tsinghua and Peking University. China’s national computer emergency response body, CNCERT, urged Windows users to apply Microsoft patches as public-sector and academic institutions issued warnings.
In an unusual move, Microsoft released public security patches for unsupported or custom-support platforms including Windows XP, Windows 8, and Windows Server 2003. The emergency action was intended to help organizations defend against the ongoing WannaCry attack.
A 22-year-old researcher in the UK discovered a kill switch that appeared to slow the ransomware's propagation. This reduced the pace of the outbreak after its initial global surge.
Investigators tracking bitcoin wallets associated with WannaCry estimated that the operators had collected only about $20,000 in ransom payments at that stage. The identified funds were reported to still be sitting in the monitored wallets.
During the early response to the outbreak, UK authorities said they believed the incident was a criminal attack rather than an attack by a foreign power. Home Secretary Amber Rudd also said the government did not yet know who was responsible.
French automaker Renault said the WannaCry outbreak affected operations, with reporting indicating production was halted at some sites as a precaution. The disclosure added Renault as a specifically identified manufacturing-sector victim of the global ransomware campaign.
UK health authorities and hospitals reported major operational disruption from WannaCry, affecting 40 NHS trusts in England, 11 Scottish health boards, and the Scottish ambulance service. Hospitals declared major incidents, shut down IT systems, cancelled routine care, diverted ambulances, and said there was no evidence at that stage that patient data had been compromised.
During the initial WannaCry outbreak, major Spanish companies were reported among the victims, with Telefonica prominently affected and other large firms also taking defensive action or reporting disruption. The disclosures highlighted Spain as one of the early heavily impacted countries in the global campaign.
A large WannaCry outbreak hit tens of thousands of computers across roughly 99-100 countries, including UK NHS hospitals, Telefonica, and FedEx. The malware encrypted systems, demanded a $300 ransom, and spread using Windows flaws linked in reporting to exploits exposed by the Shadow Brokers.
Microsoft issued a security update in March 2017 for supported Windows versions to fix the vulnerability later used by WannaCry. Systems that did not apply the patch remained exposed to exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
blog.checkpoint.com
Open sourcebbc.co.uk
Open sourcecybersecuritydive.com
Open sourceweb.archive.org
Open sourcesvt.se
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceelpais.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.