WannaCry encrypted files across organizations worldwide after a worm component exploited the Windows SMBv1 flaw patched in MS17-010, driving rapid propagation beyond initial phishing-based infections. Reported victims included the UK's NHS, Telefónica, Iberdrola, Russia's Interior Ministry, FedEx, and Deutsche Bahn, while hotspots were reported in Ukraine, Taiwan, and later China. Infected systems typically displayed ransom demands of $300 or $600 in Bitcoin, and Microsoft issued emergency patches even for unsupported platforms such as Windows XP as governments and incident responders urged organizations to report infections and patch exposed systems.
Technical analysis found the malware checked a kill-switch domain, scanned local and random external IP ranges, looked for the DoublePulsar backdoor, and used EternalBlue when DoublePulsar was absent to deliver the ransomware payload. WannaCry used RSA-2048 and AES-128 for encryption, deleted shadow copies and recovery artifacts, terminated database and Exchange-related processes, and communicated with Tor hidden services over an encrypted protocol. Later reporting indicated Windows 7 and Windows Server 2008 accounted for most infections, while many XP systems crashed instead of reliably propagating the worm; researchers also noted the kill-switch likely prevented far more infections and that shared Bitcoin wallets reduced confidence that paying victims would be consistently decrypted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On 2017-12-19, the United States and United Kingdom publicly blamed North Korea for the WannaCry ransomware attack. This marked a significant official attribution development months after the initial outbreak.
On 2017-06-14, Microsoft released additional out-of-band security updates for unsupported Windows versions including Windows XP and Windows Server 2003, warning of elevated risk of destructive attacks similar to WannaCry. The updates addressed 16 vulnerabilities, most rated critical, amid concern over leaked NSA exploit tools such as EternalBlue.
By 2017-05-30, researchers reported that Windows XP systems often crashed with a blue screen instead of successfully installing or spreading WannaCry via the common SMB exploit path. The analysis indicated most infections were concentrated on Windows 7 and Windows Server 2008 rather than XP.
On 2017-05-23, reporting cited nearly 1 million infected computers observed in China, indicating a significant regional surge after the initial global outbreak. Analysts linked the scale in part to slower adoption of newer Windows versions.
By 2017-05-18, security researchers reported a WannaCry implementation flaw that could help some victims recover files under limited conditions. The finding suggested decryption or recovery might be possible for certain affected Windows systems.
On 2017-05-16, researchers reported code similarities between an early WannaCry sample and malware previously associated with the Lazarus Group, prompting investigation into a possible North Korean connection. Multiple security firms said the overlap was noteworthy, though attribution remained unconfirmed at the time.
On 2017-05-15, Check Point reported a new WannaCry kill switch and sinkhole activity, indicating defenders were tracking variant behavior beyond the initial domain registration. This reflected ongoing technical analysis and containment efforts as the campaign evolved.
On 2017-05-13, Germany's Federal Office for Information Security called on affected organizations to report WannaCry infections and apply available patches. The agency framed the outbreak as a wake-up call for stronger long-term cybersecurity practices.
On 2017-05-13, researchers registered a WannaCry kill-switch domain checked by the worm, which significantly curtailed further spread of the initial variant. Later reporting estimated this action may have prevented millions of additional infections.
During the outbreak, Microsoft released emergency security updates for unsupported systems including Windows XP to help defend against WannaCry. This was an extraordinary response because XP had been out of normal support since 2014.
As the outbreak unfolded, victims reported across multiple countries included the UK's NHS, Telefónica, Iberdrola, Russia's Interior Ministry, FedEx, Deutsche Bahn, and organizations in Ukraine and Taiwan. The incident caused broad operational disruption in enterprises and public institutions.
Beginning on the evening of 2017-05-12, the WCry/WannaCry ransomware campaign spread rapidly worldwide, encrypting files and demanding roughly $300 in Bitcoin. Its rapid propagation was driven by an SMB worm exploiting the SMBv1 flaws addressed in MS17-010.
On 2017-03-14, Microsoft released bulletin MS17-010 to fix Windows SMBv1 vulnerabilities later used by WannaCry's worm component. Systems that had applied this update were reported as protected from the main propagation method.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
sophos.com
Open sourcetechcrunch.com
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourceheise.de
Open sourcebleepingcomputer.com
Open sourceblog.talosintelligence.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.