A renewed WannaMine outbreak is compromising Windows systems by exploiting the SMB flaws addressed in MS17-010, including the EternalBlue attack path that was also used by WannaCry. After achieving privileged code execution on unpatched hosts, the worm uses PowerShell and WMI to identify system architecture, fetch the correct payload, move laterally across the network, and execute its cryptomining components directly in memory.
Investigators found the malware also compiles and uses PingCastle to locate additional vulnerable machines, deploys a PowerShell implementation of Mimikatz for credential theft and lateral movement, and hides components in WMI classes while creating WMI event-based persistence. It further changes power settings to keep systems active for mining and terminates competing miners on common mining ports, underscoring that organizations remain exposed largely because systems vulnerable to the long-patched MS17-010 flaws are still present in enterprise environments.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft issued security bulletin MS17-010 to patch the SMB vulnerabilities later exploited by EternalBlue-based malware such as WannaCry, NotPetya, and WannaMine.
Cybereason's Nocturnus team investigated a new outbreak of WannaMine that spread by exploiting unpatched SMB services with EternalBlue. The analyzed variant used PowerShell and WMI for execution, lateral movement, persistence, credential theft, and in-memory cryptomining.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.