WannaCry is a Windows ransomware family that emerged in 2017 and combined file-encryption extortion with worm-like self-propagation over SMB. It is widely known for abusing the MS17-010 SMB vulnerability via the EternalBlue exploit and using the DoublePulsar backdoor to execute payloads in memory and spread laterally across vulnerable systems. The malware’s propagation logic checks for vulnerable hosts and, where possible, installs or reuses DoublePulsar to inject code into system processes, deploy service components, and launch the ransomware stage. Analysis of the family shows a modular design in which worm propagation and ransomware functionality can be separated into different binaries, allowing variants that retain network-spreading behavior even when encryption is absent or broken.
Core WannaCry infections typically register a service component, deploy a second-stage payload, and present a ransom interface while encrypting victim files. Some variants hide artifacts on disk and determine local network configuration to support propagation. Researchers have also documented modified samples that disabled the original kill-switch behavior and lacked functional encryption, effectively acting as worm-only derivatives while still spreading through SMB exploitation and service-based execution. Systems compromised during WannaCry propagation may remain exposed to post-compromise remote code execution through DoublePulsar until reboot, even after patch installation, because the backdoor resides in memory.
WannaCry primarily targets Windows environments, especially unpatched or legacy enterprise systems, and caused major global disruption across government, healthcare, and private-sector networks. The 2017 outbreak notably impacted the UK National Health Service and hundreds of thousands of systems worldwide. Public government attribution has linked the campaign to North Korea with high confidence. Beyond the original outbreak, WannaCry has remained an important reference point for wormable ransomware and SMB-driven lateral movement, and its tooling and tradecraft have influenced later malware and ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
WannaCry ransomware leveraged this method in 2017, and in a recent security advisory, Microsoft warned of a newly disclosed remote desktop services vulnerability that adversaries could use for a similar attack.
the ransomware perpetrators used publicly available exploit code for the patched SMB “EternalBlue” vulnerability, CVE-2017-0145, which can be triggered by sending a specially crafted packet to a targeted SMBv1 server. This vulnerability was fixed in security bulletin MS17-010 | Threats like WannaCrypt (also known as WannaCry, WanaCrypt0r, WCrypt, or WCRY) ... used publicly available exploit code for the patched SMB “EternalBlue” vulnerability, CVE-2017-0145.
One example of this is wormable ransomware attacks that take advantage of Windows vulnerabilities to propagate throughout a network. WannaCry ransomware leveraged this method in 2017, and in a recent security advisory, Microsoft warned of a newly disclosed remote desktop services vulnerability that adversaries could use for a similar attack... patches for some vulnerabilities such as Common Vulnerabilities and Exposures (CVE) CVE-2019-0708, or MS17-010, and patches for the remote desktop vulnerability and WannaCry, respectively, are all vital to apply.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As in the case of Wannacry, attribution is very difficult and finding links with previously known malware is challenging.
Five years ago, the WannaCry ransomware cryptoworm targeted computers running Microsoft Windows, encrypting data at organizations around the world.
WannaCry paralysed computers running mostly older versions of Microsoft Windows by encrypting users' computer files and displaying a message demanding anywhere from $US300 to $US600 to release them; failure to pay would leave the data mangled and likely beyond repair.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
The WannaCry attack was a massive ransomware cyberattack... This ransomware leverages an NSA exploit known as EternalBlue... Wincry was the base of the encryption, but two additional exploits, EternalBlue and DoublePulsar, were used by the malware to make it a cryptoworm.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
there are two entry points through which a municipality can be attacked: social engineering and a breach in un-updated software.
ターゲット端末では受信した「launcher.dll」をファイル化することなく、メモリ上で処理し「lsass.exe」にインジェクション(注入)します。
攻撃者は事前に作成した秘密鍵(Key)を使用してマルウェアを暗号化しておきます。... 対象が標的の場合、マルウェアを復号して攻撃を行います。
ターゲット端末では受信した「launcher.dll」をファイル化することなく、メモリ上で処理し「lsass.exe」にインジェクション(注入)します。
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
At the same time, it also executes massive scanning on Internet IP addresses to find and infect other vulnerable computers.
In wiper attacks, the malware destroys data and renders it irretrievable.
CISA defines ransomware as “an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption.” | Once launched, the malware may connect to a command-and-control server to enable the criminals to move laterally across networks and encrypt and/or exfiltrate the organization’s data.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware worm referenced as an example of rapid exploitation following patch availability.
Ransomware outbreak mentioned as historical context for Lazarus Group notoriety.
A highly destructive ransomware worm that spread via worm-like propagation, encrypted files but lacked working decryption, effectively acting as a wiper. It used the leaked EternalBlue exploit to scan for exposed SMB services and leveraged DoublePulsar as a backdoor to help deliver the ransomware.
A ransomware family listed among the most common ransomware trojan families detected in Q2 2026.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.