Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 6 actorsExploits 3 CVEs

WannaCry

Also known asWanaCryWanaCryptWanaCrypt0rwannacryptWCry

WannaCry is ransomware with worm-like self-propagation capabilities that caused a major global outbreak on May 12, 2017. It exploited the Windows SMB vulnerability MS17-010 using EternalBlue, enabling rapid spread across vulnerable Windows systems and networks. The outbreak infected more than 230,000 computers across 150 countries in a very short period and severely disrupted large organizations worldwide, including the UK National Health Service, where tens of thousands of devices were affected.

The malware is widely associated with North Korea and specifically linked in the provided content to the Lazarus Group. Symantec reported strong evidence tying Lazarus to WannaCry based on commonalities in tools, techniques, and infrastructure, and noted that earlier WannaCry variants were used in targeted enterprise attacks in February, March, and April 2017 before the broader worm outbreak. The content also describes the operation as financially motivated and attributes it to North Korea.

Behaviorally, WannaCry creates the Windows service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service" for execution/persistence. It uses "attrib +h" to hide some files. The content also states that WannaCry used fake Server Name Indicators in direct-to-IP connections to make traffic appear legitimate and bypass security controls. A ransomware note displayed a Bitcoin address for ransom payment. The malware contained a race condition bug that caused many infections to default to hardcoded Bitcoin addresses instead of unique victim addresses; attackers reportedly released an updated variant about 13 hours later to fix this, but most infections had already occurred.

High-confidence aliases in the content include WanaCry, WanaCrypt, WanaCrypt0r, WannaCrypt, and WCry.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2017-0144EternalBlue SMBv1 Remote Code ExecutionExploited in the wild

Example: WannaCry Ransomware Attack (2017) The WannaCry ransomware attack exploited a vulnerability in Windows systems (EternalBlue) that was already patched by Microsoft.

via medium abdul myidmedium.com
CVE-2019-0708BlueKeep

BlueKeep (CVE-2019-0708) exists within the Remote Desktop Protocol (RDP) used by the Microsoft Windows OSs listed above. An attacker can exploit this vulnerability to perform remote code execution on an unprotected system.

via cisa advisoriescisa.gov
CVE-2017-0143Windows SMBv1 Remote Code Execution VulnerabilityExploited in the wild

a ransomware campaign with a bite, named WannaCry, autonomously infected vulnerable systems leveraging an exploit leaked on the internet. | This port is important because the SMB service that listens on it is what the initial exploit targets (MS17-010,CVE-2017-0143).

via web archiveweb.archive.org
THREAT ACTORS

Groups observed using it

6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Lazarus

The WannaCry ransomware attacks have received extensive coverage since a widespread attack on May 12 caused the systems of many large organizations around the world, including the NHS in the UK, to come to a juddering halt.

via medium threat intelmedium.com
Lazarus

The profile shows: Attributed to: North Korea Motivations: Financial gain, Espionage Targets: Finance, Cryptocurrency, Defense Malware used: WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)

via infosec writeupsinfosecwriteups.com
TheShadowBrokers

WannaCry paralysed computers running mostly older versions of Microsoft Windows by encrypting users' computer files and displaying a message demanding anywhere from $US300 to $US600 to release them; failure to pay would leave the data mangled and likely beyond repair.

via abc australiaabc.net.au
Shadow Brokers

The malware, known as Wanna, Wannacry, or Wcry, has infected at least 75,000 computers... The Spanish CERT has called it a “massive ransomware attack” that is encrypting all the files of entire networks and spreading laterally through organizations.

via arstechnicaarstechnica.com
Sandworm

The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.

via cyber security newscybersecuritynews.com
APT38

The WannaCry attack was a massive ransomware cyberattack... This ransomware leverages an NSA exploit known as EternalBlue... Wincry was the base of the encryption, but two additional exploits, EternalBlue and DoublePulsar, were used by the malware to make it a cryptoworm.

via wikipedia cyber incidentsen.wikipedia.org
MITRE ATT&CK

Techniques & procedures

25 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1584.001DomainsEvidence1

If you go back about a decade , there were some fairly high-profile incidents -- cases like NotPetya and WannaCry -- where various companies from different parts of the world were impacted by these propagating events.

Initial Access

2 techniques
T1190Exploit Public-Facing ApplicationEvidence3

MOVEit customers found themselves the victim of an actively exploited zero-day vulnerability, since tracked as CVE-2023-34362.

T1566PhishingEvidence1

One NHS worker, who asked to remain anonymous, said the attack began at about 12.30pm and appeared to have been the result of phishing. “The computers were affected after someone opened an email attachment.

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence2

The response to cyberattacks such as the “WannaCry” worm could have been held up in export control paperwork for days, if not weeks, as would any other vulnerability disclosure or incident response in which command and control software or technical analysis of that software, were to cross a country’s virtual or physical border.

Persistence

3 techniques
T1112Modify RegistryEvidence1

The malware’s current working directory is saved to the “wd” registry value under the \SOFTWARE\WanaCrypt0r key... If WCry is running with elevated privileges, the key is created in the HKLM registry hive; otherwise, it is created in the HKCU hive.

T1543.003Windows ServiceEvidence2

During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.

T1547.001Registry Run Keys / Startup FolderEvidence1

WCry creates a registry Run key value (see Figure 5) to ensure the ransomware GUI is displayed when victims log in or restart the computer.

Privilege Escalation

3 techniques
T1068Exploitation for Privilege EscalationEvidence1

Hackers exploited vulnerabilities in outdated systems to encrypt critical data.

T1543.003Windows ServiceEvidence2

During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.

T1547.001Registry Run Keys / Startup FolderEvidence1

WCry creates a registry Run key value (see Figure 5) to ensure the ransomware GUI is displayed when victims log in or restart the computer.

Stealth

3 techniques
T1036MasqueradingEvidence1

Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.

T1497Virtualization/Sandbox EvasionEvidence1

Upon starting, the worm attempts an HTTP connection to www . iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea . com. If the connection is successful, then the worm stops running and exits. The threat actors may have added this HTTP connection test to prevent automated sandboxes from running and analyzing the malware.

T1564.001Hidden Files and DirectoriesEvidence2

Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.

Defense Impairment

1 technique
T1112Modify RegistryEvidence1

The malware’s current working directory is saved to the “wd” registry value under the \SOFTWARE\WanaCrypt0r key... If WCry is running with elevated privileges, the key is created in the HKLM registry hive; otherwise, it is created in the HKCU hive.

Discovery

4 techniques
T1016System Network Configuration DiscoveryEvidence1

The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.

T1046Network Service DiscoveryEvidence3

Scanning for Targets: Once executed, WannaCry scans local networks for vulnerable devices, attempting to exploit them without user interaction.

T1083File and Directory DiscoveryEvidence1

The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").

T1497Virtualization/Sandbox EvasionEvidence1

Upon starting, the worm attempts an HTTP connection to www . iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea . com. If the connection is successful, then the worm stops running and exits. The threat actors may have added this HTTP connection test to prevent automated sandboxes from running and analyzing the malware.

Lateral Movement

3 techniques
T1021Remote ServicesEvidence1

Connections made on port 445 (SMB).

T1210Exploitation of Remote ServicesEvidence8

WannaCry, for example, took advantage of the EternalBlue vulnerability in outdated versions of Windows' Server Message Block protocol.

T1570Lateral Tool TransferEvidence3

WannaCry stays well separated on the strength of its SMB-based spread.

Command and Control

3 techniques
T1071Application Layer ProtocolEvidence3

One method is communicating directly with IP addresses instead of domains, making it harder for security tools to collect information about a connection.

T1090.003Multi-hop ProxyEvidence1

WCry installs the Tor network anonymity software on the infected system... Tor establishes a SOCKS5 proxy server on the loopback interface (127.0.0.1) that listens on TCP port 9050. WCry connects to this proxy and attempts to contact the configured C2 hidden services.

T1105Ingress Tool TransferEvidence1

The SMB worm delivers itself to the compromised system as a DLL file payload. After the DLL is executed with a single exported function named PlayGame, it writes a copy of the original SMB worm to C:\Windows\mssecsvc.exe and then executes this file. The SMB worm then drops a secondary payload from its resources section to C:\Windows\tasksche.exe and executes this file.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Unrecognized IP addresses, outbound data transfers, and sudden bandwidth spikes can be early signs of cyber infiltration.

Impact

4 techniques
T1486Data Encrypted for ImpactEvidence8

The WannaCry ransomware attacks have received extensive coverage since a widespread attack on May 12 caused the systems of many large organizations around the world... to come to a juddering halt.

T1489Service StopEvidence1

WCry terminates several services so that their data stores can be encrypted: taskkill.exe /f /im mysqld.exe ... sqlwriter.exe ... sqlserver.exe ... MSExchange* ... Microsoft.Exchange.*

T1490Inhibit System RecoveryEvidence1

WCry executes the following single command... to complicate system and data recovery... vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet

T1499Endpoint Denial of ServiceEvidence1

you had a situation where these companies were on the hook for hundreds of millions of dollars, where they couldn't function for a certain amount of time.

INDICATORS OF COMPROMISE

IOCs tracked for this family

30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
24 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
3 tracked

Other indicator types observed in public reporting.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching30

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution6

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping25

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.