WannaCry
WannaCry is ransomware with worm-like self-propagation capabilities that caused a major global outbreak on May 12, 2017. It exploited the Windows SMB vulnerability MS17-010 using EternalBlue, enabling rapid spread across vulnerable Windows systems and networks. The outbreak infected more than 230,000 computers across 150 countries in a very short period and severely disrupted large organizations worldwide, including the UK National Health Service, where tens of thousands of devices were affected.
The malware is widely associated with North Korea and specifically linked in the provided content to the Lazarus Group. Symantec reported strong evidence tying Lazarus to WannaCry based on commonalities in tools, techniques, and infrastructure, and noted that earlier WannaCry variants were used in targeted enterprise attacks in February, March, and April 2017 before the broader worm outbreak. The content also describes the operation as financially motivated and attributes it to North Korea.
Behaviorally, WannaCry creates the Windows service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service" for execution/persistence. It uses "attrib +h" to hide some files. The content also states that WannaCry used fake Server Name Indicators in direct-to-IP connections to make traffic appear legitimate and bypass security controls. A ransomware note displayed a Bitcoin address for ransom payment. The malware contained a race condition bug that caused many infections to default to hardcoded Bitcoin addresses instead of unique victim addresses; attackers reportedly released an updated variant about 13 hours later to fix this, but most infections had already occurred.
High-confidence aliases in the content include WanaCry, WanaCrypt, WanaCrypt0r, WannaCrypt, and WCry.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Example: WannaCry Ransomware Attack (2017) The WannaCry ransomware attack exploited a vulnerability in Windows systems (EternalBlue) that was already patched by Microsoft.
BlueKeep (CVE-2019-0708) exists within the Remote Desktop Protocol (RDP) used by the Microsoft Windows OSs listed above. An attacker can exploit this vulnerability to perform remote code execution on an unprotected system.
a ransomware campaign with a bite, named WannaCry, autonomously infected vulnerable systems leveraging an exploit leaked on the internet. | This port is important because the SMB service that listens on it is what the initial exploit targets (MS17-010,CVE-2017-0143).
Groups observed using it
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The WannaCry ransomware attacks have received extensive coverage since a widespread attack on May 12 caused the systems of many large organizations around the world, including the NHS in the UK, to come to a juddering halt.
The profile shows: Attributed to: North Korea Motivations: Financial gain, Espionage Targets: Finance, Cryptocurrency, Defense Malware used: WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)
WannaCry paralysed computers running mostly older versions of Microsoft Windows by encrypting users' computer files and displaying a message demanding anywhere from $US300 to $US600 to release them; failure to pay would leave the data mangled and likely beyond repair.
The malware, known as Wanna, Wannacry, or Wcry, has infected at least 75,000 computers... The Spanish CERT has called it a “massive ransomware attack” that is encrypting all the files of entire networks and spreading laterally through organizations.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
The WannaCry attack was a massive ransomware cyberattack... This ransomware leverages an NSA exploit known as EternalBlue... Wincry was the base of the encryption, but two additional exploits, EternalBlue and DoublePulsar, were used by the malware to make it a cryptoworm.
Techniques & procedures
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
2 techniques
Initial Access
Execution
1 technique
Execution
The response to cyberattacks such as the “WannaCry” worm could have been held up in export control paperwork for days, if not weeks, as would any other vulnerability disclosure or incident response in which command and control software or technical analysis of that software, were to cross a country’s virtual or physical border.
Persistence
3 techniques
Persistence
The malware’s current working directory is saved to the “wd” registry value under the \SOFTWARE\WanaCrypt0r key... If WCry is running with elevated privileges, the key is created in the HKLM registry hive; otherwise, it is created in the HKCU hive.
Privilege Escalation
3 techniques
Privilege Escalation
Hackers exploited vulnerabilities in outdated systems to encrypt critical data.
Stealth
3 techniques
Stealth
Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.
Upon starting, the worm attempts an HTTP connection to www . iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea . com. If the connection is successful, then the worm stops running and exits. The threat actors may have added this HTTP connection test to prevent automated sandboxes from running and analyzing the malware.
Agent Tesla has created hidden folders. AppleJeus has added a leading . to plist filenames, unlisting them from the Finder app and default Terminal directory listings. APT28 has saved files with hidden file attributes. FIN13 has created hidden files and folders within a compromised Linux system /tmp directory and also used attrib.exe to hide gathered local host information.
Defense Impairment
1 technique
Defense Impairment
Discovery
4 techniques
Discovery
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
Scanning for Targets: Once executed, WannaCry scans local networks for vulnerable devices, attempting to exploit them without user interaction.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Upon starting, the worm attempts an HTTP connection to www . iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea . com. If the connection is successful, then the worm stops running and exits. The threat actors may have added this HTTP connection test to prevent automated sandboxes from running and analyzing the malware.
Lateral Movement
3 techniques
Lateral Movement
Command and Control
3 techniques
Command and Control
One method is communicating directly with IP addresses instead of domains, making it harder for security tools to collect information about a connection.
WCry installs the Tor network anonymity software on the infected system... Tor establishes a SOCKS5 proxy server on the loopback interface (127.0.0.1) that listens on TCP port 9050. WCry connects to this proxy and attempts to contact the configured C2 hidden services.
The SMB worm delivers itself to the compromised system as a DLL file payload. After the DLL is executed with a single exported function named PlayGame, it writes a copy of the original SMB worm to C:\Windows\mssecsvc.exe and then executes this file. The SMB worm then drops a secondary payload from its resources section to C:\Windows\tasksche.exe and executes this file.
Exfiltration
1 technique
Exfiltration
Impact
4 techniques
Impact
The WannaCry ransomware attacks have received extensive coverage since a widespread attack on May 12 caused the systems of many large organizations around the world... to come to a juddering halt.
WCry terminates several services so that their data stores can be encrypted: taskkill.exe /f /im mysqld.exe ... sqlwriter.exe ... sqlserver.exe ... MSExchange* ... Microsoft.Exchange.*
WCry executes the following single command... to complicate system and data recovery... vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
IOCs tracked for this family
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family noted here as being behaviorally distinct due to SMB-based spread.
Named as malware used by Lazarus Group in the example APT profile.
Described as a propagating event that impacted companies globally and contributed to major business interruption and insurance disputes.
Ransomware referenced as a historical example showing how exploit development once lagged patch release by weeks or months.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.