WannaCry, also known as WannaCrypt, WanaCrypt0r, and WCry, is Windows ransomware with self-propagating worm functionality. It encrypts user files and demands Bitcoin payments for decryption, threatening increased ransom demands and permanent loss of access if payment deadlines expire. Its global outbreak began on May 12, 2017, affecting more than 200,000 computers across approximately 150 countries and disrupting hospitals, manufacturing operations, and other organizations. The attack has been attributed to North Korean actors.
WannaCry scans local networks and the Internet for vulnerable SMBv1 services. It uses EternalBlue, an NSA-developed exploit targeting CVE-2017-0144, to compromise remote Windows systems and copy and execute its payload without user interaction. Its propagation component can also use existing DoublePulsar backdoors. Microsoft addressed the exploited vulnerability through MS17-010 in March 2017, before the outbreak. WannaCry uses Tor for command-and-control communications. A prominent outbreak variant included a domain-based kill switch; security researcher MalwareTech's registration and sinkholing of that domain curtailed its propagation. Its rapid spread primarily affected systems lacking the available security update.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
NotPetya uses the EternalBlue exploit to target unpatched systems running vulnerable SMBv1, scans for other vulnerable systems, and installs its malicious payload. The alert explicitly identifies CVE-2017-0144 among the vulnerabilities putting Windows systems at risk.
The ransomware perpetrators incorporated publicly-available exploit code for the patched SMB EternalBlue vulnerability, CVE-2017-0145, which can be triggered by sending a specially crafted packet to a targeted SMB server.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | On Friday May 12th, the WannaCry ransomware was distributed using a worm leveraging the EternalBlue SMB exploit. After successful exploitation, it installs the DoublePulsar backdoor and then proceeds to load the ransomware component.
CVE : CVE-2017-0146 Description : Exploits vulnerabilities in Microsoft SMB implementation. The vulnerability is described in CVE-2017-0146 and CVE-2017-0147. Both vulnerabilities were patched in MS17-010 update from March this year. | On Friday May 12th, the WannaCry ransomware was distributed using a worm leveraging the EternalBlue SMB exploit. After successful exploitation, it installs the DoublePulsar backdoor and then proceeds to load the ransomware component.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus was also linked to the WannaCry ransomware outbreak in May 2017.
On 12 May 2017, WannaCry ransomware began spreading like wildfire through computer networks across the world, encrypting over 200,000 devices across150 countries in 24 hours.
Five years ago, the WannaCry ransomware cryptoworm targeted computers running Microsoft Windows, encrypting data at organizations around the world.
WannaCry paralysed computers running mostly older versions of Microsoft Windows by encrypting users' computer files and displaying a message demanding anywhere from $US300 to $US600 to release them; failure to pay would leave the data mangled and likely beyond repair.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
EternalBlue required zero user interaction and zero authentication, allowing it to spread laterally across networks at machine speed. The article also recommends restricting internal SMB traffic to limit the blast radius of lateral movement.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware mentioned as a historical example of worldwide attacks enabled by the leaked EternalBlue exploit against a Microsoft Windows vulnerability. The article notes that many organizations had not installed the available security patch.
A ransomware threat for which recovery tools may work under limited conditions, particularly on unpatched Windows systems that have not been rebooted after infection.
Mentioned only as an example of a memorable cyber-threat name; the content provides no behavioral or campaign details.
Ransomware campaign whose authors weaponized the EternalBlue SMBv1 exploit for unauthenticated, machine-speed propagation and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.