EternalBlue is a Windows SMBv1 remote-code-execution exploit originally developed by the U.S. National Security Agency and publicly released by the Shadow Brokers in April 2017. It targets CVE-2017-0144, a memory-corruption vulnerability addressed by Microsoft's MS17-010 security update on March 14, 2017. Specially crafted SMB requests trigger an integer-conversion error and a kernel buffer overflow, enabling remote compromise of vulnerable Windows clients and servers without user interaction.
EternalBlue supports initial access through exposed SMB services and lateral movement across internal networks. It is exploit tooling rather than a standalone ransomware family, worm, or backdoor. In the leaked Fuzzbunch toolkit, it can install the DoublePulsar kernel backdoor, which provides subsequent payload-execution capabilities. Malware integrating EternalBlue can use it to propagate automatically between vulnerable systems.
EternalBlue was used in the WannaCry ransomware outbreak and the NotPetya destructive-malware campaign, and was incorporated into EternalRocks and Lucifer propagation mechanisms. BackdoorDiplomacy has also used the leaked exploit. Its reuse spans espionage, ransomware, destructive attacks, and cryptocurrency-mining operations; targeting depends on the deploying actor and payload rather than an inherent industry focus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
EternalBlue is an exploit designed to attack SMB (Server Message Block) file and print sharing services on the affected windows versions.
EternalBlue is an exploit designed to attack SMB (Server Message Block) file and print sharing services on the affected windows versions.
The ransomware perpetrators incorporated publicly-available exploit code for the patched SMB EternalBlue vulnerability, CVE-2017-0145, which can be triggered by sending a specially crafted packet to a targeted SMB server.
EternalBlue exploits (MS17-010) CVE-2017-0144
EternalBlue is an exploit designed to attack SMB (Server Message Block) file and print sharing services on the affected windows versions.
EternalBlue is an exploit designed to attack SMB (Server Message Block) file and print sharing services on the affected windows versions.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.
The leak included EternalBlue, an exploit for the SMB protocol in Windows that the NSA had likely held for years.
The leak included EternalBlue, an exploit for the SMB protocol in Windows that the NSA had likely held for years.
The leak included EternalBlue, an exploit for the SMB protocol in Windows that the NSA had likely held for years.
Windows executable versions of publically available EternalBlue/EternalRomance exploit scripts.
If the DoublePulsar backdoor does not exist, then the SMB worm attempts to compromise the target using the Eternalblue SMBv1 exploit.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During our analysis, we also discovered that Amadey was actively pushing the Remcos RAT via its control panel... We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine.
EternalBlue required zero user interaction and zero authentication, allowing it to spread laterally across networks at machine speed. The article also recommends restricting internal SMB traffic to limit the blast radius of lateral movement.
MS08-067 allowed an unauthenticated attacker to send a specially crafted RPC request over SMB and obtain SYSTEM-level privileges. EternalBlue targeted SMBv1 transaction handling and spread laterally across networks without authentication or user interaction.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A leaked NSA-linked Windows exploit set described as enabling system intrusion, lateral movement, and automatic malware propagation. It later underpinned major destructive attacks.
A leaked NSA-linked exploit family targeting Windows that enabled network compromise, lateral spread, and deployment of self-propagating worms.
SMBv1 remote code execution exploit used by WannaCry for initial access and worm-like propagation by triggering a kernel memory corruption condition via crafted SMB packets.
Leaked NSA exploit later abused broadly by criminals, including in ransomware campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.