EternalBlue is a leaked offensive exploit for the Windows SMBv1 protocol that targets the MS17-010 vulnerability set, most notably CVE-2017-0144, to achieve remote code execution on unpatched Windows systems. It became one of the most consequential publicly exposed cyber capabilities after its 2017 release by the Shadow Brokers from tooling widely attributed to the NSA-linked Equation Group. EternalBlue is not a conventional self-contained malware family; it is an exploitation capability and attack tool used to compromise vulnerable hosts and enable follow-on payload delivery, privilege escalation to SYSTEM, lateral movement, and worm-like propagation across networks.
Technically, EternalBlue abuses flaws in SMBv1 request handling in the Windows kernel, including memory corruption conditions in srv.sys, to trigger a nonpaged pool overflow and gain kernel-level code execution. Public analyses describe heap grooming, transaction manipulation, and overwrite of adjacent kernel structures to redirect execution and install or invoke follow-on implants such as DoublePulsar. Operationally, EternalBlue has often been paired with DoublePulsar, which can provide a memory-resident backdoor used to inject DLLs or shellcode into target processes after exploitation.
The capability was rapidly repurposed by both state and criminal actors. It was used in the WannaCry outbreak to automate ransomware propagation and in NotPetya to accelerate destructive spread inside enterprise networks. Reporting also links its use to additional ransomware and intrusion activity, and to threat actors that acquired leaked offensive tooling, including BackdoorDiplomacy. EternalBlue has also been incorporated into public security research and penetration-testing frameworks, which expanded defender understanding but also lowered the barrier to operational misuse.
EternalBlue primarily targets legacy and unpatched Microsoft Windows environments, especially systems exposing SMB services and still supporting SMBv1. Affected platforms documented in public exploit implementations and analyses span older desktop and server releases from Windows 2000 through multiple later Windows versions when unpatched. Its practical impact has been greatest in enterprises with poor patching, flat internal networks, and exposed SMB services, where it can be used to move laterally and support self-propagating malware outbreaks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
EternalBlue:MS17-010の脆弱性を攻撃するために使用するエクスプロイトコードおよび攻撃ツールの総称
CVE-2017-0143 Vulnerable Products: Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 Associated Malware: Multiple using the EternalSynergy and EternalBlue Exploit Kit Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0143 Vulnerable Products: Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 Associated Malware: Multiple using the EternalSynergy and EternalBlue Exploit Kit
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.
If the DoublePulsar backdoor does not exist, then the SMB worm attempts to compromise the target using the Eternalblue SMBv1 exploit.
"...the Shadow Brokers hacked and disclosed a cache of stockpiled NSA cyber capabilities, including the EternalBlue vulnerability, which was later used in the devastating WannaCry and NotPetya ransomware attacks."
"The NSA-developed Windows exploit EternalBlue was stolen and exposed in 2017, eventually enabling destructive operations like North Korea’s WannaCry attack and Russia-linked NotPetya hacks."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During our analysis, we also discovered that Amadey was actively pushing the Remcos RAT via its control panel... We have also seen instances of Amaday C&C servers recently that are actively pushing DoublePulsar backdoor and EternalBlue exploit payloads on the victim machine.
まず、EternalBlueによるSMBサービスの脆弱性攻撃ですが、カーネルスペースの非ページプール領域でバッファオーバーフローを発生させ、DoublePulsarのシェルコードを動作させます。
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A leaked NSA-linked Windows exploit set described as enabling system intrusion, lateral movement, and automatic malware propagation. It later underpinned major destructive attacks.
A leaked NSA-linked exploit family targeting Windows that enabled network compromise, lateral spread, and deployment of self-propagating worms.
SMBv1 remote code execution exploit used by WannaCry for initial access and worm-like propagation by triggering a kernel memory corruption condition via crafted SMB packets.
Leaked NSA exploit later abused broadly by criminals, including in ransomware campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.