EternalRomance is a remote code execution exploit targeting vulnerabilities in Microsoft Windows SMBv1, rather than a standalone malware family. Associated with the NSA and Equation Group toolset, it was publicly released by the Shadow Brokers in April 2017. Microsoft addressed the affected SMB vulnerabilities in security update MS17-010, released in March 2017.
The exploit abuses SMB transaction handling and memory corruption to obtain arbitrary read and write access to kernel memory. Implementations can manipulate SMB session security structures to obtain administrative or SYSTEM-level access, enabling remote service execution or installation of a separate payload such as DoublePulsar. Reliable exploitation depends on knowledge or control of the target's memory layout. Later public implementations broadened support across 32-bit and 64-bit Windows desktop and server versions and were incorporated into the Metasploit Framework.
EternalRomance has been used for lateral movement and network propagation by NotPetya and Bad Rabbit, with different implementations exploiting the same underlying weakness. NotPetya's campaign was publicly attributed by the U.S. Government to the Russian military. EternalRomance has also been incorporated into propagation toolsets used by EternalRocks and Lucifer. Its role is to compromise vulnerable Windows hosts; encryption, cryptocurrency mining, and other subsequent actions are performed by the malware using it.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
EternalRomance is a remote code execution attack that exploits CVE-2017-0145.
EternalRomance - another Windows SMBv1 exploit
Besides EternalBlue, the NotPetya and Bad Rabbit ransomware outbreaks also utilized the EternalRomance exploit that Dillon has recently ported to target a more broader spectrum of Windows versions.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Windows executable versions of publically available EternalBlue/EternalRomance exploit scripts.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
MS17-010 exploit for Windows 2000 and later... If we can overwrite Token to NULL and UsePsImpersonateClient to true, a running thread will use primary token (SYSTEM) to do all SMB operations.
The threat actor responsible for the attack has purposefully included evidence to frustrate analysts and lead researchers to false attribution flags.
It uses two tools (ETERNALBLUE and ETERNALROMANCE) from the ShadowBrokers dump in April that exploit vulnerabilities in SMBv1... The ransomware can also perform lateral movement by using two exploits... called ETERNALBLUE and ETERNALROMANCE.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named offensive exploit tool mentioned in historical reporting as part of Lucifer's intranet infection capabilities. Its use was not reported as observed in this campaign.
An exploit dropped by the spreader component as part of the toolkit used for network propagation.
NSA SMB exploit tool referenced as part of the leaked NSA toolkit; used for compromising Windows systems via SMB.
An NSA-developed exploit leaked by Shadow Brokers and subsequently leveraged in major destructive campaigns alongside other leaked exploit tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.