EternalRomance is an SMB exploit associated with the leaked NSA offensive toolkit and the MS17-010 vulnerability family. It targets Microsoft Windows systems through flaws in SMB transaction handling, specifically CVE-2017-0143, and is designed to obtain administrative or SYSTEM-level access on vulnerable hosts without user interaction. Public implementations and later ports expanded support across a broad range of Windows versions and architectures, including legacy and modern 32-bit and 64-bit releases, typically by abusing named pipes over IPC$ and manipulating SMB session structures to elevate privileges.
Operationally, EternalRomance has been used as a lateral-movement and post-exploitation capability rather than a standalone payload. Implementations commonly perform target OS detection, named-pipe discovery, memory corruption and transaction grooming, then alter SMB session security context or related token data to convert an existing session into an administrative one. This enables follow-on actions such as remote service creation and command execution. The exploit has been incorporated into offensive frameworks and has also appeared in malware campaigns as a propagation component alongside DoublePulsar and EternalBlue.
EternalRomance is historically significant because it was used in major destructive outbreaks, including NotPetya and Bad Rabbit, and has been referenced in broader discussions of Shadow Brokers–leaked SMB tooling that reshaped the threat landscape after 2017. Reporting has also linked related SMB exploit usage and repurposing to Buckeye, also known as APT3 or Gothic Panda, in espionage activity predating the public leak. Systems patched by Microsoft’s MS17-010 updates are not vulnerable to this exploit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploit use the bug same as eternalromance and eternalsynergy, so named pipe is needed
Besides EternalBlue, the NotPetya and Bad Rabbit ransomware outbreaks also utilized the EternalRomance exploit that Dillon has recently ported to target a more broader spectrum of Windows versions.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
MS17-010 exploit for Windows 2000 and later... If we can overwrite Token to NULL and UsePsImpersonateClient to true, a running thread will use primary token (SYSTEM) to do all SMB operations.
The threat actor responsible for the attack has purposefully included evidence to frustrate analysts and lead researchers to false attribution flags.
Our analysis of the artifacts and network traffic at victim networks indicate that modified versions of the EternalBlue and EternalRomance SMB exploits were used, at least in part, to spread laterally.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit dropped by the spreader component as part of the toolkit used for network propagation.
NSA SMB exploit tool referenced as part of the leaked NSA toolkit; used for compromising Windows systems via SMB.
An NSA-developed exploit leaked by Shadow Brokers and subsequently leveraged in major destructive campaigns alongside other leaked exploit tooling.
Leaked NSA SMB exploit ported to support a broader range of Windows versions; used to gain elevated access and explicitly linked to ransomware outbreaks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.