The WannaCry ransomware worm disrupted healthcare and businesses worldwide by exploiting the Windows SMBv1 flaw tracked as CVE-2017-0145 and patched in MS17-010. In the U.K., the outbreak hit at least 16 National Health Service hospitals initially and later was reported to have affected 81 NHS trusts in England and nearly 600 GP surgeries, forcing ambulance diversions and widespread service disruption. The malware also struck organizations including Telefonica and spread rapidly across roughly 150 countries, infecting more than 300,000 computers, with major impact on older, unpatched Windows systems such as Windows 7, Windows Server 2008, and earlier versions.
Microsoft said the malware combined worm-like propagation with file encryption, checking a kill-switch domain before execution, creating the mssecsvc2.0 service to spread, appending the .WNCRY extension to encrypted files, and deleting shadow copies to complicate recovery. Reporting on the incident said the campaign used EternalBlue-style exploit code and was linked to the leaked NSA-associated SMB exploit chain, while later U.K. government statements said they were highly confident North Korea was responsible. The NHS said there was no early evidence patient data had been accessed, but subsequent reviews found basic cyber hygiene failures, especially delayed patching and weak follow-through on critical alerts, contributed to the scale of the disruption; Microsoft responded by urging organizations to install MS17-010, disable SMBv1, and block inbound SMB traffic on port 445, and it issued emergency updates for unsupported systems including Windows XP.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On 2017-06-29, researchers published an analysis showing WannaCry 2.0 used EternalBlue together with DoublePulsar for propagation and that infected systems could retain an accessible DoublePulsar backdoor for later remote code execution by third parties. They also warned that applying MS17-010 patches alone was insufficient until systems were rebooted, because the in-memory backdoor could persist after patching.
On June 7, researchers reported a modified WannaCry sample captured by a honeypot that continued SMB worm propagation even though the original kill-switch URL was contacted, because the relevant conditional jump had been patched out. They also found the ransomware component was corrupted and nonfunctional, suggesting a third party had altered the compiled malware rather than rebuilding it from source.
Reporting on May 12 said an unknown number of computers in Russia's Interior Ministry were infected by the WannaCry/WCry ransomware outbreak after it spread into the ministry's internal network. The same reporting cited widespread global infections and identified the malware as the ransomware encrypting files and demanding payment.
Microsoft reported detecting the new WannaCrypt ransomware campaign on May 12 and described it as a worm-enabled attack exploiting CVE-2017-0145 against unpatched Windows systems.
On May 12, WannaCry disrupted NHS IT systems, forcing hospitals in England to divert emergency patients and affecting organizations across multiple sectors. The NHS said there was no evidence at that stage that patient data had been accessed.
A May 2017 technical analysis detailed WannaCry 2.0's modular design, showing that SMB-based propagation, second-stage execution, and ransomware functions were split across multiple binaries including tasksche.exe, taskse.exe, and @WannaDecryptor@.exe. The report also published infection indicators such as registry artifacts, a mutex, NTFS permission changes, and the ZIP password "WNcry@2ol7".
Microsoft fixed the SMBv1 vulnerability CVE-2017-0145 in security bulletin MS17-010, the flaw later exploited by WannaCry using EternalBlue-style code.
According to the National Audit Office, NHS Digital issued critical alerts about WannaCry before the outbreak, warning in March and April ahead of the attack.
The British government said for the first time it was highly confident North Korea was responsible for the WannaCry attack, with security minister Ben Wallace naming North Korea publicly.
A National Audit Office report concluded the NHS had been left vulnerable because basic cybersecurity practices were not followed and said the attack could have been prevented with basic IT security measures.
In response to the scale of the outbreak, Microsoft released security updates for unsupported platforms including Windows XP, Windows 8, and Windows Server 2003.
Spain's national computer emergency response team, CCN-CERT, published an alert about the rapidly spreading WannaCry outbreak affecting organizations including Telefonica.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
gist.github.com
Open sourceindependent.co.uk
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcembsd.jp
Open sourcethemoscowtimes.com
Open sourcemicrosoft.com
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.