Skip to content

WannaCry

WannaCry is a Windows ransomware cryptoworm that caused a major global outbreak in May 2017.

Profile source: Mallory opens in a new tab

WannaCry

Family profile

WannaCry is a Windows ransomware cryptoworm that caused a major global outbreak in May 2017. It combines file-encrypting ransomware behavior with worm-like self-propagation, allowing it to spread automatically across vulnerable networks without user interaction. The malware exploited the SMBv1 remote code execution vulnerability tracked as CVE-2017-0144 using the EternalBlue exploit, enabling rapid compromise of unpatched Microsoft Windows systems, particularly legacy and unsupported environments.

Once executed, WannaCry encrypts victim files and presents a ransom demand in Bitcoin. Its propagation capability made it unusually disruptive compared with conventional ransomware, contributing to widespread operational outages across healthcare, telecommunications, manufacturing, logistics, and government organizations worldwide. High-profile impacts included severe disruption to the UK National Health Service, as well as interruptions affecting major multinational enterprises. Loss estimates reached into the billions of dollars, while ransom revenue appears to have been comparatively limited.

WannaCry also scans for additional reachable systems and can encrypt files on newly attached drives, reinforcing its ability to spread and maximize impact inside flat or poorly segmented environments. It establishes persistence on infected Windows hosts through creation of a Windows service masquerading as a legitimate security-related component. Researchers identified a kill-switch mechanism in the original outbreak variant that helped slow propagation, although later variants without the original kill switch continued to circulate on unpatched systems.

Governments including the United States and United Kingdom formally attributed WannaCry to the Lazarus Group, a North Korean state-linked threat actor. The malware remains a landmark example of wormable ransomware and of the systemic risk created by delayed patching, exposed SMB services, legacy Windows deployments, and weak network segmentation.

Capabilities

  • Extortion
  • Persistence
  • Scanning

Operational record

1
YARA rules
1
Leak sites
0 available

Reported operators

Threat actors

5 named in public reporting
Lazarus

WannaCry is a self-propagating ransomware worm that infected more than 200,000 computers across 150 countries within four days in May 2017, encrypting victims’ files and demanding Bitcoin payments for their release.

Shadow Brokers

Five years ago, the WannaCry ransomware cryptoworm targeted computers running Microsoft Windows, encrypting data at organizations around the world.

TheShadowBrokers

WannaCry paralysed computers running mostly older versions of Microsoft Windows by encrypting users' computer files and displaying a message demanding anywhere from $US300 to $US600 to release them; failure to pay would leave the data mangled and likely beyond repair.

Sandworm

The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.

APT38

The WannaCry attack was a massive ransomware cyberattack... This ransomware leverages an NSA exploit known as EternalBlue... Wincry was the base of the encryption, but two additional exploits, EternalBlue and DoublePulsar, were used by the malware to make it a cryptoworm.

Exploited software

Vulnerabilities linked to WannaCry

4 CVEs

MITRE ATT&CK

WannaCry in ATT&CK

66 distinct techniques

Techniques

66 techniques
T1210 Exploitation of Remote Services T1570 Lateral Tool Transfer T1497 Virtualization/Sandbox Evasion T1486 Data Encrypted for Impact T1021 Remote Services T1046 Network Service Discovery T1190 Exploit Public-Facing Application T1120 Peripheral Device Discovery T1041 Exfiltration Over C2 Channel T1068 Exploitation for Privilege Escalation T1203 Exploitation for Client Execution T1499 Endpoint Denial of Service T1584.001 Domains T1036 Masquerading T1543.003 Windows Service T1083 File and Directory Discovery T1564.001 Hidden Files and Directories T1016 System Network Configuration Discovery T1071 Application Layer Protocol T1490 Inhibit System Recovery T1489 Service Stop T1105 Ingress Tool Transfer T1112 Modify Registry T1547.001 Registry Run Keys / Startup Folder T1090.003 Multi-hop Proxy T1566 Phishing T1566.001 Spearphishing Attachment T1090.002 External Proxy T1059 Command and Scripting Interpreter T1498 Network Denial of Service T1021.002 SMB/Windows Admin Shares T1135 Network Share Discovery T1047 Windows Management Instrumentation T1657 Financial Theft T1568.002 Domain Generation Algorithms T1071.001 Web Protocols T1566.002 Spearphishing Link T1059.003 Windows Command Shell T1564 Hide Artifacts T1080 Taint Shared Content T1070.004 File Deletion T1059.005 Visual Basic T1222 File and Directory Permissions Modification T1204.002 Malicious File T1189 Drive-by Compromise T1003.001 LSASS Memory T1003 OS Credential Dumping T1562 Impair Defenses T1055 Process Injection T1018 Remote System Discovery T1133 External Remote Services T1078 Valid Accounts T1195 Supply Chain Compromise T1543 Create or Modify System Process T1119 Automated Collection T1027.013 Encrypted/Encoded File T1027.003 Steganography T1560 Archive Collected Data T1480.002 Mutual Exclusion T1027.007 Dynamic API Resolution T1140 Deobfuscate/Decode Files or Information T1569.002 Service Execution T1222.001 Windows File and Directory Permissions Modification T1573.002 Asymmetric Cryptography T1563.002 RDP Hijacking T1595 Active Scanning

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.