WannaCry is a self-propagating ransomware worm that infected more than 200,000 computers across 150 countries within four days in May 2017, encrypting victims’ files and demanding Bitcoin payments for their release.
WannaCry
WannaCry is a Windows ransomware cryptoworm that caused a major global outbreak in May 2017.
Profile source: Mallory opens in a new tabWannaCry
Family profile
WannaCry is a Windows ransomware cryptoworm that caused a major global outbreak in May 2017. It combines file-encrypting ransomware behavior with worm-like self-propagation, allowing it to spread automatically across vulnerable networks without user interaction. The malware exploited the SMBv1 remote code execution vulnerability tracked as CVE-2017-0144 using the EternalBlue exploit, enabling rapid compromise of unpatched Microsoft Windows systems, particularly legacy and unsupported environments.
Once executed, WannaCry encrypts victim files and presents a ransom demand in Bitcoin. Its propagation capability made it unusually disruptive compared with conventional ransomware, contributing to widespread operational outages across healthcare, telecommunications, manufacturing, logistics, and government organizations worldwide. High-profile impacts included severe disruption to the UK National Health Service, as well as interruptions affecting major multinational enterprises. Loss estimates reached into the billions of dollars, while ransom revenue appears to have been comparatively limited.
WannaCry also scans for additional reachable systems and can encrypt files on newly attached drives, reinforcing its ability to spread and maximize impact inside flat or poorly segmented environments. It establishes persistence on infected Windows hosts through creation of a Windows service masquerading as a legitimate security-related component. Researchers identified a kill-switch mechanism in the original outbreak variant that helped slow propagation, although later variants without the original kill switch continued to circulate on unpatched systems.
Governments including the United States and United Kingdom formally attributed WannaCry to the Lazarus Group, a North Korean state-linked threat actor. The malware remains a landmark example of wormable ransomware and of the systemic risk created by delayed patching, exposed SMB services, legacy Windows deployments, and weak network segmentation.
Capabilities
- Extortion
- Persistence
- Scanning
Operational record
Reported operators
Threat actors
5 named in public reportingFive years ago, the WannaCry ransomware cryptoworm targeted computers running Microsoft Windows, encrypting data at organizations around the world.
WannaCry paralysed computers running mostly older versions of Microsoft Windows by encrypting users' computer files and displaying a message demanding anywhere from $US300 to $US600 to release them; failure to pay would leave the data mangled and likely beyond repair.
The exploit chains in play included EternalBlue, DoublePulsar, and WannaCry, all tools that have been publicly known and patchable for years.
The WannaCry attack was a massive ransomware cyberattack... This ransomware leverages an NSA exploit known as EternalBlue... Wincry was the base of the encryption, but two additional exploits, EternalBlue and DoublePulsar, were used by the malware to make it a cryptoworm.
Exploited software
Vulnerabilities linked to WannaCry
4 CVEsMITRE ATT&CK