Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 87 IP / 183 hostnames
WannaCry, also known as WannaCryptor, WCry, WanaCrypt0r 2.0, and Wana Decryptor, is a Windows ransomware family that caused a global outbreak in May 2017.
Profile source: Mallory opens in a new tabWannaCryptor
WannaCry, also known as WannaCryptor, WCry, WanaCrypt0r 2.0, and Wana Decryptor, is a Windows ransomware family that caused a global outbreak in May 2017. It encrypts victim files and presents a ransom demand, while also incorporating worm-like propagation that enabled rapid self-spreading across networks. The outbreak disrupted organizations worldwide, including critical healthcare environments in the United Kingdom.
The malware is widely associated with the North Korea-aligned Lazarus Group. Public attribution has linked WannaCry to Lazarus through code overlaps and shared development artifacts with earlier Lazarus malware. Reporting also identifies pre-outbreak variants and beta builds from early 2017, indicating development and testing before the large-scale campaign.
A defining characteristic of WannaCry was its use of the EternalBlue SMB exploit to spread between vulnerable Windows systems, allowing mass propagation where systems had not been patched. Separate reporting also notes an earlier near-identical variant that spread via SMB brute-forcing shortly before the main outbreak. This combination of ransomware functionality with automated network propagation made WannaCry unusually disruptive compared with conventional manually deployed ransomware.
WannaCry targeted Windows systems and is best classified as ransomware with worm-like behavior. Its known capabilities include encrypting data for extortion, propagating laterally through vulnerable hosts, and establishing broad post-compromise impact through automated spread. The malware remains one of the most consequential ransomware incidents due to its scale, speed of propagation, and operational linkage to Lazarus.
C2 tracking
Derp observations, rolling seven-day window
Samples
49d7c6c1ad16595c2695a17bd7552b8754dcb9a744a2bb436800c751720952b7 5ed7fd177ce9768ec67e1b6feb23fddb258e7ae25dd730239a807d020deb35c2 8d9aed2ea77f3bd9912cc598f0d2956e46d6147b8b4f50cf54b021f9f9bc0aaf a6234024b31a0011fc13f2bcda5a06c3e2aac4cf18ac7a27b22baed5a2734c66 ea8287cfb278d9590ea31d44d8451c413d09e7a27072063a6bc65d98ca1f87f2 13b81b02451705e43f95f3e4937f5b2ec36cecf46dcf9495620c49dce213d4e4 897f1cbe4f6f19ab081ba382a8d8b2663902d36aded97aecabe8985dc150ae86 c3e0801ad8291a394be399f9b40af2c56b50a54475a46ec2c74d6ae10a50cb55 dbee15d75e4bfc40a0091878009dedf0cca795f224554c91ad776710eb3a76a9 1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 Reported operators
Tracking Ransomware End-to-end Cerber Locky WannaCryptor
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.