WannaCry

lore

securityops culture

The 2017 ransomware worm that spread through a leaked Windows exploit and crippled systems worldwide.

It used the EternalBlue SMB exploit to self-propagate, encrypting files and demanding Bitcoin, and hit hospitals, factories, and rail networks within hours. A researcher's accidental discovery of a kill-switch domain slowed it, but not before it caused billions in damage.

WannaCry spread in May 2017 using EternalBlue, an exploit for a Windows file-sharing flaw that had been developed by the NSA, leaked by a group calling itself the Shadow Brokers, and patched by Microsoft roughly two months before the outbreak. It encrypted files and demanded payment in bitcoin.

Its impact was disproportionate because it was a worm, not an email campaign: once inside a network it spread machine to machine without anyone clicking anything. Britain's National Health Service was among the most visible casualties, with appointments and procedures cancelled, and the reason was a familiar one, which is that systems too critical to take offline for patching are also too critical to lose.

Two details are worth remembering. A researcher stopped the outbreak almost by accident by registering a domain the malware checked, which functioned as a kill switch, and the ransom mechanism was so poorly built that paying frequently did not recover data. But the underlying lesson is about the patch gap: the fix existed, the exploit was public, and the interval between those two facts is where the entire event took place.

Also known as: WannaCry, WannaCrypt, WCry

Sources

  • Widely documented (May 2017); NCSC/US-CERT advisories

All glossary entries