Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware WannaCry

WannaCry

TLP:CLEAR
Family

Also known as: WanaCry, WanaCrypt, WanaCrypt0r, WCry

AI Analysis

· 1 day ago

Executive Summary

WannaCry is a ransomware and worm hybrid that exploited Microsoft's EternalBlue SMB vulnerability to spread across networks in 2017. It encrypts user data with AES and demands Bitcoin payment while disabling backup services and persistence mechanisms. Rapid global impact underscores the necessity of updated patches, SMB disallowance, and robust backups.

Enhanced Description

WannaCry is a high‑profile ransomware that emerged in May 2017 and rapidly infected more than 150 countries, leveraging the widespread deployment of Microsoft Windows systems worldwide. The malware combines classic ransomware encryption routines with worm‑like capabilities: it uses the EternalBlue SMBv1 exploit (CVE‑2017-0144) to move laterally across networks without requiring user interaction or valid credentials. Once inside a host, WannaCry disables security services, creates malicious registry keys, and deletes scheduled tasks to avoid detection. After compromising a system, the malware encrypts user files with an 256‑bit AES key, which is then encrypted with an embedded RSA public key before being stored in the victim’s machine. A ransom note appears in each affected directory demanding payment in Bitcoin and threatening permanent data loss if the deadline passes. The persistence mechanism relies on Windows scheduling tasks that re‑spawn the executable even after a reboot. The widespread impact of the 2017 WannaCry incident highlighted critical gaps in Windows patch management, SMB configurations, and backup strategies. Although the Microsoft Security Advisory MS17-010 closed the EternalBlue vulnerability, the rapid spread demonstrated how quickly dormant exploits can be weaponised. Subsequent variants have appeared with minor changes—most notably a newer “WannaCry 2.0” that adds key‑logging functionality—but the core worm/cyber‑attack architecture remains consistent. Organisations exposed to older Windows installations or legacy SMB traffic remain at risk, especially if they lack timely patching or proper network segmentation.

Key Capabilities

  • Exploits EternalBlue (SMBv1) for network lateral movement and self‑propagation
  • Implements a ransomware payload that encrypts files with AES while protecting key with RSA
  • Creates malicious registry entries and disables Windows security services to evade detection
  • Schedules persistence tasks to survive reboots
  • Drops a ransom note demanding Bitcoin payment with time‑based threat of permanent data loss

ATT&CK Techniques

T1016.001 Network Service Scanning
T1071 Application Layer Protocol: SMB
T1203 Exploit for Privilege Escalation
T1059 Command-Line Interface

Recommended Actions

  • Apply or backport Microsoft MS17-010 patch or disable SMBv1 altogether
  • Implement network segmentation and firewall rules to block outbound traffic on TCP 445
  • Maintain up‑to‑date offline backups of critical data and verify restore processes
  • Use reputable endpoint protection that detects ransomware indicators such as .wncry files, encrypted random filenames, and bitcoin address patterns
  • Deploy intrusion detection systems to spot anomalous SMB activity
  • Conduct regular security audits for unpatched vulnerabilities

Suggested Tags

ransomware
network-propagation
EternalBlue
SMBv1
cryptoworm
2017-outbreak
Bitcoin
WannaCry
WanaCrypt

Confidence Assessment

Confidence in the core technical and behavioral details of WannaCry is high due to extensive public reporting (e.g., FireEye, US‑CERT) and academic analysis. However, information about newer variants’ precise capabilities (keylogging, advanced tunneling) is limited, creating a gap for nuanced detection rules on those updates.

Description

WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries. It contains worm-like features to spread itself across a computer network using the SMBv1 exploit EternalBlue.(Citation: LogRhythm WannaCry)(Citation: US-CERT WannaCry 2017)(Citation: Washington Post WannaCry 2017)(Citation: FireEye WannaCry 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.