Also known as: WanaCry, WanaCrypt, WanaCrypt0r, WCry
Executive Summary
WannaCry is a ransomware and worm hybrid that exploited Microsoft's EternalBlue SMB vulnerability to spread across networks in 2017. It encrypts user data with AES and demands Bitcoin payment while disabling backup services and persistence mechanisms. Rapid global impact underscores the necessity of updated patches, SMB disallowance, and robust backups.
Enhanced Description
WannaCry is a high‑profile ransomware that emerged in May 2017 and rapidly infected more than 150 countries, leveraging the widespread deployment of Microsoft Windows systems worldwide. The malware combines classic ransomware encryption routines with worm‑like capabilities: it uses the EternalBlue SMBv1 exploit (CVE‑2017-0144) to move laterally across networks without requiring user interaction or valid credentials. Once inside a host, WannaCry disables security services, creates malicious registry keys, and deletes scheduled tasks to avoid detection. After compromising a system, the malware encrypts user files with an 256‑bit AES key, which is then encrypted with an embedded RSA public key before being stored in the victim’s machine. A ransom note appears in each affected directory demanding payment in Bitcoin and threatening permanent data loss if the deadline passes. The persistence mechanism relies on Windows scheduling tasks that re‑spawn the executable even after a reboot. The widespread impact of the 2017 WannaCry incident highlighted critical gaps in Windows patch management, SMB configurations, and backup strategies. Although the Microsoft Security Advisory MS17-010 closed the EternalBlue vulnerability, the rapid spread demonstrated how quickly dormant exploits can be weaponised. Subsequent variants have appeared with minor changes—most notably a newer “WannaCry 2.0” that adds key‑logging functionality—but the core worm/cyber‑attack architecture remains consistent. Organisations exposed to older Windows installations or legacy SMB traffic remain at risk, especially if they lack timely patching or proper network segmentation.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core technical and behavioral details of WannaCry is high due to extensive public reporting (e.g., FireEye, US‑CERT) and academic analysis. However, information about newer variants’ precise capabilities (keylogging, advanced tunneling) is limited, creating a gap for nuanced detection rules on those updates.
WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries. It contains worm-like features to spread itself across a computer network using the SMBv1 exploit EternalBlue.(Citation: LogRhythm WannaCry)(Citation: US-CERT WannaCry 2017)(Citation: Washington Post WannaCry 2017)(Citation: FireEye WannaCry 2017)