Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors wannacry

Description

WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat. Cybercriminals used the ransomware to hold an organization's data hostage and extort money in the form of cryptocurrency. WannaCry spreads using EternalBlue, an exploit leaked from the National Security Agency (NSA). EternalBlue enables attackers to use a zero-day vulnerability to gain access to a system. It targets Windows computers that use a legacy version of the Server Message Block (SMB) protocol. Known victims: 33

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 months ago

Executive Summary

The WannaCry ransomware attack, first seen in May 2017, is a global cyber threat that spreads by exploiting vulnerabilities in the Windows operating system, with the primary motivation of organizational gain through financial extortion. The attack targets Windows computers using a legacy version of the Server Message Block (SMB) protocol. WannaCry's impact was significant, with 33 known victims.

Goals & Targeting

The WannaCry ransomware attack is primarily motivated by financial gain, with the attackers seeking to extort money from organizations in exchange for the decryption key. The attack targets Windows computers using a legacy version of the SMB protocol, which suggests that the attackers are seeking to exploit vulnerability in widely used systems. The typical victims of the WannaCry attack are organizations that have not prioritized patching and vulnerability management, and that use outdated systems and protocols.

Enhanced Description

The WannaCry attack also highlights the risks associated with the use of legacy systems and protocols. The attack's ability to spread using the SMB protocol, which is widely used in many organizations, underscores the need for organizations to prioritize the retirement of legacy systems and the adoption of more secure protocols. Furthermore, the attack demonstrates the importance of having robust incident response plans in place, including regular backups, disaster recovery procedures, and employee training on cybersecurity best practices.

Key Capabilities

  • Lateral movement within a network
  • Exploitation of zero-day vulnerabilities
  • Use of cryptocurrency for payment
  • Ability to spread using legacy protocols

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

EternalBlue exploit

Campaigns & Victims

The WannaCry attack is characterized by its rapid spread and global reach, with the attackers seeking to extort money from organizations in a short period of time. The attack's operational tempo is high, with the attackers seeking to quickly compromise a large number of systems and demand payment. The attack's notable past operations include the compromise of several high-profile organizations, including the UK's National Health Service (NHS) and the Spanish telecoms company, Telefonica.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Prioritize patching and vulnerability management
  • Implement robust incident response plans
  • Use secure protocols and retire legacy systems
  • Conduct regular backups and disaster recovery procedures

Suggested Tags

Ransomware
Cybercrime
Financial gain

Confidence Assessment

The confidence level in the available data is high, given the widespread impact of the WannaCry attack and the extensive media coverage. However, there may be some information gaps regarding the attackers' identities and motivations, as well as the full extent of the attack's impact.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA256 10 MD5 10

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

52

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Targeting
Zero-Day Exploitation
Cybercrime
Financial gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 12, 2017
Last Seen
Feb 23, 2018
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.