WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat. Cybercriminals used the ransomware to hold an organization's data hostage and extort money in the form of cryptocurrency. WannaCry spreads using EternalBlue, an exploit leaked from the National Security Agency (NSA). EternalBlue enables attackers to use a zero-day vulnerability to gain access to a system. It targets Windows computers that use a legacy version of the Server Message Block (SMB) protocol. Known victims: 33
Objectives
Executive Summary
The WannaCry ransomware attack, first seen in May 2017, is a global cyber threat that spreads by exploiting vulnerabilities in the Windows operating system, with the primary motivation of organizational gain through financial extortion. The attack targets Windows computers using a legacy version of the Server Message Block (SMB) protocol. WannaCry's impact was significant, with 33 known victims.
Goals & Targeting
The WannaCry ransomware attack is primarily motivated by financial gain, with the attackers seeking to extort money from organizations in exchange for the decryption key. The attack targets Windows computers using a legacy version of the SMB protocol, which suggests that the attackers are seeking to exploit vulnerability in widely used systems. The typical victims of the WannaCry attack are organizations that have not prioritized patching and vulnerability management, and that use outdated systems and protocols.
Enhanced Description
The WannaCry attack also highlights the risks associated with the use of legacy systems and protocols. The attack's ability to spread using the SMB protocol, which is widely used in many organizations, underscores the need for organizations to prioritize the retirement of legacy systems and the adoption of more secure protocols. Furthermore, the attack demonstrates the importance of having robust incident response plans in place, including regular backups, disaster recovery procedures, and employee training on cybersecurity best practices.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The WannaCry attack is characterized by its rapid spread and global reach, with the attackers seeking to extort money from organizations in a short period of time. The attack's operational tempo is high, with the attackers seeking to quickly compromise a large number of systems and demand payment. The attack's notable past operations include the compromise of several high-profile organizations, including the UK's National Health Service (NHS) and the Spanish telecoms company, Telefonica.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is high, given the widespread impact of the WannaCry attack and the extensive media coverage. However, there may be some information gaps regarding the attackers' identities and motivations, as well as the full extent of the attack's impact.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
52
IOCs
0
Observed Data
0
Tactics