WannaCry

Last reviewed:

WannaCry is a ransomware cryptoworm that emerged in May 2017, targeting computers running the Microsoft Windows operating system. It encrypts files on the infected computer, demanding a ransom payment in Bitcoin to decrypt the files. WannaCry exploits a vulnerability in the Windows Server Message Block (SMB) protocol, which was publicly disclosed by the hacking group known as the Shadow Brokers. The attack affected hundreds of thousands of computers across more than 150 countries, causing significant disruption to various sectors, including healthcare, telecommunications, and logistics. As of October 2023, WannaCry remains a notable example of the impact of ransomware on global cybersecurity.

Overview

WannaCry is a form of ransomware that encrypts files on a victim's computer, rendering them inaccessible until a ransom is paid. It leverages the EternalBlue exploit, which targets a vulnerability in the SMB protocol on Windows systems. The malware spread rapidly across networks, affecting organizations worldwide. The attack highlighted the importance of timely software updates and robust cybersecurity measures. Despite efforts to mitigate its impact, WannaCry continues to serve as a cautionary tale in the cybersecurity community.

History

WannaCry first appeared on May 12, 2017, and quickly gained notoriety due to its rapid spread and significant impact. The ransomware attack was facilitated by the EternalBlue exploit, which was part of a collection of hacking tools allegedly developed by the United States National Security Agency (NSA) and leaked by the Shadow Brokers group. The attack primarily affected older versions of Windows that had not been updated with security patches released by Microsoft in March 2017. The global scale of the attack prompted widespread media coverage and led to increased awareness of the vulnerabilities in outdated software systems.

Technical characteristics

WannaCry is a cryptoworm that combines ransomware with a self-propagating worm mechanism. It encrypts files using the Advanced Encryption Standard (AES) and RSA encryption algorithms, appending the ".wncry" extension to affected files. The malware demands a ransom payment in Bitcoin, typically ranging from $300 to $600, to provide the decryption key. WannaCry exploits the SMB vulnerability (CVE-2017-0144) to spread across networks, allowing it to infect other vulnerable machines without user interaction.

Infection vector

WannaCry primarily spreads through the exploitation of the SMB protocol vulnerability in Windows systems. Once a computer is infected, the malware scans the network for other vulnerable machines and attempts to propagate itself using the EternalBlue exploit. This self-replicating capability contributed to the rapid spread of WannaCry across networks and organizations. The initial infection vector for WannaCry remains unclear, but it is believed to have been introduced through phishing emails or malicious websites.

Notable campaigns

The WannaCry ransomware attack in May 2017 is one of the most significant cyber incidents in recent history. It affected numerous organizations, including the United Kingdom's National Health Service (NHS), which experienced widespread disruption to its operations. Other notable victims included telecommunications companies, logistics firms, and government agencies. The attack prompted a global response, with cybersecurity experts and organizations working to contain the spread of the malware and mitigate its impact.

Detection and mitigation

Detecting WannaCry involves monitoring network traffic for signs of the SMB exploit and identifying encrypted files with the ".wncry" extension. Antivirus and endpoint protection solutions can help detect and block the ransomware. Mitigation strategies include applying security patches to vulnerable systems, disabling SMBv1, and implementing network segmentation to limit the spread of the malware. Regular data backups and user education on phishing and social engineering attacks are also essential components of a comprehensive defense strategy against ransomware threats.

Timeline of WannaCry Attack

Impact of WannaCry by Sector

See also

  • Lateral movement

Sources

Categories: Malware | Incidents
Last updated: September 3, 2026