WannaCry

  • First known sample

    2017
  • Discovery

    2017
  • Number of targets

    10000-300000
  • Current status

    Active
  • Type

    Trojan
  • Targeted platforms

    Windows
  • TOP targeted countries

    India , Russia , Taiwan , Ukraine
  • The way of propagation

    Exploits
  • Purpose/Functions

    Ransomware
  • Special features
    It’s important to understand that while unpatched Windows computers exposing their SMB services can be remotely attacked with the “EternalBlue” exploit and infected by the WannaCry ransomware, the lack of existence of this vulnerability doesn’t really prevent the ransomware component from working. Nevertheless, the presence of this vulnerability appears to be the most significant factor that caused the outbreak.
  • Targets

    Government entities , Telecoms
  • Artefacts/Attribution
    Similarities in cryptic messages could indicate ties with Lazarus group.
  • Description

    The largest ransomware attack in history, attributed to Lazarus, targeting hundreds of thousands of organizations, including medical institutions, across at least 74 countries. After access to the system is gained through an already patched, leaked exploit for a Windows vulnerability, corporate networks are infected with a cryptoworm that encrypts their data.

    Additional information