EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/wannacry-ransomware-2017
239/430

File EL-0192CriticalResolvedRansomware Attack / Cryptoworm/Wiper

WannaCry Ransomware

Also filed as WannaCry · EternalBlue Ransomware Attack · DPRK Ransomware Attack

WannaCry was a global cryptoworm that exploited the EternalBlue vulnerability in Windows SMB protocol. It rapidly spread across 150 countries, crippling critical infrastructure, most notably the UK's National Health Service. The attack demanded ransom payments in Bitcoin, demonstrating a sophisticated blend of cyber warfare and financial extortion.

  • #ransomware
  • #eternalblue
  • #nsa-leak
  • #lazarus-group
  • #dprk
  • #windows
  • #cyberattack
Notoriety9/10
Event
12 May 2017
Disclosed
12 May 2017
Target
National Health Service (NHS)
Actor
Lazarus Group
Status
Resolved

01Summary

The WannaCry ransomware attack, which began on May 12, 2017, was a massive global cyber incident targeting unpatched Microsoft Windows systems. The attack's primary mechanism was the exploitation of the EternalBlue vulnerability, a flaw in the Server Message Block (SMB) protocol, which was reportedly stolen from the NSA and leaked by the Shadow Brokers. WannaCry encrypted data on infected machines and displayed a ransom note demanding Bitcoin. The worm's self-propagating nature allowed it to spread laterally across networks with minimal human interaction. Key victims included the UK's NHS, which was forced to cancel appointments and divert ambulances, and major industrial targets like Renault and Nissan, which halted production lines. The incident highlighted the severe risks posed by unpatched legacy systems and the weaponization of state-level exploits.

02Background

The attack leveraged the EternalBlue exploit, a vulnerability that had been publicly known but not universally patched across all corporate and government networks. The preceding leak of NSA tools by the Shadow Brokers significantly lowered the barrier to entry for sophisticated cyberattacks, making state-level exploits available to criminal groups like the Lazarus Group.

03Key revelations

  1. 01The attack demonstrated the global vulnerability of unpatched legacy IT infrastructure.
  2. 02It confirmed the weaponization of state-level exploits (EternalBlue) by criminal groups.
  3. 03The attack severely disrupted critical national services, such as the UK's NHS.

04Technical analysis

WannaCry utilized the EternalBlue exploit (MS17-010) to achieve remote code execution on vulnerable Windows machines. Once inside, the ransomware encrypted files using strong algorithms and displayed a ransom note. Its worm-like capability allowed it to scan for and infect other machines on the same network segment without user intervention. The attack was highly effective because it targeted a fundamental, widely used protocol (SMB) and exploited a flaw that was difficult to patch across diverse global IT environments.

Attack vector
Exploitation of the EternalBlue vulnerability (MS17-010) in the Server Message Block (SMB) protocol.
Attack method
Cryptoworm/Wormable Ransomware
Initial access
Network vulnerability exploitation (SMB)
Lateral movement
Wormable propagation via SMB protocol
Persistence
File encryption and ransom note display
Tool / malware
WannaCry
Malware family
WannaCry
Malware type
Ransomware

Vulnerabilities exploited

  • MS17-010 (EternalBlue)

MITRE ATT&CK techniques

  • T1190
  • T1021.001

05Threat actor

The Lazarus Group is widely believed to be a state-sponsored hacking collective operating under the direction of North Korea's government. They are known for conducting highly sophisticated, financially motivated attacks, targeting financial institutions, intellectual property, and critical infrastructure to generate foreign currency.

Aliases

  • DPRK RGB
  • North Korea

APT designations

  • Lazarus Group

MITRE groups

  • T1190

Attribution sources

  • Microsoft
  • Mandiant
  • BBC
  • Reuters

06Victims and impact

Additional victims

  • Renault
  • Nissan
  • FedEx

Countries affected

  • United Kingdom
  • United States
  • France
  • Japan
  • Global

07Data exposed

Data types

  • Encrypted files
  • System data

Notable documents

  • Ransom Note (WannaCry)

08Financial damage

Estimated costs include operational downtime, recovery efforts, and lost productivity across multiple sectors.

09Timeline

  1. 2017-05-01Shadow Brokers leak NSA tools (EternalBlue)
  2. 2017-05-12WannaCry ransomware begins global propagation
  3. 2017-05-12UK NHS reports major system outages
  4. 2017-05-17Global security patches and mitigation efforts stabilize

10Key figures

  • NSAOriginal developer of the exploit · National Security AgencyAmericanExploit leaked, leading to global vulnerability
  • Shadow BrokersGroup that leaked the exploit tools · Cybercrime GroupMade state-level tools available for criminal use

11On the record

The attack spread rapidly across 150 countries, infecting over 200,000 computers.

Source Content, Describing the scale of the global impact.

12Reaction and fallout

Public reaction

The public reaction was characterized by alarm regarding the fragility of critical services, particularly healthcare. Governments worldwide issued urgent warnings and mandated immediate patching of vulnerable systems.

Political impact

The attack forced governments to accelerate the adoption of robust cybersecurity policies and increased international dialogue regarding cyber warfare norms. It highlighted the need for better coordination between private industry and national security agencies.

Geopolitical consequences

The attribution to the Lazarus Group reinforced the perception of North Korea as a major state-sponsored cyber threat actor, escalating international sanctions and cyber defense efforts against the DPRK.

13Legal

No specific criminal convictions were widely reported in relation to the attack's execution, but the incident spurred significant international legal and regulatory discussions regarding cyber liability and critical infrastructure protection.

Civil lawsuits

  • NHS Trust · Operational disruption and data loss · UK · Ongoing/Settlement

14Aftermath

Policy changes

  • Mandatory patching of critical vulnerabilities (e.g., SMB protocol)
  • Increased investment in network segmentation for critical infrastructure

Regulatory changes

  • Strengthened GDPR enforcement regarding cyber incident reporting

Security improvements

  • Deployment of network intrusion detection systems (NIDS)
  • Adoption of Zero Trust Architecture principles
  • Immediate patching of all known critical vulnerabilities

15Significance and legacy

Significance

WannaCry is a landmark event in cyber history because it successfully demonstrated the weaponization of state-level exploits against civilian critical infrastructure. It moved ransomware from a purely criminal enterprise to a tool of geopolitical warfare, forcing global policy shifts in cybersecurity defense.

Legacy

The incident permanently raised the global baseline for cyber risk awareness, leading to massive corporate and governmental spending on defensive cybersecurity measures. It also accelerated the public understanding of the threat posed by nation-state cyber espionage and ransomware.

16Disclosure and media

Authentication
Technical analysis of malware samples and network traffic

Media partners

  • BBC
  • The Guardian
  • Reuters

Publishing organisations

  • BBC
  • Mandiant

17Related files

Related events

  • EternalBlue

Inspired by

  • wannacry-ransomware-2017

Went on to inspire

  • colony-spionge-2017

18Field notes

  1. 01The attack was initially contained by a 'kill switch' domain registered by security researchers, which prevented further spread.
  2. 02The ransomware was highly effective because it targeted the SMB protocol, which is essential for many basic network functions.

19Resolution

The attack was mitigated by rapid patching of the MS17-010 vulnerability and the implementation of network segmentation, though the full recovery of affected systems was a prolonged process.

20Sources

Wikipedia article ↗

Official documents

  • Microsoft Security Advisory MS17-010

References

  1. [1]BBC News Report on WannaCry
  2. [2]Mandiant Threat Intelligence Report
  3. [3]Microsoft Security Update Documentation
Fact sheetEL-0192

Dates

Event
12 May 2017
Started
12 May 2017
Ended
17 May 2017
Duration
6 days
Discovered
12 May 2017
Disclosed
12 May 2017
Resolved
17 May 2017
Ongoing
No

Target

Organisation
National Health Service
Type
Healthcare
Sector
Healthcare
Country
United Kingdom
Gov. level
National

Actor

Name
Lazarus Group
Type
Nation-State Actor
Nationality
North Korean
Nation-state
Democratic People's Republic of Korea (DPRK)
Motivation
Financial gain and geopolitical disruption
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Mixed
Published
No

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.