Wannacry Ransomware

Description Summary

WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat. Cybercriminals used the ransomware to hold an organization's data hostage and extort money in the form of cryptocurrency. WannaCry spreads using EternalBlue, an exploit leaked from the National Security Agency (NSA). EternalBlue enables attackers to use a zero-day vulnerability to gain access to a system. It targets Windows computers that use a legacy version of the Server Message Block (SMB) protocol.

Threat Actor

Attributed by the U.S., U.K. and allied governments to the Lazarus Group (North Korea). Not a leak-site/extortion crew — WannaCry was a self-propagating worm, and its spread was halted when a researcher (Marcus Hutchins) registered its kill-switch domain.

Technical Indicators

Encryption Extension
.WNCRY (also .WCRY; temporary files use .wncryt)
Encryption Algorithm
AES-128 (CBC) for files + RSA-2048 (key wrapping)
Ransom Note Name
@Please_Read_Me@.txt (plus the 'Wana Decrypt0r 2.0' GUI / @WanaDecryptor@.exe)
Targeted Industries
Cross-sector — notably Healthcare (UK NHS), Telecommunications, Manufacturing, Logistics
First Seen
12 May 2017
Last Seen
May 2017 (outbreak halted by the kill-switch domain; unpatched variants persist)
Geographical Location
Worldwide — ~230,000 systems across 150+ countries

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Lateral Movement x 3 T1210 Exploitation of Remote Services (EternalBlue / MS17-010)
T1021.002 SMB/Windows Admin Shares
T1570 Lateral Tool Transfer (worm self-propagation)
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery (deletes shadow copies)
T1489 Service Stop