WannaCry
MITRE ATT&CK: S0366 View on attack.mitre.org
Aliases: WanaCry, WanaCrypt, WanaCrypt0r, WCry, WannaCrypt, WannaCry, WCrypt, WCRY, Wana Decrypt0r, Wcry
- First seen
- 2017-05-12 00:00:00
- Malware type
- ransomware, worm
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1294 (1261 malicious)
- Last IoC activity
- 2026-09-02 03:33:03
- Profile updated
- 2026-07-07 15:42:14
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector technology-and-telecommunications energy-and-utilities transportation-and-logistics
Context
WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries. It contains worm-like features to spread itself across a computer network using the SMBv1 exploit EternalBlue.
Recent IoC activity
1,266 malicious indicators in Maltiverse are attributed to WannaCry (S0366). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 212 Sigma rules
Malware & tools used
- Exploitation of Remote Services (attack-pattern)
- Service Stop (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- RDP Hijacking (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Remote System Discovery (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Windows Permissions (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Windows Service (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Detection rules
- CAPE_Wanacry (yara-rule)
Reports & references
- media.kasperskycontenthub.com — Guerrero Saade Raiu Vb2017 (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- gist.github.com — 989428Fa5504F378B993Ee6Efbc0B168 (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- resources.malwarebytes.com — 2020 State Of Malware Report (report)
- sites.temple.edu — Ci Rw Attacks (report)
- ESET — Eset Threat Report Q22020 (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- i.blackhat.com — Eu 20 Rivera From Zero To Sixty The Story Of North Koreas Rapid Ascent To Becoming A Global Cyber Superpower (report)
- Kaspersky — 97239 (report)
- brandefense.io — Lazarus Apt Group Apt38 (report)
- Broadcom/Symantec — Wannacry Ransomware Attacks Show Strong Links Lazarus Group (report)
- virusbulletin.com — Vb2018 Kalnai Poslusny (report)
- metaswan.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 1 (report)
- swanleesec.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 1 (report)
- storage.googleapis.com — Ce44Cbda9Fdc061050C1D2A5Dec0270874A9Dc85 (report)
- Microsoft — Human Operated Ransomware (report)
- news.sophos.com — Dearcry Ransomware Attacks Exploit Exchange Server Vulnerabilities (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Wannacryptor (report)
- flashpoint-intel.com — Linguistic Analysis Wannacry Ransomware (report)
- github.com — Wannacry%20Ransomware%20Report (report)
- youtube.com — Watch (report)
- blog.avast.com — Ransomware That Infected Telefonica And Nhs Hospitals Is Spreading Aggressively With Over 50000 Attacks So Far Today (report)
- independent.co.uk — Wannacry Malware Hack Nhs Report Cybercrime North Korea Uk Ben Wallace A8022491 (report)
- Kaspersky — Wannacry Ransomware Used In Widespread Attacks All Over The World (report)