WannaCry

MITRE ATT&CK: S0366 View on attack.mitre.org

Aliases: WanaCry, WanaCrypt, WanaCrypt0r, WCry, WannaCrypt, WannaCry, WCrypt, WCRY, Wana Decrypt0r, Wcry

First seen
2017-05-12 00:00:00
Malware type
ransomware, worm
Family
Malware family
Operating systems
windows
Related IoCs
1294 (1261 malicious)
Last IoC activity
2026-09-02 03:33:03
Profile updated
2026-07-07 15:42:14

Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector technology-and-telecommunications energy-and-utilities transportation-and-logistics

Context

WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries. It contains worm-like features to spread itself across a computer network using the SMBv1 exploit EternalBlue.

Recent IoC activity

1,266 malicious indicators in Maltiverse are attributed to WannaCry (S0366). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample b19285bcdf3fed2f9bda055d9f61118a616664ee0a6b594f9731ce20cb67daf5 2026-09-03 3
file sample KerberOPSEC-x86.exe 2026-09-02 1
URL https://github.com/acastillorobles77/MalwareDatabase/tree/master/Windows 2026-09-02 1
URL https://github.com/limiteci/WannaCry/tree/main 2026-09-02 1
URL https://github.com/Zusyaku/Malware-Collection-Part-2/blob/main/WannaCry.exe 2026-09-02 1
URL https://gofile.io/d/XCIXJPmC 2026-09-02 1
URL https://github.com/Da2dalus/The-MALWARE-Repo/blob/master/Ransomware/WannaCrypt0r.exe 2026-09-02 1
file sample Unconfirmed 764834.crdownload 2026-09-02 1
file sample eceb2f25bac4cbca1da5f4e390124912cd91f541ad1ccada2ae2b46f4aceb414.zip 2026-09-02 1
URL https://github.com/limiteci/Wannacry 2026-09-02 1
file sample 934199794bc60824ef445d176576f5af005716f2c9d92c11c6bcf8be92af832b 2026-09-02 1
file sample ba4015669d28f5517b55998833ea2c0690caa0a23beab77119426555827be461 2026-09-02 2
file sample 8540b339ae5a8ce9b54e4a41e42a364b317d78ac6679a8a845d33c27d3f435c8 2026-09-02 3
URL https://github.com/liuchen1701/FakeWannaCry 2026-09-02 1
URL https://github.com/kh4sh3i/Ransomware-Samples/tree/main/Jigsaw 2026-09-02 1
file sample wannacryplus (1).zip 2026-09-02 1
file sample 608371b1c6e84d844d1d07642e404c4d7083567f766ca3055dcb0780c23d016d 2026-09-02 2
file sample ceaa4bf36125d1d0c88e29187b2897b9ab2131c4cfc7bd03d84e89a4cad4ed0f 2026-09-02 2
file sample f5537b45126a777856da43e83ec9327ea284cdf85bd7e1ac29d114444f2e8a80 2026-09-01 2
URL https://github.com/ytisf/theZoo/tree/master/malware/Source/Original/Win32.MCRYPT 2026-09-01 1

Detection coverage

  • 1 YARA rules
  • 212 Sigma rules

Malware & tools used

  • Exploitation of Remote Services (attack-pattern)
  • Service Stop (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • RDP Hijacking (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Windows Permissions (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Windows Service (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)

Used by threat actors

Detection rules

  • CAPE_Wanacry (yara-rule)

Reports & references

  • media.kasperskycontenthub.com — Guerrero Saade Raiu Vb2017 (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • gist.github.com — 989428Fa5504F378B993Ee6Efbc0B168 (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • resources.malwarebytes.com — 2020 State Of Malware Report (report)
  • sites.temple.edu — Ci Rw Attacks (report)
  • ESET — Eset Threat Report Q22020 (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • i.blackhat.com — Eu 20 Rivera From Zero To Sixty The Story Of North Koreas Rapid Ascent To Becoming A Global Cyber Superpower (report)
  • Kaspersky — 97239 (report)
  • brandefense.io — Lazarus Apt Group Apt38 (report)
  • Broadcom/Symantec — Wannacry Ransomware Attacks Show Strong Links Lazarus Group (report)
  • virusbulletin.com — Vb2018 Kalnai Poslusny (report)
  • metaswan.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 1 (report)
  • swanleesec.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 1 (report)
  • storage.googleapis.com — Ce44Cbda9Fdc061050C1D2A5Dec0270874A9Dc85 (report)
  • Microsoft — Human Operated Ransomware (report)
  • news.sophos.com — Dearcry Ransomware Attacks Exploit Exchange Server Vulnerabilities (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Wannacryptor (report)
  • flashpoint-intel.com — Linguistic Analysis Wannacry Ransomware (report)
  • github.com — Wannacry%20Ransomware%20Report (report)
  • youtube.com — Watch (report)
  • blog.avast.com — Ransomware That Infected Telefonica And Nhs Hospitals Is Spreading Aggressively With Over 50000 Attacks So Far Today (report)
  • independent.co.uk — Wannacry Malware Hack Nhs Report Cybercrime North Korea Uk Ben Wallace A8022491 (report)
  • Kaspersky — Wannacry Ransomware Used In Widespread Attacks All Over The World (report)

External references