WannaCry Global Self-Propagating Ransomware Worm
Key Facts
- Legal Status: CHARGED in U.S. District Court for the Central District of California.
- Primary Target Sector: Healthcare, Logistics, Critical Infrastructure.
- Documented Financial Loss: $4.0 billion.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Automated network worm propagation exploiting the MS17-010 SMBv1 vulnerability (EternalBlue / DOUBLEPULSAR) against Internet-facing and internal TCP port 445 services without requiring user interaction.
Operational & Financial Fallout
Infected over 200,000 computers across 150 countries within hours. Paralyzed the United Kingdom National Health Service (NHS), forcing hospital emergency ward diversions, canceling 19,000 medical appointments, and freezing operations at Renault, FedEx, and Deutsche Bahn, with estimated economic damages exceeding $4 billion.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Automated network worm propagation exploiting the MS17-010 SMBv1 vulnerability (EternalBlue / DOUBLEPULSAR) against Internet-facing and internal TCP port 445 services without requiring user interaction.
Adversary Kill Chain Flow
5 Documented PhasesEternalBlue (CVE-2017-0144) buffer overflow exploited unpatched SMBv1 servers, installing the DOUBLEPULSAR ring-0 kernel payload.
The kernel payload injected the WannaCry launcher into lsass.exe, initiating worm replication threads and payload unpacking.
WannaCry spawned threads scanning random public IP addresses and local RFC 1918 subnets on TCP port 445 to propagate autonomously.
The binary queried a hardcoded, unregistered domain; when cybersecurity researcher Marcus Hutchins sinkholed the domain, execution halted globally.
Target files were encrypted, shadow copies purged with vssadmin, and @[email protected] UI presented demanding Bitcoin payments.
Infected over 200,000 computers across 150 countries within hours. Paralyzed the United Kingdom National Health Service (NHS), forcing hospital emergency ward diversions, canceling 19,000 medical appointments, and freezing operations at Renault, FedEx, and Deutsche Bahn, with estimated economic damages exceeding $4 billion.
Procedural & Incident Timeline
WannaCry breaks out globally, taking 80 UK National Health Service hospitals offline.
Security researcher registers unregistered killswitch domain, stopping global worm propagation.
U.S. DOJ unseals charges attributing the outbreak to North Korean military intelligence.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Park Jin Hyok | Democratic People's Republic of Korea | fugitive | Pending | None | Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1210 | "WannaCry scanned local subnets and external IP address ranges on TCP port 445, exploiting unpatched SMBv1 implementations using EternalBlue to gain remote kernel execution." | DOJ Criminal Complaint ¶ 88, Page 61 | reviewed | |
| T1486 | Data Encrypted for Impact Impact | "The worm utilized RSA-2048 and AES-128 cryptographic algorithms to encrypt user documents, changing file extensions to .WNCRY and creating @[email protected] instructions." | National Cyber Security Centre (NCSC) Technical Brief | reviewed |
| T1562.001 | Disable or Modify Tools Defense Evasion | "The executable terminated security software processes and ran icacls . /grant Everyone:F /T /C /Q to grant universal write permissions before encryption." | CISA Alert TA17-132A | reviewed |