CASE DOSSIER charged

WannaCry Global Self-Propagating Ransomware Worm

Docket: 2:18-cr-00569 Court: U.S. District Court for the Central District of California Opened: 2017-05-12 Sector: Healthcare, Logistics, Critical Infrastructure

Key Facts

Status
CHARGED
Legal disposition
Loss Amount
$4.0 billion
Global emergency response costs, canceled surgeries, and shipping terminal closures.
Techniques
3
Verified mappings
Defendants
1
Named in charges
  • Legal Status: CHARGED in U.S. District Court for the Central District of California.
  • Primary Target Sector: Healthcare, Logistics, Critical Infrastructure.
  • Documented Financial Loss: $4.0 billion.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Global automated ransomware worm that weaponized the leaked NSA EternalBlue exploit (MS17-010) to self-propagate across 200,000 Windows computers in over 150 countries within hours, paralyzing 80 National Health Service (NHS) hospital trusts in the UK.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Automated network worm propagation exploiting the MS17-010 SMBv1 vulnerability (EternalBlue / DOUBLEPULSAR) against Internet-facing and internal TCP port 445 services without requiring user interaction.

Operational & Financial Fallout

Infected over 200,000 computers across 150 countries within hours. Paralyzed the United Kingdom National Health Service (NHS), forcing hospital emergency ward diversions, canceling 19,000 medical appointments, and freezing operations at Renault, FedEx, and Deutsche Bahn, with estimated economic damages exceeding $4 billion.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Automated network worm propagation exploiting the MS17-010 SMBv1 vulnerability (EternalBlue / DOUBLEPULSAR) against Internet-facing and internal TCP port 445 services without requiring user interaction.

Adversary Kill Chain Flow

5 Documented Phases
1
Remote Exploitation SMBv1 Remote Exploit Propagation (EternalBlue)
MITRE ATT&CK T1210 →

EternalBlue (CVE-2017-0144) buffer overflow exploited unpatched SMBv1 servers, installing the DOUBLEPULSAR ring-0 kernel payload.

Artifacts & Tooling: EternalBlue exploit (MS17-010) DOUBLEPULSAR kernel implant
2
Execution & Injection In-Memory Payload Execution
MITRE ATT&CK T1055 →

The kernel payload injected the WannaCry launcher into lsass.exe, initiating worm replication threads and payload unpacking.

Artifacts & Tooling: lsass.exe code injection tasksche.exe launcher
3
Autonomous Propagation Global Subnet & Internet Scanning
MITRE ATT&CK T1046 →

WannaCry spawned threads scanning random public IP addresses and local RFC 1918 subnets on TCP port 445 to propagate autonomously.

Artifacts & Tooling: Port 445 SYN scanner Autonomous replication module
4
Evasion & Control Domain Kill-switch Probe
MITRE ATT&CK T1489 →

The binary queried a hardcoded, unregistered domain; when cybersecurity researcher Marcus Hutchins sinkholed the domain, execution halted globally.

Artifacts & Tooling: Kill-switch sinkhole domain probe HTTP GET beacon
5
Extortion Impact RSA-2048 / AES-128 Encryption & Ransom Demand
MITRE ATT&CK T1486 →

Target files were encrypted, shadow copies purged with vssadmin, and @[email protected] UI presented demanding Bitcoin payments.

Artifacts & Tooling: vssadmin.exe Delete Shadows /All /Quiet @[email protected] wnry encrypted files
Real-World Blast Radius & Operational Fallout

Infected over 200,000 computers across 150 countries within hours. Paralyzed the United Kingdom National Health Service (NHS), forcing hospital emergency ward diversions, canceling 19,000 medical appointments, and freezing operations at Renault, FedEx, and Deutsche Bahn, with estimated economic damages exceeding $4 billion.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Completely disable the legacy SMBv1 protocol across all endpoints and servers.
✓ Block inbound and lateral TCP port 445 traffic at network edge perimeters and internal boundary firewalls.
✓ Maintain disciplined patch management cycles to rapidly deploy critical security updates such as MS17-010.
✓ Protect Volume Shadow Copies and implement immutable offsite backups.

Procedural & Incident Timeline

2017-05-12 incident

WannaCry breaks out globally, taking 80 UK National Health Service hospitals offline.

2017-05-12 discovery

Security researcher registers unregistered killswitch domain, stopping global worm propagation.

2018-09-06 indictment

U.S. DOJ unseals charges attributing the outbreak to North Korean military intelligence.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Park Jin Hyok Democratic People's Republic of Korea fugitive Pending None Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1210
"WannaCry scanned local subnets and external IP address ranges on TCP port 445, exploiting unpatched SMBv1 implementations using EternalBlue to gain remote kernel execution." DOJ Criminal Complaint ¶ 88, Page 61 reviewed
T1486 Data Encrypted for Impact
Impact
"The worm utilized RSA-2048 and AES-128 cryptographic algorithms to encrypt user documents, changing file extensions to .WNCRY and creating @[email protected] instructions." National Cyber Security Centre (NCSC) Technical Brief reviewed
T1562.001 Disable or Modify Tools
Defense Evasion
"The executable terminated security software processes and ran icacls . /grant Everyone:F /T /C /Q to grant universal write permissions before encryption." CISA Alert TA17-132A reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, WannaCry Global Self-Propagating Ransomware Worm, No. 2:18-cr-00569 (U.S. District Court for the Central District of California 2017), https://cybercaselibrary.com/cases/wannacry-global-ransomware-worm/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/wannacry-global-ransomware-worm" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>