{
  "id": "case-wannacry-worm",
  "slug": "wannacry-global-ransomware-worm",
  "title": "WannaCry Global Self-Propagating Ransomware Worm",
  "summary": "Global automated ransomware worm that weaponized the leaked NSA EternalBlue exploit (MS17-010) to self-propagate across 200,000 Windows computers in over 150 countries within hours, paralyzing 80 National Health Service (NHS) hospital trusts in the UK.",
  "case_number": "2:18-cr-00569",
  "court": "U.S. District Court for the Central District of California",
  "district": "C.D. Cal.",
  "country": "International / United States",
  "opened_at": "2017-05-12",
  "status": "charged",
  "victim_sector": "Healthcare, Logistics, Critical Infrastructure",
  "victim_country": "United Kingdom",
  "loss_amount_usd": 4000000000,
  "loss_amount_note": "Global emergency response costs, canceled surgeries, and shipping terminal closures.",
  "first_seen_at": "2017-05-12T07:44:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "lazarus-group",
  "defendant_slugs": [
    "park-jin-hyok"
  ],
  "cves": [
    "CVE-2017-0144"
  ],
  "techniques": [
    {
      "technique_id": "T1210",
      "evidence_excerpt": "WannaCry scanned local subnets and external IP address ranges on TCP port 445, exploiting unpatched SMBv1 implementations using EternalBlue to gain remote kernel execution.",
      "evidence_locator": "DOJ Criminal Complaint \u00b6 88, Page 61",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint: U.S. v. Park Jin Hyok",
      "source_url": "https://www.justice.gov"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "The worm utilized RSA-2048 and AES-128 cryptographic algorithms to encrypt user documents, changing file extensions to .WNCRY and creating @Please_Read_Me@.txt instructions.",
      "evidence_locator": "National Cyber Security Centre (NCSC) Technical Brief",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "NCSC UK WannaCry Guidance",
      "source_url": "https://www.ncsc.gov.uk",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1562.001",
      "evidence_excerpt": "The executable terminated security software processes and ran icacls . /grant Everyone:F /T /C /Q to grant universal write permissions before encryption.",
      "evidence_locator": "CISA Alert TA17-132A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert TA17-132A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/ta17-132a",
      "technique_name": "Disable or Modify Tools",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2017-05-12",
      "description": "WannaCry breaks out globally, taking 80 UK National Health Service hospitals offline."
    },
    {
      "event_type": "discovery",
      "event_date": "2017-05-12",
      "description": "Security researcher registers unregistered killswitch domain, stopping global worm propagation."
    },
    {
      "event_type": "indictment",
      "event_date": "2018-09-06",
      "description": "U.S. DOJ unseals charges attributing the outbreak to North Korean military intelligence."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Automated network worm propagation exploiting the MS17-010 SMBv1 vulnerability (EternalBlue / DOUBLEPULSAR) against Internet-facing and internal TCP port 445 services without requiring user interaction.",
    "blast_radius": "Infected over 200,000 computers across 150 countries within hours. Paralyzed the United Kingdom National Health Service (NHS), forcing hospital emergency ward diversions, canceling 19,000 medical appointments, and freezing operations at Renault, FedEx, and Deutsche Bahn, with estimated economic damages exceeding $4 billion.",
    "kill_chain": [
      {
        "phase": "Remote Exploitation",
        "title": "SMBv1 Remote Exploit Propagation (EternalBlue)",
        "description": "EternalBlue (CVE-2017-0144) buffer overflow exploited unpatched SMBv1 servers, installing the DOUBLEPULSAR ring-0 kernel payload.",
        "technical_artifacts": [
          "EternalBlue exploit (MS17-010)",
          "DOUBLEPULSAR kernel implant"
        ],
        "mitre_technique_id": "T1210"
      },
      {
        "phase": "Execution & Injection",
        "title": "In-Memory Payload Execution",
        "description": "The kernel payload injected the WannaCry launcher into lsass.exe, initiating worm replication threads and payload unpacking.",
        "technical_artifacts": [
          "lsass.exe code injection",
          "tasksche.exe launcher"
        ],
        "mitre_technique_id": "T1055"
      },
      {
        "phase": "Autonomous Propagation",
        "title": "Global Subnet & Internet Scanning",
        "description": "WannaCry spawned threads scanning random public IP addresses and local RFC 1918 subnets on TCP port 445 to propagate autonomously.",
        "technical_artifacts": [
          "Port 445 SYN scanner",
          "Autonomous replication module"
        ],
        "mitre_technique_id": "T1046"
      },
      {
        "phase": "Evasion & Control",
        "title": "Domain Kill-switch Probe",
        "description": "The binary queried a hardcoded, unregistered domain; when cybersecurity researcher Marcus Hutchins sinkholed the domain, execution halted globally.",
        "technical_artifacts": [
          "Kill-switch sinkhole domain probe",
          "HTTP GET beacon"
        ],
        "mitre_technique_id": "T1489"
      },
      {
        "phase": "Extortion Impact",
        "title": "RSA-2048 / AES-128 Encryption & Ransom Demand",
        "description": "Target files were encrypted, shadow copies purged with vssadmin, and @WanaDecryptor@.exe UI presented demanding Bitcoin payments.",
        "technical_artifacts": [
          "vssadmin.exe Delete Shadows /All /Quiet",
          "@WanaDecryptor@.exe",
          "wnry encrypted files"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Completely disable the legacy SMBv1 protocol across all endpoints and servers.",
      "Block inbound and lateral TCP port 445 traffic at network edge perimeters and internal boundary firewalls.",
      "Maintain disciplined patch management cycles to rapidly deploy critical security updates such as MS17-010.",
      "Protect Volume Shadow Copies and implement immutable offsite backups."
    ]
  }
}