Overview
WannaCry combined ransomware with a worm that exploited SMB via the EternalBlue exploit, which had been leaked from a government toolkit.\nWithin hours it crossed borders automatically, taking the UK's National Health Service offline: operations cancelled, ambulances diverted, records unreachable.\nThe spread only stopped because a researcher registered an unregistered domain that acted as a kill switch.\nPatch MS17-010 and disable SMBv1 and the same event cannot repeat.
Indicators of Compromise
Signals that suggest this is present on a system.
- Port 445 reachable from untrusted networks
- wcry ransom note files
- MS17-010 missing on Windows hosts
Controls that stop it
-
Keep Tested, Offline Backups
Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.