Critical severity Famous Malware

WannaCry

The 2017 ransomware worm that crippled hospitals using a leaked Windows exploit.

Overview

WannaCry combined ransomware with a worm that exploited SMB via the EternalBlue exploit, which had been leaked from a government toolkit.\nWithin hours it crossed borders automatically, taking the UK's National Health Service offline: operations cancelled, ambulances diverted, records unreachable.\nThe spread only stopped because a researcher registered an unregistered domain that acted as a kill switch.\nPatch MS17-010 and disable SMBv1 and the same event cannot repeat.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Port 445 reachable from untrusted networks
  • wcry ransom note files
  • MS17-010 missing on Windows hosts

Controls that stop it

  • Keep Tested, Offline Backups

    Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used