onlinesyscfg.research
utc
syscfg://research
home/research/wannacry-eternalblue
PublishedMalware Analysis

WannaCry and EternalBlue: How the NSA's Hoarded Exploit Infected 200,000 Machines in 72 Hours

2026-08-08-18 min read
#wannacry#eternalblue#ransomware#nsa#shadowbrokers#smb#lazarus

On May 12, 2017, a Friday morning in Europe, NHS hospitals began losing access to patient records. Within hours, screens across 150 countries were showing the same message: Ooops, your files have been encrypted. The ransomware responsible - WannaCry - had spread to over 200,000 machines in 72 hours. It remains the most damaging ransomware deployment in history, measured by both scale and economic impact, estimated at $4–8 billion.

What made WannaCry different from every ransomware that came before it wasn't the ransom demand. The $300–600 price tag was relatively modest. What made it different was how it spread. Every previous ransomware needed a victim to click something - a phishing link, a malicious attachment. WannaCry needed nothing. It scanned the internet for vulnerable machines and infected them automatically. It was a cryptoworm, not a campaign.

And the vulnerability it used to do this had been sitting in the NSA's arsenal for years.

//EternalBlue: The NSA's Crown Jewel

EternalBlue (MS17-010) is an exploit targeting a vulnerability in Microsoft's implementation of the Server Message Block (SMB) protocol - specifically SMBv1, the Windows file-sharing protocol that had been running on virtually every Windows machine since the 1990s. The flaw allows remote code execution without authentication. Send the right packet to port 445 of a vulnerable machine and you own it. No user interaction. No credentials. One network packet.

The NSA discovered this vulnerability sometime around 2010 and classified it as a Tier 1 offensive capability - their most valuable category. They sat on it for approximately five years, using it in active operations rather than reporting it to Microsoft. The agency's calculus was standard for offensive cyber: the exploit's value to their missions outweighed the risk of someone else finding it first. That calculation turned out to be catastrophically wrong.

[WARNING]
Microsoft had released MS17-010 - the patch for EternalBlue - on March 14, 2017. WannaCry launched May 12, 2017. Every machine hit by WannaCry was running an unpatched OS. Many were Windows XP or Windows Server 2003, both end-of-life, with no patch available at all.

//Shadow Brokers

In August 2016, a group calling itself the Shadow Brokers appeared and claimed to have stolen a stockpile of NSA cyberweapons. They auctioned some tools, released others for free, and gradually escalated their disclosures over the following year. Nobody was quite sure who they were - theories ranged from a disgruntled NSA insider to Russian intelligence, to both at once.

On April 14, 2017, Shadow Brokers released their largest dump yet: a tranche of NSA exploits they called "Lost in Translation." The dump included EternalBlue, EternalRomance, EternalChampion, DoublePulsar (a backdoor implant), and a dozen other tools. Everything needed to remotely compromise virtually any unpatched Windows machine.

The release was public. The tools were free. Security researchers, criminals, and foreign intelligence services all downloaded them on the same day. Microsoft had already patched EternalBlue one month earlier, but the gap between patch release and worldwide deployment is measured in months or years - and in government networks, utilities, and hospitals running legacy hardware, sometimes never.

//The Ransomware

WannaCry combined EternalBlue for initial infection with DoublePulsar for payload injection. Once on a machine, it encrypted files using AES-128 and appended a .WNCRY extension. The ransom note demanded $300 in Bitcoin, doubling to $600 after three days, with a threat to delete files permanently after seven days.

The spreading mechanism was what made it extraordinary. After infecting a machine, WannaCry immediately began scanning the local subnet and random internet IP ranges for other systems with port 445 open. Finding one, it attempted the EternalBlue exploit. If successful, it installed itself and repeated the cycle. The worm had no targeting logic - it hit hospitals, car factories, telecoms, universities, and government agencies with equal indifference.

◈ interactive artifact
WannaCry Ransom Screen - May 2017
Accurate recreation of the WannaCry ransom notification. Countdown timer, payment panel, file list - exactly as victims saw it. No functionality.

//The Kill Switch

A 22-year-old British security researcher named Marcus Hutchins - known online as MalwareTech - was reverse-engineering a WannaCry sample on the afternoon of May 12 when he found something odd. The malware was checking a specific domain before executing: a long, random-looking string ending in.com. If the domain resolved, the malware stopped. If it didn't, it continued.

The domain wasn't registered. The check was likely an anti-sandbox mechanism - sandbox environments often return positive for any DNS query to prevent malware from detecting they're being analysed. WannaCry was checking whether it was in a sandbox before running.

Hutchins registered the domain for $10.69. Within minutes, the global spread stopped. The kill switch worked because the worm checked a single hardcoded domain before every infection. Once the domain resolved, every copy of WannaCry in the world halted.

[INFO]
The kill switch domain was iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com. Hutchins registered it at 3:03 PM BST. The Kryptos Logic sinkhole it pointed to absorbed hundreds of millions of connection attempts from infected machines in the following days.

//Attribution

Within months of the attack, US, UK, and Australian intelligence agencies formally attributed WannaCry to the Lazarus Group - a threat actor linked to North Korean intelligence (RGB). The evidence included code reuse from earlier known Lazarus tools (Contopee, Destover), shared infrastructure, and linguistic analysis of Korean-language strings in early versions.

The attack netted North Korea approximately $140,000 in ransom payments - a remarkably small sum for the damage caused. The Bitcoin wallets associated with WannaCry were poorly managed, addresses were tracked publicly, and the operators appeared to have difficulty actually cashing out without attracting attention. For a state-sponsored operation, the operational security was surprisingly poor.

The broader lesson was the one nobody wanted to learn: the NSA's decision to stockpile rather than report the EternalBlue vulnerability directly enabled one of the most damaging cyberattacks in history. When the vulnerability was eventually disclosed - not by the NSA, but by criminals who stole it - critical infrastructure around the world paid the price.

[IOC] WannaCry Indicators of Compromise
# SHA-256 Hashes
24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c
ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa
# Kill Switch Domains
iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.com
# C2 / Bitcoin Wallets
115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn
12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw