Vectra Detection and Response to WannaCry Ransomware by Vectra AI Security Research team
ID: 028dad0f-015f-586e-bca3-60807384f15d
STIX ID: report--028dad0f-015f-586e-bca3-60807384f15d
Feed Name: Vectra AI Blog
In May 2017 the WannaCry ransomware outbreak leveraged the EternalBlue/MS17-010 exploit (leaked from the NSA) to rapidly infect an estimated 200,000+ systems across 150 countries and was attributed to the Lazarus Group; Vectra analyzes the attack’s core ransomware behaviors—reconnaissance, lateral movement, scanning, automated replication, file encryption and TOR-based C2—recommends behavior-focused detections, and outlines response actions such as quarantining hosts, reimaging, and restoring from offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
