What is the WannaCry Ransomware Attack? | UpGuard
ID: 4f8899a9-1576-50b6-8e13-de231cebdbe3
STIX ID: report--4f8899a9-1576-50b6-8e13-de231cebdbe3
Feed Name: UpGuard Blog
WannaCry was a 2017 global cryptoworm ransomware campaign that exploited the NSA-derived EternalBlue SMB vulnerability and leveraged the DoublePulsar backdoor to self-propagate across Windows systems, infecting an estimated 200,000+ machines in 150 countries and causing widespread disruption (notably to the UK NHS); the report describes the malware's behavior, kill-switch discovery, Microsoft patches (MS17-010), attribution to North Korean-linked Lazarus actors, impact, and recommended mitigations such as prompt patching and backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
