logo

Massive outbreak of ransomware variant infects large amounts of computers around the world

ID: 69798d0b-46fa-5755-b217-911a32bfc397

STIX ID: report--69798d0b-46fa-5755-b217-911a32bfc397

Feed Name: Fox-IT blog

Threat Score
85/100

Date Published: 2017-05-12

Date Updated: 2026-04-27

...
...

On May 12, 2017 a global WannaCry ransomware campaign exploited the Windows SMB vulnerability (MS17-010/ETERNALBLUE) to self-propagate and encrypt files across internal networks; the report documents the large-scale impact, discovery of a hardcoded kill-switch domain that temporarily halted execution, Tor-based C2 onion addresses, Snort detection rules, recommended mitigations (apply MS17-010, disable SMBv1, isolate unpatched systems, verify backups), and other IoCs and behavioral details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.