logo

WannaCry 2.0 ransomware attacks continue...

ID: 627917e5-7c24-5982-b827-dd7400baaaf3

STIX ID: report--627917e5-7c24-5982-b827-dd7400baaaf3

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report analyzes the WannaCry (WannaCrypt) 2017 ransomware outbreak: initial droppers that check killswitch domains, network propagation using the MS17-010/ETERNALBLUE SMB exploit, embedded WannaCry 2.0 payloads that install as services and encrypt user files (appending .wnry), and observed downloader variants hosted on compromised servers; it provides IoCs (MD5 hashes, domains, URLs), installation/config details, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.