Five years after the WannaCry dumpster fire, ransomware remains a global threat
ID: 02020e3e-feec-501e-a7b8-9336d2dfef0e
STIX ID: report--02020e3e-feec-501e-a7b8-9336d2dfef0e
Feed Name: ReliaQuest Blog
This report reviews the 12 May 2017 WannaCry ransomware campaign: a wormable ransomware outbreak that used the NSA-leaked EternalBlue SMB exploit and DoublePulsar backdoor to self-propagate, was partially halted by a researcher-registered kill-switch domain, infected over 230,000 devices across ~150 countries, caused roughly $4 billion in damage and major disruption (notably to the UK NHS), and was later attributed to North Korean APT actors (Lazarus/APT38); the analysis highlights operational failures by attackers and defenders’ lessons on patch management and ransomware operational security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
