logo

Five years after the WannaCry dumpster fire, ransomware remains a global threat

ID: 02020e3e-feec-501e-a7b8-9336d2dfef0e

STIX ID: report--02020e3e-feec-501e-a7b8-9336d2dfef0e

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2022-05-11

Date Updated: 2026-04-29

...
...

This report reviews the 12 May 2017 WannaCry ransomware campaign: a wormable ransomware outbreak that used the NSA-leaked EternalBlue SMB exploit and DoublePulsar backdoor to self-propagate, was partially halted by a researcher-registered kill-switch domain, infected over 230,000 devices across ~150 countries, caused roughly $4 billion in damage and major disruption (notably to the UK NHS), and was later attributed to North Korean APT actors (Lazarus/APT38); the analysis highlights operational failures by attackers and defenders’ lessons on patch management and ransomware operational security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.