wannacry

Ransomware
Sourceransomware.live

About the group

WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat. Cybercriminals used the ransomware to hold an organization's data hostage and extort money in the form of cryptocurrency. WannaCry spreads using EternalBlue, an exploit leaked from the National Security Agency (NSA). EternalBlue enables attackers to use a zero-day vulnerability to gain access to a system. It targets Windows computers that use a legacy version of the Server Message Block (SMB) protocol.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group wannacry has 3 known ransomware victims. See the most affected sectors and countries and recent victims.

3known victims
3in Brazil
2sectors hit
Most attacked sectors
Government & Defense2
Energy & Utilities1
Most affected countries
🇧🇷 Brasil3
Recent victims
Brazil's social security systemGovernment & Defense · BR · 2017-05-12
PetrobrasEnergy & Utilities · BR · 2017-05-12
Brazil's Foreign MinistryGovernment & Defense · BR · 2017-05-12

wannacry uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →