WannaCry Global Ransomworm
May 2017 worldwide ransomware outbreak (WannaCry) that spread automatically via EternalBlue (CVE-2017-0144), disrupting hospitals, logistics and enterprises in 150+ countries.
WannaCry (May 2017) was an SMB-based ransomware worm exploiting EternalBlue (CVE-2017-0144) that self-propagated across unpatched Windows systems, encrypting files and demanding ransom in 150+ countries within days.
Definition
Self-propagating ransomware (WannaCry) using leaked NSA SMB exploits (EternalBlue) to move laterally without user interaction; encrypted files with .WNCRY extension and displayed ransom notes in 27 languages.
Why It Matters / Impact
Disrupted the U.K. National Health Service, FedEx, Renault and hundreds of thousands of systems; abrupt global halt after a kill-switch domain registration slowed propagation.
Current Status
- Review status: published
- Last updated: 2026-08-26
- Evidence: 3 source(s) · 2 CVE(s) linked
- Confidence: 95%
Related CVEs
EvidenceRelated Malware
Timeline
- 2017-03-14 — MS17-010 patch released
- 2017-05-12 — WannaCry outbreak begins worldwide
- 2017-05-15 — Kill-switch mitigation slows spread
Sources
Start Investigation
Move from reading to investigating WannaCry Global Ransomworm. The workspace is a structured analysis surface — not a chat — organised as:
- Question — what do you need to know about WannaCry Global Ransomworm?
- Evidence — assertions mapped to verifiable references.
- Timeline — events in chronological order.
- Related Entities — CVE, threat actor, campaign, malware links.
- Sources — NVD, CISA KEV, MITRE ATT&CK, vendor advisories.
- Notes — your own observations and working hypotheses.
AI assistance is limited to summarising, explaining, and suggesting related evidence. AI never completes your investigation, modifies entity relationships, or generates facts — all published analysis stays human-reviewed.
Recommended Tools
- IOC LookupSearch OpenTrojan intelligence for indicators tied to this campaign.Look up IOC
Every tool runs passively or locally — inputs are never stored and no target is scanned. Start an investigation on this entity →