Skip to content

Ransomware

WannaCryptor

aka Wana Decrypt0r · WannaCry · WannaCrypt · Wcry

WannaCry is ransomware that contains a worm component enabled by the EternalBlue exploit.

WannaCryptor, also known as Wana Decrypt0r, WannaCry, WannaCrypt, Wcry, is a Windows ransomware operated by Lazarus Group.

Background

WannaCry is ransomware with a worm-like spreading capability driven by the EternalBlue exploit. It targets flaws in the Windows SMBv1 server to remotely take over machines, encrypt their files, and propagate to additional hosts. Machines that have applied the MS17-010 patch are immune to the exploits it leverages. The outbreak's propagation was halted roughly 8 hours after it began when a kill switch domain was triggered.


Source: Malpedia (Fraunhofer FKIE).