WannaCry Ransomware | The Complete Guide to the 2017 Cyberattack That Shook the World

Knowledge Hub
WannaCry Ransomware

WannaCry is a self-propagating ransomware worm that infected more than 200,000 computers across 150 countries within four days in May 2017, encrypting victims’ files and demanding Bitcoin payments for their release. It spread by exploiting EternalBlue, a Windows SMB protocol vulnerability originally developed by the US National Security Agency and leaked online weeks before the attack. The outbreak forced the UK’s National Health Service to cancel thousands of appointments, halted production at Renault and Nissan factories, and disrupted operations at FedEx and Telefónica, with global losses estimated at $4 billion. WannaCry remains one of the most cited case studies in cybersecurity training because it demonstrated, at scale, what happens when a known vulnerability goes unpatched. This guide covers how the attack worked, why it spread so fast, and the practical lessons organizations still apply today to prevent a repeat.

What Is WannaCry Ransomware?

WannaCry is a ransomware cryptoworm that encrypts files on a Windows computer and demands payment, typically $300 to $600 in Bitcoin, in exchange for a decryption key. Unlike ordinary ransomware, which needs a human to open an infected attachment or click a malicious link on every single machine, WannaCry could jump from one computer to the next on its own once it found a single unpatched entry point on a network. That self-spreading capability is why a single infected endpoint inside a hospital or a factory could take down thousands of connected machines in hours rather than days.

Definition and Origin of the Name

The name “WannaCry” comes directly from the file extension and ransom note the malware left behind, “.WNCRY”, which researchers shortened when the attack was first being analyzed and reported in real time. Security researchers also refer to it as WCry or Wanna Decryptor, names pulled from the same executable and note text found on infected machines. The malware itself was built around two components: a worm module that handled network propagation, and a ransomware payload responsible for encrypting files using RSA and AES encryption once a machine was compromised. There was no clever social-engineering hook behind the name; it was simply extracted from the attacker’s own code and ransom demand.

WannaCry as a Cryptoworm, Why It’s Different from Typical Ransomware

Most ransomware families rely on a delivery mechanism- phishing emails, malicious downloads, or compromised websites- to reach each victim. WannaCry skipped that step almost entirely by functioning as a cryptoworm: malware that combines file-encrypting ransomware with the self-replicating behavior of a computer worm. Once it infected one machine on a network, it scanned for other reachable devices running an unpatched version of the SMBv1 protocol. It copied itself across automatically, with no click, download, or user action required on the newly infected systems. This is the detail that separates WannaCry from nearly every ransomware strain before it, and it’s the reason a patch that had been available for two months before the attack could have stopped the outbreak entirely on any network that applied it. Microsoft’s own advisory (MS17-010) had shipped the fix in March 2017, a full two months before the May outbreak, underscoring that WannaCry’s damage was ultimately a patching failure as much as a technical exploit.

The 2017 WannaCry Outbreak, A Timeline

The WannaCry outbreak unfolded in a matter of hours on May 12, 2017, when the ransomware began exploiting an unpatched Windows vulnerability to spread across corporate and public-sector networks worldwide, ultimately reaching over 150 countries within four days. What made the timeline remarkable wasn’t just the speed of infection but how quickly it was contained once one researcher spotted a flaw the attackers had left in their own code.

How WannaCry Ransomware Works

Patient Zero and Initial Spread

The exact patient zero, the first machine infected, has never been conclusively identified. However, early spread was traced to networks in Asia and Europe within the opening hours of the attack. What is documented is the mechanism: WannaCry entered a network through a single unpatched Windows machine exposed to the internet or reachable on a local network, then used the EternalBlue exploit to scan for other devices running vulnerable versions of the SMBv1 file-sharing protocol and copy itself across automatically. Spain’s Telefónica and the UK’s National Health Service were among the earliest and most visibly affected organizations, with NHS trusts reporting locked-out systems and canceled procedures within hours of the initial infections on English soil. Because the worm needed no human interaction to spread once inside a network, a single vulnerable endpoint was enough to compromise an entire hospital trust or corporate estate before IT teams could react.

Who Was Behind the Attack

The United States, United Kingdom, and several allied governments have formally attributed WannaCry to the Lazarus Group, a hacking group linked to North Korea’s Reconnaissance General Bureau. The UK’s National Cyber Security Center and the US government issued public statements in December 2017 assigning responsibility to North Korean state actors, a rare instance of formal, coordinated government attribution for a global ransomware event. Researchers supported this conclusion by identifying code overlaps between WannaCry and earlier malware associated with the same group, including tools used in the 2014 Sony Pictures breach. North Korea has denied involvement.

The Kill Switch Discovery

The outbreak’s spread was halted not by a patch or law enforcement action, but by a 22-year-old security researcher, Marcus Hutchins, who noticed the malware queried an unregistered domain before executing its payload. Hutchins registered that domain for research purposes, unaware at the time that doing so would activate a hardcoded kill switch the attackers had built into WannaCry, likely intended as an anti-analysis or sandbox-evasion mechanism rather than a safety valve. The moment the domain went live, any infected machine that could reach it stopped encrypting new files, effectively halting further spread within hours of the discovery on May 13 May 13 2017. The fix was accidental and incomplete; later WannaCry variants without the same kill-switch domain continued to appear. Still, the discovery is widely credited with preventing what could have been a substantially larger second wave of damage.

How WannaCry Ransomware Works

WannaCry works by combining a network-based exploit that lets it spread without user interaction with a standard ransomware payload that encrypts files and demands payment. That combination, silent propagation plus file encryption, is what allowed a single infected machine to compromise entire corporate networks before anyone noticed a problem.

The Global Impact of WannaCry

The EternalBlue Exploit and SMB Vulnerability (CVE-2017-0144)

WannaCry’s entry point was EternalBlue, an exploit for a flaw in Microsoft’s Server Message Block version 1 (SMBv1) protocol, cataloged as CVE-2017-0144. The vulnerability allowed an attacker to send specially crafted packets to a vulnerable machine and execute arbitrary code remotely, with no login credentials or user action required. EternalBlue was originally developed by the US National Security Agency as an offensive cyber tool, then leaked to the public in April 2017 by a group calling itself the Shadow Brokers, roughly a month before WannaCry used it in the wild. Microsoft had already released a patch, MS17-010, in March 2017, meaning the vulnerability was fixable for two months before the outbreak. Still, the sheer number of unpatched machines, particularly older Windows 7 and Windows XP systems in hospitals, government agencies, and industrial environments, gave the exploit an enormous surface area to work with.

How WannaCry Spreads Across Networks

Once WannaCry compromised a single machine, it used the EternalBlue exploit to scan the local network and the wider internet for other devices with SMBv1 exposed, then automatically copied itself onto every vulnerable machine it found. This worm-like propagation meant infection didn’t require a second phishing email or a second careless click; the malware handled its own distribution, moving laterally through a network in minutes. Organizations with flat network architectures, where a device in one department could freely reach machines in another, saw the fastest and widest internal spread, since there was no segmentation to slow the worm down. This is also why the outbreak disproportionately hit large institutional networks like the NHS and multinational manufacturers rather than isolated home users, whose machines typically sat behind routers that blocked the SMB port from external scanning.

The Ransom Note and Payment Screen

Once WannaCry finished encrypting a machine’s files, it displayed a red-and-white ransom screen demanding a payment of $300 in Bitcoin, rising to $600 if the victim didn’t pay within three days, with a threat that files would be permanently deleted after seven days. The note included a countdown timer, step-by-step Bitcoin payment instructions, and, in a detail that stood out even at the time, a live chat support function so victims could message the attackers directly for help completing payment. Despite the polished presentation, cybersecurity researchers found no reliable evidence that payment guaranteed file recovery, since the payment infrastructure lacked a way to automatically match a specific ransom payment to a specific victim’s decryption key. Security agencies including the FBI and the UK’s NCSC advised against paying, both because recovery wasn’t guaranteed and because payment funded further attacks.

Encryption Behavior and File Targeting

WannaCry used a combination of AES-128 encryption for the victim’s files and RSA-2048 encryption to protect the AES keys, a standard but effective approach that made brute-force decryption computationally infeasible without the attacker’s private key. It specifically targeted around 176 file types, prioritizing documents, images, videos, archives, and source code, the file categories most likely to represent irreplaceable personal or business data rather than system files needed to keep the machine running. Encrypted files had their extensions changed to.WNCRY, and the original files were deleted after encryption, removing the option of simply recovering an unencrypted backup copy from the same disk. Because the encryption process worked silently in the background before the ransom note appeared, many victims had no warning that anything was wrong until every targeted file on the machine was already unrecoverable without the key.

The Global Impact of WannaCry

WannaCry’s global impact was measured not just in the number of machines it infected but in the real-world disruption it caused to hospitals, factories, and government services across more than 150 countries, with total damages estimated at up to $4 billion. It remains one of the clearest examples of how a single unpatched vulnerability can cascade into physical-world consequences far beyond IT departments.

Indicators of Compromise (IOCs) and Technical Analysis

Impact on the NHS and Global Hospitals

The UK’s National Health Service was the outbreak’s most visible casualty, with at least 80 of 236 NHS trusts in England affected either directly or indirectly, forcing staff back to pen-and-paper record-keeping and locking clinicians out of patient files, scanners, and other connected equipment. A UK National Audit Office report found that the attack led to the cancellation of roughly 19,000 medical appointments, including operations, and disrupted services in at least 34 hospital trusts directly. Ambulances were diverted from some affected emergency departments, and several hospitals had to turn away non-critical patients. At the same time, systems were restored, making WannaCry one of the first ransomware attacks to endanger patient care rather than just corporate data demonstrably. The NAO later attributed much of the damage to the NHS’s reliance on outdated, unpatched Windows systems; some trusts were still running Windows XP, a version Microsoft had stopped supporting three years earlier.

Country-by-Country Effects (UK, India, Singapore, and Beyond)

Beyond the UK, the outbreak’s severity varied significantly by country, largely based on how widely SMBv1 remained exposed on local networks. Russia reported the highest number of infections globally, affecting systems within its interior ministry and major telecom providers. At the same time, Spain’s Telefónica, FedEx in the United States, and Renault-Nissan’s European and Asian manufacturing plants all halted operations at some point during the outbreak. India recorded thousands of infections concentrated in West Bengal’s police department and several state-run institutions, reflecting the country’s large base of legacy Windows systems in government use. Singapore, by contrast, reported comparatively minimal disruption, an outcome cybersecurity analysts linked to the government’s earlier push for patch compliance and network segmentation across public agencies. This spread of outcomes, from crippled hospital trusts to near-unaffected national networks, underscored that the deciding factor wasn’t the sophistication of the attack but each organization’s patching discipline going in.

Statistics, Infections, Costs, and Confidentiality Breaches

WannaCry infected an estimated 200,000 to 300,000 computers across at least 150 countries within its first four days, spreading at a rate researchers described as unprecedented for ransomware at the time. Global financial losses from the attack have been estimated at up to $4 billion, a figure that accounts for ransom payments, IT recovery costs, and lost productivity across affected sectors including healthcare, logistics, telecommunications, and manufacturing. Despite the scale of infection, total ransom payments collected were comparatively small, roughly $130,000 across the three Bitcoin wallets linked to the attack, since most affected organizations focused on system restoration from backups rather than payment. No large-scale confirmed data exfiltration or confidentiality breach was tied to WannaCry itself; the malware’s core function was encryption and disruption rather than data theft, which distinguished it from later ransomware strains that combined encryption with the threat of leaking stolen data.

WannaCry as a Cybersecurity Case Study

WannaCry is taught in security training programs worldwide because it compresses nearly every core lesson in vulnerability management into a single, well-documented event: the danger of unpatched systems, the risk of flat network architecture, the real cost of running unsupported operating systems, and the value of network segmentation in limiting an outbreak’s blast radius. Its status as a nation-state-attributed attack that exploited a leaked government-developed tool also made it a frequently cited case in discussions of responsible vulnerability disclosure and the risks of intelligence agencies stockpiling zero-day exploits rather than reporting them to vendors. For organizations building security awareness programs or incident response playbooks, WannaCry remains one of the most concrete, well-verified examples available of what happens when patch management fails at scale.

Indicators of Compromise (IOCs) and Technical Analysis

Government and vendor threat intelligence teams well document indicators of compromise for WannaCry, and they fall into three categories: file hashes, network indicators, and behavioral signatures that security tools still use today to detect this ransomware family and its variants. These IOCs remain relevant years after the 2017 outbreak because WannaCry variants without the kill-switch domain continue to circulate.

How to Detect, Fix, and Stop WannaCry Ransomware

File Hashes and Signatures

The US Computer Emergency Readiness Team analyzed three files submitted for review, confirming all three as components of the WannaCry ransomware campaign, also known as WannaCrypt or .wnCry, and published them alongside YARA detection rules. One of the most widely referenced samples is the dropper component, a malicious PE32 executable identified by the MD5 hash 5bef35496fcbdbe841c82f4d1ab8b7c2, which contains and executes the ransomware payload after propagating through the network. This dropper functions by embedding and running the ransomware itself, spreading through the MS17-010/EternalBlue SMBv1.0 exploit. At the same time, the remaining files serve as ransomware components with encrypted plug-ins responsible for encrypting a victim’s files. Security teams typically cross-reference these hashes against endpoint detection platforms and VirusTotal, where the original WannaCry executable is flagged by dozens of security vendors, giving defenders a fast way to confirm whether a suspicious file matches known WannaCry samples rather than relying on behavioral analysis alone.

Ports and Network Indicators

WannaCry’s network footprint centers on SMB traffic over TCP port 445, the port used by the vulnerable SMBv1 protocol that EternalBlue exploits to spread between machines, making unrestricted inbound or lateral port 445 traffic one of the clearest network-level red flags. The single most cited network indicator is the malware’s callback to a specific hardcoded domain, iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com, which the dropper attempts to connect to upon execution before deciding whether to proceed with encryption; this is the same domain a researcher accidentally registered to trigger the malware’s kill switch. Security teams monitoring DNS logs or proxy traffic for outbound requests to this domain, or to its known sinkhole infrastructure, can identify infected machines even before encryption begins, since the callback happens as a very first step in execution. Organizations conducting retrospective threat hunts are advised to check historical DNS and firewall logs for both port 445 exposure to untrusted networks and any historical resolution attempts against the kill-switch domain.

Vendor Threat Reports (Symantec, Kaspersky Analysis)

Independent vendor analysis from firms including Symantec and Kaspersky corroborated government findings within days of the outbreak, confirming the malware’s use of the EternalBlue exploit and its attribution links to the Lazarus Group through code-similarity analysis against prior malware samples. These vendor reports were significant because they cross-validated the technical findings from CISA’s TA17-132A advisory using independently collected samples, strengthening confidence in the IOC set circulating publicly rather than relying on a single source. Vendor telemetry also tracked the emergence of WannaCry variants that patched out the kill-switch domain check entirely, a development that shifted defensive guidance away from relying on the kill switch and toward patching MS17-010 and disabling SMBv1 as the only durable fixes. For technical teams, the practical takeaway from these combined reports is that hash-based detection alone is insufficient given ongoing variants, and defenses should layer file hash blocklists with network monitoring for port 445 abuse and SMBv1 protocol disablement.

How to Detect, Fix, and Stop WannaCry Ransomware

Stopping WannaCry comes down to three actions: applying Microsoft’s MS17-010 patch, turning off the outdated SMBv1 protocol, and, for machines already encrypted, attempting recovery through free decryption tools before the window to use them closes. Because the underlying vulnerability was patched months before the 2017 outbreak, most of what “stopping” WannaCry looks like today is really about closing gaps that should have been closed already.

How to Detect, Fix and Stop WannaCry Ransomware

Official Patches and Microsoft’s Response

Microsoft’s primary fix, security bulletin MS17-010, had been available for supported Windows versions since March 2017, two months before the outbreak, and systems that installed this patch are not vulnerable to the exploits WannaCry uses. What made Microsoft’s response unusual was its decision to extend that protection to operating systems it no longer officially supported: after the attacks began, Microsoft released emergency updates for Windows XP, Windows Server 2003, and Windows 8 on the night of May 12 May 12, 2017, despite having ended mainstream support for those systems years earlier. This was a rare exception to standard vendor policy, and it reflected the scale of the emergency: millions of legacy machines in hospitals, government agencies, and industrial systems were running exactly the unsupported versions the emergency patch targeted. Organizations still running legacy Windows today should treat this patch, and disabling SMBv1 entirely, as a non-negotiable baseline rather than optional hardening.

NCSC Guidance and Best Practices

The UK’s National Cyber Security Center issued guidance during the outbreak built around three core actions: deploy the MS17-010 patch immediately, disable SMBv1 wherever the patch cannot be applied, and keep antivirus and gateway protections current to catch variants that bypass the original kill switch. For networks with legacy platforms that can’t be patched through standard channels, NCSC guidance specifically flagged that Windows XP, Server 2003, and Windows 8 require an out-of-band patch obtained directly from Microsoft rather than through Windows Update. Beyond patching, longer-term best practice guidance converged on network segmentation, limiting how far a worm can travel once it lands on one machine, and turning off SMBv1 organization-wide as a permanent policy rather than a one-time emergency response, since the protocol offers little modern functionality that newer SMB versions don’t already provide more securely.

Decryption Tools and Recovery Options

For machines already encrypted, two free tools, WannaKey and its successor WanaKiwi, offer a genuine chance at recovery, but only under narrow conditions. Security researcher Adrien Guinet released WannaKey to decrypt Windows XP systems, and shortly after, Benjamin Delpy released WanaKiwi, which extended decryption support to a wider range of Windows versions. Both tools work by recovering the prime numbers used to build the encryption keys directly from the computer’s memory, which means the affected system must not have been powered down or rebooted since infection, and the user needs administrator-level access to the machine for the tool to have any chance of success. This is a hard constraint, not a preference: once a machine reboots, the memory holding those prime numbers is typically overwritten, and the recovery window closes permanently. WanaKiwi has been tested and confirmed to work across Windows XP through Windows 7, giving it the broadest practical coverage among available free tools. However, researchers caution that no decryption tool works on every infected system, and security agencies consistently advise against paying the ransom itself since payment carries no guarantee of recovery.

How WannaCry Was Ultimately Stopped

The outbreak’s spread was halted not by a patch rollout but by an accidental kill-switch discovery, paired afterward with a rapid, coordinated patching effort across affected organizations. Security researcher Marcus Hutchins identified and registered the hardcoded domain WannaCry checked before executing its payload, which activated a kill switch built into the malware and caused any newly infected machine that could reach that domain to stop encrypting files. That single action bought organizations worldwide the time needed to patch remaining systems, disable SMBv1, and segment vulnerable networks before a second wave could take hold. However, it did not address machines already encrypted, and later variants without the same kill-switch domain continued to circulate. The episode left behind a durable lesson still cited across cybersecurity guidance: emergency patching, protocol hardening, and network segmentation remain the only reliable long-term defense, since kill switches, decryption tools, and researcher luck are not something any organization can plan around twice.

Is WannaCry Still a Threat Today?

Yes, WannaCry is still a threat, but not in the form that caused global chaos in 2017. Security researchers continue to detect WannaCry infections on unpatched legacy systems nearly a decade later, and the vulnerability it exploits still represents an active attack surface in organizations running unsupported Windows versions or delayed patch management. The original outbreak strain no longer poses the same risk since its kill switch remains registered. Still, the ecosystem of variants it spawned has kept the malware family in active circulation far longer than most ransomware threats survive.

Is WannaCry Still a Threat Today

WannaCry 2.0 and Variant Activity

Detections have not reached zero: the registered kill switch prevents the original variant from executing, but derivative strains with the kill switch removed remain in active circulation, particularly on networks that never patched MS17-010 or disabled SMBv1. This staying power is unusual for ransomware, which typically has a short operational lifespan before defenders adapt; ESET data showed WannaCry accounted for 40.5% of all ransomware detections globally in Q1 2020, three years after the original outbreak, and the strain ranked fourth among the most-detected malware families of 2021, the only legacy ransomware variant to appear on that year’s top-ten list. Separate device-tracking research has found WannaCry active on well over 100,000 devices worldwide at various points since 2019, a figure that reflects how many organizations, particularly in manufacturing and healthcare, never fully remediated the SMBv1 exposure that let the original worm spread. The pattern holds because the vulnerability, not the specific malware sample, is the persistent weakness: any device still running unpatched SMBv1 remains susceptible to WannaCry variants regardless of how old the original code is.

Lessons for Modern Ransomware Defense

WannaCry’s longest-lasting impact isn’t the malware itself but the defensive doctrine it forced the security industry to adopt: patch management, network segmentation, and behavioral detection over reliance on any single control. Security vendors now build detection around the behaviors ransomware exhibits inside a network, including reconnaissance, lateral movement via known exploits, and mass file encryption, rather than static signatures alone, precisely because WannaCry proved that a single well-known, already-patched vulnerability could still cause billions in damage if organizations depended on prevention alone. That lesson has only grown more relevant as ransomware has scaled industry-wide; Verizon’s 2025 Data Breach Investigations Report found that 44% of cybersecurity breaches in 2024 involved ransomware, underscoring that the operational failures WannaCry exposed- unpatched systems, flat networks, and unsupported legacy software- remain the same root causes driving ransomware incidents today. For any organization building a modern ransomware defense strategy, WannaCry’s persistence years after its patch became available is the clearest available proof that “we already fixed that” is rarely true across an entire estate, and that verifying patch compliance matters more than assuming it.

Frequently Asked Questions (FAQ’s)

What made WannaCry spread so fast?

WannaCry spread so fast because it combined ransomware with a self-propagating worm, meaning it didn’t need a single victim to click a link or open an attachment to infect the next machine. Once inside a network through one unpatched entry point, it used the leaked NSA exploit EternalBlue to scan for other devices running the vulnerable SMBv1 protocol and copy itself across automatically, with no human interaction required at any stage of the internal spread. That mechanism let it infect over 200,000 computers across more than 150 countries within four days, a scale and speed no prior ransomware strain had achieved, precisely because the malware handled its own distribution rather than depending on repeated social engineering.

Is WannaCry ransomware still active?

Yes, variants of WannaCry remain active, even though the original outbreak strain has been neutralized by its own registered kill switch. Security researchers continue to detect WannaCry infections on unpatched legacy systems, and the underlying MS17-010 vulnerability still represents an active attack surface in organizations running unsupported Windows versions or delayed patching. The strain ranked fourth among the most-detected malware families as recently as 2021, the only legacy ransomware variant to appear on that year’s top-ten list, showing that its persistence isn’t a historical footnote but an ongoing risk tied directly to how many networks still run exposed SMBv1 services.

How can organizations protect against WannaCry-style attacks?

The most effective protection against WannaCry-style attacks is patch discipline: applying MS17-010 and every subsequent Windows security update promptly, disabling SMBv1 entirely rather than merely restricting it, and segmenting networks so a single infected device can’t reach every other machine on the estate. Because WannaCry’s worm behavior depends on lateral movement across a flat network, organizations that separate critical systems into isolated segments limit how far any similar worm can travel even if one endpoint is compromised. Maintaining offline or immutable backups closes the remaining gap, since even a fully patched network can be reached through a phishing email or a new zero-day, and a tested backup is what turns a ransomware infection from a catastrophic loss into a recoverable incident. Behavioral monitoring for reconnaissance and mass file-encryption patterns, rather than relying solely on known malware signatures, rounds out a defense strategy built around the specific lessons WannaCry made unavoidable.

Free Dark Web Report

Keep reading

No results found.