Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Archive categories

Security Incidents

EternalBlue and Its Use in WannaCry and NotPetya

The Windows SMB vulnerability that became the most consequential exploited vulnerability of the 2010s, and the two campaigns built on it.

Event date 14 March 2017 Status Confirmed Review UNCHECKED

The defect

SMBv1 contained a memory management flaw allowing remote code execution. It required three things to be true of a target: SMB exposed to the network, the patch not applied, and a listener on port 445. The third is why this was mainly an internet-facing problem and why segmentation was an effective mitigation.

WannaCry, May 2017

A ransomware worm using MS17-010 for propagation, with a kill switch consisting of registered domain checks. It caused reported disruption to healthcare, manufacturing, telecommunications, and logistics organisations, several of which halted operations on encrypted systems.

NotPetya, June 2017

A worm that combined MS17-010 propagation with credential theft and a destructive filesystem operation. Unlike WannaCry, it had no effective kill switch, and its effects were not limited to encryption: the master boot record was overwritten and the operating system was left unbootable in many cases.

The attribution question

Canada?셲 Communications Security Establishment published a statement noting that it was aware of the statements made by its allies and partners concerning the role of actors in North Korea in the development of WannaCry, and that this assessment was consistent with its own analysis. This is an official government statement, which is why it is recorded here as an attributed claim rather than as established fact, and it is not accompanied by published technical evidence. It says nothing about the origin of EternalBlue, which is attributed elsewhere and is not sourced in this entry.

Why this entry is grouped the way it is

WannaCry and NotPetya were global events with significant disruption, but they are not primarily privacy events: the harm was availability, integrity, and physical-world consequences rather than exposure of personal data. The archive keeps them because they are the reference cases for patch discipline, not because they belong in a breach count.

Sources

Claim labels

FACT

The vulnerability is tracked as CVE-2017-0143 (SMBv1 information disclosure) and CVE-2017-0144 (SMBv1 remote code execution).

FACT

Microsoft released security update MS17-010 on 14 March 2017, which required a restart.

FACT

Microsoft had shipped related fixes for EternalBlue in earlier monthly updates, and security researchers later reported that the defect was present in SMB since at least 2008, based on analysis of archived Windows source code.

FACT

NotPetya propagated using MS17-010 together with other techniques, including credential theft, and combined encryption of the master file table with overwriting of the master boot record.

FACT

The WannaCry propagation used MS17-010, and the malware also dropped a patch to prevent further exploitation of the vulnerability on infected machines, which limited re-infection but did not undo the encryption.

SOURCE CLAIM

The Canadian Centre for Cyber Security stated that it was aware of the statements made by its allies and partners concerning the role of actors in North Korea in the development of the malware known as WannaCry, and that this assessment was consistent with its own analysis. An earlier version of this entry cited a joint NSA, NCSC and CCCS statement also attributing EternalBlue to the Russian military intelligence service; no such statement could be located in a first-party record, so that attribution is not carried here.

Sources

Last link check: 2026-09-27. A link check confirms reachability, not that every claim has been independently reviewed.

  1. CVE-2017-0144 — SMB Remote Code Execution Vulnerability Microsoft Security Response Center company Accessed
  2. Security Update Guide, March 2017 Microsoft Security Response Center company Accessed
  3. CSE Statement on the Attribution of WannaCry Malware Communications Security Establishment Canada government Accessed