Skip to content
WannaCry Ransomware: Infection, Impact, and Prevention

WannaCry Ransomware: Infection, Impact, and Prevention

Cyberint July 19, 2026

WannaCry, also known as WannaCrypt, is a notorious ransomware strain that gained global attention in May 2017 due to its widespread and damaging impact. It belongs to the category of malware known as ransomware, which encrypts a victim’s files and demands a ransom payment, usually in cryptocurrency, in exchange for a decryption key that can unlock the files.

The WannaCry outbreak had significant consequences, leading to the disruption of critical services, data loss, and financial losses for individuals and organizations. The attack highlighted the importance of keeping software up to date and patching known vulnerabilities to prevent such large-scale incidents. Microsoft released emergency patches to address the vulnerability that WannaCry exploited, even for unsupported versions of Windows.

The WannaCry ransomware attack was a global epidemic that took place in May 2017. This ransomware attack spread through computers operating Microsoft Windows. User’s files were held hostage, and a Bitcoin ransom was demanded for their return. Were it not for the continued use of outdated computer systems and poor education around the need to update software, the damage caused by this attack could have been avoided.

Unlike many other ransomware variants, WannaCry spreads on its own rather than being carried by malicious emails or installed via malware droppers. WannaCry’s worm functionality comes from its use of the EternalBlue exploit, which takes advantage of a vulnerability in Windows’ Server Message Block (SMB) protocol. The vulnerability was first discovered by the National Security Agency (NSA) and publicly leaked by the Shadow Brokers.

After EternalBlue was leaked, Microsoft released an updated version of SMB that corrected the issue in April 2017. While this was a month before the main WannaCry outbreak, many organizations had not yet installed the patch, making them vulnerable to WannaCry.

According to broader estimates, WannaCry managed to infect more than 200,000 computers worldwide during the brief period of its active attack. The containment of the malicious campaign was achieved mainly through the rectification of the EternalBlue exploit and the identification of the “kill switch,” which enabled the cessation of the malware’s execution. Despite these efforts, the final toll of the attack resulted in financial losses reaching billions of dollars, impacting victims across more than 150 countries.

Such a vast-scale offensive prompted a high-level international investigation in an attempt to unmask the orchestrators of the outbreak. In the course of analyzing WannaCry, experts scrutinized the ransom notes, revealing indicators that they were possibly handwritten. Linguistic analysis hinted at the proficiency of the authors in both Chinese and English. A deeper inquiry implied that the writer’s native tongue was Chinese, evidenced by the presence of two ransom note versions in Chinese – one in Simplified and the other in Traditional Chinese. Furthermore, the identification of certain typographical errors in the notes led researchers to conclude that a Chinese input system was employed for composition, as such mistakes would have been unlikely with alternative input methods.

Check Point Exposure Management is an intelligence-led, validation-driven, remediation-first unified platform that helps security teams move quickly and safely from exposure visibility to exposure reduction. Delivered through a single UI, it brings together threat intelligence, exposure prioritization, Agentic Exposure Validation, and safe remediation so teams can understand risk, prove exploitability, and act from one place.

Extracted Entities

Attack Types (1)

Platforms (1)

Ransomware Groups (1)

Vulnerabilities (1)