WannaCry ransomware campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 5, 2025
Last Seen
November 5, 2025

The WannaCry ransomware campaign was a globally disruptive malware outbreak in 2017 that spread rapidly through Windows systems by exploiting the EternalBlue SMB vulnerability, encrypting user data and demanding Bitcoin payments.

Overview

The WannaCry ransomware campaign was a globally disruptive malware outbreak in 2017 that spread rapidly through Windows systems by exploiting the EternalBlue SMB vulnerability, encrypting user data and demanding Bitcoin payments. It is widely attributed to North Korea's Lazarus Group, highlighting state-sponsored ransomware capabilities and the danger of worm-like propagation to critical infrastructure. The incident underscored the importance of timely patching, network segmentation, and rapid incident response in cybersecurity.

Related Threat Clusters

Recent Intelligence Reports

  • Australia and US impose sanctions on North Korean cyber ops — Itnews.Au · November 5, 2025

CVSS v3.1 Breakdown