Wanacry

Threat Actor updated 4 months ago (2024-05-04T20:17:53.402Z)
Download STIX
Preview STIX
WannaCry is a notable threat actor that gained infamy for its global ransomware attack in May 2017. The malware associated with this group encrypts files on the victim's computer, appending the string "WANACRY!" at the beginning of each file to mark its territory. The encrypted files become inaccessible until a ransom is paid, typically demanded in Bitcoin. Various messages are displayed to the victim during the process, including warnings such as "Ooops, your files have been encrypted!" and demands like "Pay now, if you want to decrypt ALL your files!". This malicious software also leaves behind distinct file references, such as "!WannaCryptor!.bmp", "!WannaDecryptor!.exe.lnk", and "!Please Read Me!.txt". The WannaCry ransomware not only encrypts files but also executes various commands to further disrupt the system. These include disabling system recovery options and deleting shadow copies of files, which are often used for backups or restorations. Commands such as "vssadmin.exe Delete Shadows /All /Quiet", "wmic shadowcopy delete", and "bcdedit /set {default} bootstatuspolicy ignoreallfailures" are executed to ensure the victim cannot easily recover their files without paying the ransom. The encryption format used by WannaCry is identifiable by the unique file header "WANACRY!". This acts as a signature of sorts, making it easier for cybersecurity experts to identify infections caused by this particular threat actor. Despite the havoc wreaked by WannaCry, understanding its modus operandi has helped in developing countermeasures and strategies to mitigate similar threats in the future. As a result, knowledge about WannaCry serves as an important case study in the field of cybersecurity.
Description last updated: 2024-05-04T20:07:06.575Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Wanacry Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
WannaCry Malware Profile | Mandiant
MITRE
2 years ago
A Technical Analysis of WannaCry Ransomware | LogRhythm