Ransomware Group intelligence
Wannacry
InactiveTrack Wannacry with 33 published victims and 1 known leak locations in a single intelligence view.
Overview
Wannacry is tracked by Breach House as a ransomware group with 33 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Web location | Down checked 1h ago | none. |
Top Activity Sectors (10)
Typical Attacks (16)
▼How Wannacry typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via WannaCry.
-
T1047 Windows Management Instrumentation Execution
What they do: WannaCry utilizes wmic to delete shadow copies.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: WannaCry creates the service "mssecsvc2.0" with the display name "Microsoft Security Center (2.0) Service."
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1564.001 Hidden Files and Directories Stealth
What they do: WannaCry uses attrib +h to make some of its files hidden.
What that means: Adversaries may set files and directories to be hidden to evade detection mechanisms.
-
T1222.001 Windows Permissions Defense Impairment
What they do: WannaCry uses attrib +h and icacls . /grant Everyone:F /T /C /Q to make some of its files hidden and grant all users full access controls.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1016 System Network Configuration Discovery Discovery
What they do: WannaCry will attempt to determine the local network segment it is a part of.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: WannaCry scans its local network segment for remote systems to try to exploit and copy itself to.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1083 File and Directory Discovery Discovery
What they do: WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1120 Peripheral Device Discovery Discovery
What they do: WannaCry contains a thread that will attempt to scan for new attached drives every few seconds.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1210 Exploitation of Remote Services Lateral Movement
What they do: WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network.
What that means: Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
-
T1563.002 RDP Hijacking Lateral Movement
What they do: WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session.
What that means: Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment.
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: WannaCry uses Tor for command and control traffic.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1486 Data Encrypted for Impact Impact
What they do: WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: WannaCry attempts to kill processes associated with Exchange, Microsoft SQL Server, and MySQL to make it possible to encrypt their data stores.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: WannaCry uses vssadmin, wbadmin, bcdedit, and wmic to delete and disable operating system recovery features.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Crypto Wallets (5)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw |
bitcoin | $42,671 | 234 |
13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 |
bitcoin | $38,664 | 141 |
115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn |
bitcoin | $30,766 | 122 |
15zGqZCTcys6eCjDkE3DypCjXi6QWRV6V1 |
bitcoin | $4,526 | 15 |
1QAc9S5EmycqjzzWDc1yiWzr9jJLC8sLiY |
bitcoin | $3,898 | 12 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Victims (33)
Search, filter and paginate the victim timeline for Wannacry. Showing 1–33 of 33.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | State of Connecticut (12 State Agencies, including the Department of Administrative Services) id242 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Becker County id233 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Murfreesboro PD and FD id232 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Honda Motor Co. id231 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Telkom id229 View details | South Africa | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Rensselaer County Library id228 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | National Health Service (NHS) UK id201 View details | United Kingdom | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Telefonica id202 View details | Spain | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Renault id203 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | FedEx id204 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Nissan id205 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Russia Central Bank id206 View details | Russian Federation | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Russian Railways id207 View details | Russian Federation | Transportation / Travel / Logistics | — | |
|
No additional victim description available. |
|||||
| Ransomware | Russian Interior Ministry id208 View details | Russian Federation | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Iberdrola id209 View details | Spain | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Indian police in the state of Andhra Pradesh id210 View details | India | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | MegaFon id211 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sberbank id212 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Thailand Digital Billboard id213 View details | Thailand | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | Singapore shopping mall id214 View details | Singapore | Retail / E-commerce | — | |
|
No additional victim description available. |
|||||
| Ransomware | Chinese Police id215 View details | China | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Bank Of China id216 View details | China | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | China gas stations id217 View details | China | Energy | — | |
|
No additional victim description available. |
|||||
| Ransomware | Chinese traffic police, immigration and public security bureaus id218 View details | China | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sandvik id219 View details | Sweden | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Petrobras id220 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brazil's Foreign Ministry id221 View details | Brazil | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brazil's social security system id222 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Portugal Telecom id223 View details | Portugal | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Deutsche Bahn (Germany Rail Network) id224 View details | Germany | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | MediaOnline id225 View details | Singapore | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Hitachi id226 View details | Japan | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Cook County id227 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||