What is Wanncry?
Wannacry ransomware first gained notoriety in 2017 after a global attack that was seen in over 150 countries and in excess of 300,000 devices. Some notable victims include the National Health Service (NHS) in the UK, Renault and FedEx. The feature that made this ransomware variant so successful was its worm-like properties, enabling it to spread across a computer network using the SMBv1 exploit EternalBlue. Wannacry encrypts user files and demands ransom be paid in bitcoin. The amounts were relatively small, usually between $300-$500 dollars, indicating the initial idea was less targeted and to get as many victims to pay as quickly as possible.
Although no threat actor took responsibility for the attacks, researchers found key identifiers in the code pointing towards the Lazurus group, an infamous North Korean cybercriminal organisation, and Korean timestamps in the ransomware metadata.