Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a40dd6360b77725b

Jump to content

EternalBlue

From Wikipedia, the free encyclopedia

Eternal - Anonymous
Malware details
Technical name
  • Trojan:Win32/EternalBlue (Microsoft)[1]
  • Rocks Variant
  • Synergy Variant
    • Win32/Exploit.Equation.EternalSynergy (ESET)[4]
TypeExploit
AuthorEquation Group
Technical details
PlatformsWindows 95, Windows 98, Windows Me, Windows NT 3.x, Windows NT 4.0, Windows 2000, Windows XP, Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows NT 3.1–2000 Server Editions, Windows Server 2003, Windows Server 2003 R2, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016

EternalBlue[5] is a computer exploit software developed by the U.S. National Security Agency (NSA).[6] It is based on a zero-day vulnerability in Microsoft Windows software that allowed attackers to gain access to any number of computers connected to a network. The NSA was aware of this vulnerability but did not disclose it to Microsoft for several years, as it intended to use the exploit as part of its offensive cyber operations. In 2017, the NSA discovered that the software had been stolen by a group of hackers known as The Shadow Brokers. Microsoft was subsequently informed of this and released security updates in March 2017 patching the vulnerability. While this was happening, the hacker group attempted to auction off the software, but did not succeed in finding a buyer. EternalBlue was then released publicly on April 14, 2017.[5]

On May 12, 2017, a computer worm in the form of ransomware, nicknamed WannaCry, used the EternalBlue exploit to attack computers using Windows that had not received the latest system updates removing the vulnerability.[5][7][8][9][10][11] On June 27, 2017, the exploit was again used to help carry out the 2017 NotPetya cyberattack on more vulnerable computers.[12]

The exploit was also reported to have been used since March 2016 by the Chinese hacking group Buckeye (APT3), after they likely found and re-purposed the software,[11] as well as reported to have been used as part of the Retefe banking trojan since at least September 5, 2017.[13]

Details

[edit]

EternalBlue exploits a vulnerability in Microsoft's implementation of the Server Message Block (SMB) protocol. This vulnerability is denoted by entry CVE-2017-0144[14][15] in the Common Vulnerabilities and Exposures (CVE) catalog. The vulnerability exists because the SMB version 1 (SMBv1) server in various versions of Microsoft Windows mishandles specially crafted packets from remote attackers, allowing them to remotely execute code on the target computer.[16]

The NSA did not alert Microsoft about the vulnerability, holding onto it for more than five years before the breach forced its hand. The agency then warned Microsoft after learning about EternalBlue's possible theft, allowing the company to prepare a software patch issued in March 2017,[6] after delaying its regular release of security patches in February 2017.[17] On Tuesday, March 14, 2017, Microsoft issued security bulletin MS17-010,[18] which detailed the flaw and announced that patches had been released for all Windows versions supported at that time, including Windows Vista, Windows 7, Windows 8.1, Windows 10, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016.[19][20]

The Shadow Brokers publicly released the EternalBlue exploit code on April 14, 2017, along with several other NSA hacking tools.[5]

Many Windows users had not installed the Microsoft patches when, on May 12, 2017, the WannaCry ransomware attack started using the EternalBlue vulnerability to spread.[21][22] The next day (May 13, 2017), Microsoft released emergency security patches for unsupported versions, including Windows XP, Windows 8, and Windows Server 2003.[23][24]

In February 2018, EternalBlue was ported to all Windows operating systems released since Windows 2000 by RiskSense security researcher Sean Dillon. EternalChampion and EternalRomance, two other exploits originally developed by the NSA and leaked by The Shadow Brokers, were also ported during the same event and made available as open-source Metasploit modules.[25]

By late 2018, millions of systems remained vulnerable to EternalBlue, leading to millions of dollars in damages primarily caused by ransomware worms. Following the massive impact of WannaCry, which caused over $8 billion in damages across 150 countries, later outbreaks such as NotPetya and BadRabbit also propagated using EternalBlue as either an initial compromise vector or a method of lateral movement.[26]

City of Baltimore cyberattack

[edit]

In May 2019, the city of Baltimore struggled with a cyberattack by digital extortionists; the attack froze thousands of computers, shut down email, and disrupted real estate sales, water bills, health alerts, and many other services. Nicole Perlroth, writing for The New York Times, initially attributed this attack to EternalBlue;[27] however, in a February 2021 book on the cyber arms market, Perlroth clarified that EternalBlue was not responsible for the Baltimore cyberattack, while criticizing others for pointing out "the technical detail that in this particular case, the ransomware attack had not spread with EternalBlue".[28]

As a result of the cyberattack, four Baltimore City chief information officers were fired or resigned; two left while under investigation.[29] Some security researchers argued that responsibility for the breach lay with the city for failing to update its computers. Security consultant Rob Graham noted: "If an organization has substantial numbers of Windows machines that have gone 2 years without patches, then that’s squarely the fault of the organization, not EternalBlue."[30]

Russian computers hacked

[edit]

First appearing in February 2017, an updated version of EternalBlue emerged in May 2017, according to a Kaspersky forum report. It affected internal systems at the Ministry of Internal Affairs of Russia and computers across several regions, including Tatarstan. The WannaCry ransomware (also known as WCry or WannaCryptor) encrypted user files, appended the '.WNCRY' extension, and demanded payment in bitcoins for a decryption tool under threat of permanent file deletion. Worldwide, over 36,000 computers were infected, with the majority located in Russia, Ukraine, and Taiwan, according to cybersecurity firm Avast.[31][32]

Responsibility

[edit]

Following the WannaCry attack, Microsoft took primary responsibility for addressing the vulnerability, but criticized U.S. intelligence agencies like the NSA and CIA for stockpiling vulnerabilities rather than disclosing them. Microsoft stated that "an equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen".[33] This stockpiling strategy prevented Microsoft from identifying and patching the exploit earlier.[33][34] However, commentators including Alex Abdo of Columbia University's Knight First Amendment Institute criticized Microsoft for shifting blame to the NSA, arguing the company should remain accountable for releasing a vulnerable product.[35] The company was also faulted for initially limiting the patch to actively supported Windows versions and paying Extended Support customers, leaving entities like the UK's NHS vulnerable. A month later, Microsoft took the unusual step of releasing free patches for legacy systems back to Windows XP.[36]

EternalRocks

[edit]

EternalRocks (also known as MicroBotMassiveNet) is a computer worm that infects Microsoft Windows systems using seven NSA-developed exploits.[37] In comparison, WannaCry utilized only two, leading researchers to consider EternalRocks potentially more dangerous.[38] The worm was first identified using a honeypot.[39]

Infection

[edit]

EternalRocks initially installs Tor to communicate with command-and-control servers covertly. After a 24-hour incubation period,[37] it downloads executable payloads and replicates across host machines.

To avoid early detection, the malware claims to be WannaCry in its file properties. However, unlike WannaCry, EternalRocks does not contain a kill switch or deliver a ransomware payload.[37]

See also

[edit]

References

[edit]
  1. ↑ "Trojan:Win32/EternalBlue threat description - Microsoft Security Intelligence". www.microsoft.com.
  2. ↑ "TrojanDownloader:Win32/Eterock.A threat description - Microsoft Security Intelligence". www.microsoft.com.
  3. ↑ "TROJ_ETEROCK.A - Threat Encyclopedia - Trend Micro USA". www.trendmicro.com.
  4. ↑ "Win32/Exploit.Equation.EternalSynergy.A | ESET Virusradar". www.virusradar.com.
  5. 1 2 3 4 Goodin, Dan (April 14, 2017). "NSA-leaking Shadow Brokers just dumped its most damaging release yet". Ars Technica. p. 1. Retrieved May 13, 2017.
  6. 1 2 Nakashima, Ellen; Timberg, Craig (May 16, 2017). "NSA officials worried about the day its potent hacking tool would get loose. Then it did". Washington Post. ISSN 0190-8286. Archived from the original on September 26, 2017. Retrieved September 25, 2017.
  7. ↑ Fox-Brewster, Thomas (May 12, 2017). "An NSA Cyber Weapon Might Be Behind A Massive Global Ransomware Outbreak". Forbes. p. 1. Retrieved May 13, 2017.
  8. ↑ Goodin, Dan (May 12, 2017). "An NSA-derived ransomware worm is shutting down computers worldwide". Ars Technica. p. 1. Retrieved May 13, 2017.
  9. ↑ Ghosh, Agamoni (April 9, 2017). "'President Trump what the f**k are you doing' say Shadow Brokers and dump more NSA hacking tools". International Business Times UK. Retrieved April 10, 2017.
  10. ↑ "'NSA malware' released by Shadow Brokers hacker group". BBC News. April 10, 2017. Retrieved April 10, 2017.
  11. 1 2 Greenberg, Andy (May 7, 2019). "The Strange Journey of an NSA Zero-Day—Into Multiple Enemies' Hands". Wired. Archived from the original on May 12, 2019. Retrieved August 19, 2019.
  12. ↑ Perlroth, Nicole; Scott, Mark; Frenkel, Sheera (June 27, 2017). "Cyberattack Hits Ukraine Then Spreads Internationally". The New York Times. p. 1. Retrieved June 27, 2017.
  13. ↑ "EternalBlue Exploit Used in Retefe Banking Trojan Campaign". Threatpost. Retrieved September 26, 2017.
  14. ↑ "CVE-2017-0144". CVE - Common Vulnerabilities and Exposures. The MITRE Corporation. September 9, 2016. p. 1. Retrieved June 28, 2017.
  15. ↑ "Microsoft Windows SMB Server CVE-2017-0144 Remote Code Execution Vulnerability". SecurityFocus. Symantec. March 14, 2017. p. 1. Retrieved June 28, 2017.
  16. ↑ "Vulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN". ESET North America. Archived from the original on May 16, 2017. Retrieved May 16, 2017.
  17. ↑ Warren, Tom (April 15, 2017). "Microsoft has already patched the NSA's leaked Windows hacks". The Verge. Vox Media. p. 1. Retrieved April 25, 2019.
  18. ↑ "Microsoft Security Bulletin MS17-010 – Critical". technet.microsoft.com. Retrieved May 13, 2017.
  19. ↑ Cimpanu, Catalin (May 13, 2017). "Microsoft Releases Patch for Older Windows Versions to Protect Against Wana Decrypt0r". Bleeping Computer. Retrieved May 13, 2017.
  20. ↑ "Windows Vista Lifecycle Policy". Microsoft. Retrieved May 13, 2017.
  21. ↑ Newman, Lily Hay (March 12, 2017). "The Ransomware Meltdown Experts Warned About Is Here". wired.com. p. 1. Retrieved May 13, 2017.
  22. ↑ Goodin, Dan (May 15, 2017). "Wanna Decryptor: The NSA-derived ransomware worm shutting down computers worldwide". Ars Technica UK. p. 1. Archived from the original on May 17, 2017. Retrieved May 15, 2017.
  23. ↑ Surur (May 13, 2017). "Microsoft release Wannacrypt patch for unsupported Windows XP, Windows 8 and Windows Server 2003". Retrieved May 13, 2017.
  24. ↑ MSRC Team. "Customer Guidance for WannaCrypt attacks". microsoft.com. Retrieved May 13, 2017.
  25. ↑ "NSA Exploits Ported to Work on All Windows Versions Released Since Windows 2000". www.bleepingcomputer.com. Retrieved February 5, 2018.
  26. ↑ "One Year After WannaCry, EternalBlue Exploit Is Bigger Than Ever". www.bleepingcomputer.com. Retrieved February 20, 2019.
  27. ↑ Perlroth, Nicole; Shane, Scott (May 25, 2019). "In Baltimore and Beyond, a Stolen N.S.A. Tool Wreaks Havoc". The New York Times.
  28. ↑ Perlroth, Nicole (February 9, 2021). This Is How They Tell Me the World Ends: The Cyberweapons Arms Race. Bloomsbury.
  29. ↑ Gallagher, Sean (May 28, 2019). "Eternally Blue: Baltimore City leaders blame NSA for ransomware attack". Ars Technica.
  30. ↑ Rector, Ian Duncan, Kevin (May 26, 2019). "Baltimore political leaders seek briefings after report that NSA tool was used in ransomware attack". baltimoresun.com.{{cite web}}: CS1 maint: multiple names: authors list (link)
  31. ↑ Biddle, Sam (May 12, 2017). "Leaked NSA Malware Is Helping Hijack Computers Around the World: A large-scale digital infestation used leaked NSA malware to spread itself across the internet today". The Intercept. Archived from the original on October 20, 2024. Retrieved June 25, 2025.
  32. ↑ "Вирус-вымогатель атаковал компьютеры по всему миру. Онлайн" [The ransomware virus attacked computers all over the world. Online]. "Варламов.ру" (in Russian). May 12, 2017. Archived from the original on May 13, 2017. Retrieved June 25, 2025.{{cite news}}: CS1 maint: bot: original URL status unknown (link)
  33. 1 2 "The need for urgent collective action to keep people safe online: Lessons from last week's cyberattack - Microsoft on the Issues". Microsoft on the Issues. May 14, 2017. Retrieved June 28, 2017.
  34. ↑ Titcomb, James (May 15, 2017). "Microsoft slams US government over global cyber attack". The Telegraph. p. 1. Retrieved June 28, 2017.
  35. ↑ Bass, Dina (May 16, 2017). "Microsoft faulted over ransomware while shifting blame to NSA". Bloomberg News. Retrieved March 11, 2022.
  36. ↑ Waters, Richard; Kuchler, Hannah (May 17, 2017). "Microsoft held back free patch that could have slowed WannaCry". Financial Times. Retrieved March 11, 2022.
  37. 1 2 3 Cimpanu, Catalin (May 19, 2017). "New SMB Worm Uses Seven NSA Hacking Tools. WannaCry Used Just Two". Bleeping Computer.
  38. ↑ "Newly identified ransomware 'EternalRocks' is more dangerous than 'WannaCry' - Tech2". Tech2. May 22, 2017. Archived from the original on June 4, 2017. Retrieved May 25, 2017.
  39. ↑ "Miroslav Stampar on Twitter". Twitter. Retrieved May 30, 2017.

Further reading

[edit]
[edit]