---
title: Wormable ransomware strain uses freshly leaked exploit to encrypt data
description: A new family of ransomware called WannaCryptor has started targeting businesses in more than 70 countries around the world.
image: https://businessinsights.bitdefender.com/hubfs/Blog_pics/photo_47673_20151019.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Ransomware](https://businessinsights.bitdefender.com/topic/ransomware) [#Threat Research](https://businessinsights.bitdefender.com/topic/threat-research)

 By [**Bogdan Botezatu**](https://businessinsights.bitdefender.com/author/bogdan-botezatu) / May 12, 2017

# Wormable ransomware strain uses freshly leaked exploit to encrypt data

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/wormable-ransomware-strain-uses-freshly-leaked-exploit-to-encrypt-data&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/wormable-ransomware-strain-uses-freshly-leaked-exploit-to-encrypt-data&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/wormable-ransomware-strain-uses-freshly-leaked-exploit-to-encrypt-data&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/wormable-ransomware-strain-uses-freshly-leaked-exploit-to-encrypt-data&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/wormable-ransomware-strain-uses-freshly-leaked-exploit-to-encrypt-data&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/wormable-ransomware-strain-uses-freshly-leaked-exploit-to-encrypt-data&utm_medium=social&utm_source=facebook)

**Update 5/13/3017**: *Yesterday evening the WannaCryptor (WannaCry) ransomware family infected thousands of computers across the world. In just 24 hours, the number of infections has spiked to 185,000 machines in more than 100 countries. Analysis of the Bitcoin wallets hardcoded into the samples show that the group behind WannaCryptor managed to extort roughly $US 25,000 worth of Bitcoin.*

 

A new family of ransomware called WannaCryptor has started targeting businesses in more than 70 countries around the world. Hospitals, telelcom companies or gas and utilities plants are just some of the verticals that suffered massive disruptions caused by data being held at ransom.

Conventional ransomware [is still one of the most visible threats for both consumers and businesses](https://businessinsights.bitdefender.com/ransomware-attacks-increase-300-in-2016?hsLang=en-us) across the world. While most of it spreads via malicious e-mail attachments, browser and third-party exploits in web-facing applications, today’s attack automates the exploitation of a vulnerability called MS17-010 that is present in most versions of Windows. This flaw allows a remote attacker to run code on the vulnerable computer and use that code **to plant ransomware without anybody having to click malicious links or recklessly open e-mail attachments. ** This wormable behavior makes it the perfect tool to hold at ransom data stored on computers that are not operated by a human, such as servers running a vulnerable version of the Server Message Block (SMB protocol).

In case “SMB exploit” or “MS17-010” does not ring a bell, maybe you remember it as the “EternalBlue” flaw, a zero-day exploit leaked earlier in April along with a bigger dump of data allegedly exfiltrated from the NSA. This hybrid threat combines a ransomware payload with a wormable behavior that can be remotely exploited, making it the world’s most dangerous piece of ransomware written to date.

This vulnerability has become public along with the release of a series of other hacking techniques allegedly used by the US government agencies to spy on citizens. It has subsequently been weaponized and added in the commercial malware circuit, thus causing widespread havoc and forcing businesses to shut down in order to protect their assets.

**Patch this immediately and install additional safeguards**

In mid-March, [Microsoft released a patch for MS17-010](https://technet.microsoft.com/en-us/library/security/ms17-010.aspx) that blocks this exploitation avenue, but an unknown numer of computers and servers around the world - including those running unsupported versions of Windows - have not got it, and risk getting held for ransom anytime. In order to minimize the risk, you are advised to deploy the MS17-010 hotfix and update your local anti-malware solution immediately.

In addition to patching, make sure that your security solution can block both the delivery mechanism (the MS17-010 exploitation technique) and the variants of the WannaCryptor ransomware known to date. Businesses running our innovtive Hypervisor Introspection technology on virtualized servers [are not affected by this exploitation mechanism as demonstrated earlier in April](https://businessinsights.bitdefender.com/hypervisor-introspection-defeated-enternalblue-a-priori?hsLang=en-us).

---

To protect your business against WannaCry and other similar ransomware waves, all of Bitdefender’s **endpoint security solutions** are able to prevent the infection of our customers, thanks to their effective machine-learning based detection.

**[START A FREE TRIAL](https://www.bitdefender.com/business/advanced-security.html)** 

 

To further enhance protection against similar attack waves, you can completely seal your infrastructure against **zero-days or unpatched vulnerabilities**, by employing Hypervisor Introspection to protect your virtual workloads.

**[REQUEST A DEMO](https://www.bitdefender.com/business/hypervisor-introspection.html)** 

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/bitdefender-advisory-rce-vulnerability-microsoft-sharepoint-server-cve-2025-53770ce?hsLang=en-us>

### [Technical Advisory: Critical Remote Code Execution Vulnerability in Microsoft SharePoint Server (CVE-2025-53770)](https://businessinsights.bitdefender.com/bitdefender-advisory-rce-vulnerability-microsoft-sharepoint-server-cve-2025-53770ce?hsLang=en-us)

<https://businessinsights.bitdefender.com/most-public-sector-organizations-fear-supply-chain-attacks-survey-finds?hsLang=en-us>

### [Most Public Sector Organizations Fear Supply Chain Attacks, Survey Finds](https://businessinsights.bitdefender.com/most-public-sector-organizations-fear-supply-chain-attacks-survey-finds?hsLang=en-us)

<https://businessinsights.bitdefender.com/advisory-react2shell-critical-unauthenticated-rce-in-react-cve-2025-55182?hsLang=en-us>

### [Technical Advisory: React2Shell Critical Unauthenticated RCE in React (CVE-2025-55182)](https://businessinsights.bitdefender.com/advisory-react2shell-critical-unauthenticated-rce-in-react-cve-2025-55182?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Bogdan Botezatu",
    "url" : "https://businessinsights.bitdefender.com/author/bogdan-botezatu"
  },
  "datePublished" : "2017-05-12T23:02:49.000Z",
  "headline" : "Wormable ransomware strain uses freshly leaked exploit to encrypt data",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/Blog_pics/photo_47673_20151019.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/wormable-ransomware-strain-uses-freshly-leaked-exploit-to-encrypt-data",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```