WannaCry Group
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The WannaCry Group is the alias used to describe the threat actor responsible for the WannaCry ransomware outbreak that began on May 12 2017. Public attributions have linked this actor to North Korea, based on analyses of the code, infrastructure, and the geopolitical context surrounding the incident. The actor is therefore understood to operate under the direction or sponsorship of the North Korean state, although the exact internal structure remains undisclosed in open sources.
The WannaCry Group’s activity has been observed targeting a broad range of sectors worldwide, including healthcare providers, government agencies, telecommunications firms, energy companies, transportation operators, and various private corporations. The geographic scope of the attacks spanned more than 150 countries, affecting institutions such as the United Kingdom’s National Health Service, Russian governmental bodies, Chinese universities and petrol stations, German rail networks, Indian police systems, Indonesian hospitals, and Spanish telecommunications operators. The primary objective demonstrated in these operations was financial gain, as the ransomware encrypted files and demanded payment in Bitcoin for decryption keys, rather than pursuing espionage or purely destructive aims.
In terms of tactics, the group relied heavily on the EternalBlue exploit, which targets a vulnerability in unpatched Microsoft Windows systems to gain initial access. Once inside a network, the actor deployed the WannaCry ransomware malware family, which propagates laterally using Server Message Block (SMB) protocols, encrypts user files, and displays ransom notes demanding cryptocurrency payment. The May 2017 WannaCry campaign serves as the most notable and representative operation, illustrating the actor’s capability to combine a leaked NSA‑derived exploit with ransomware to cause rapid, global disruption across critical infrastructure and commercial entities. This event remains a defining example of the group’s methodology and impact.
Incidents
Attributed incidents are available to members.
8 incidents