Darket Diaries
Darket Diaries

73: WannaCry

It is recommend to listen to episodes 53 “Shadow Brokers”, 71 “FDFF”, and 72 “Bangladesh Bank Heist” before listening to this one. In May 2017 the world fell victim to a major ransomware attack known as WannaCry. One of the victims was UK’s national health service. Security researchers scrambled to

Featured Speakers

Jack Rhysider HostMatt Sweesh Guest

Topics Discussed

Episode Summary

Executive Summary: The episode recounts the 2017 WannaCry ransomware outbreak, centered on emergency physician Tony Bleetman’s experience inside a disrupted NHS hospital. It explains how the attack spread via the leaked EternalBlue exploit, how weak patching and legacy systems amplified damage, and how researchers—including Marcus Hutchins and Matt Sweesh—helped slow the worm by discovering and registering kill-switch domains. The episode closes by linking WannaCry to North Korea’s Lazarus Group and broader concerns about destructive state-backed cyber operations.

Main Topics: NHS operational impact during WannaCry (Priority: 5/5): Tony Bleetman describes how the hospital reverted to paper processes, manual lab retrievals, whiteboards, and portable imaging because networked systems were unavailable. EternalBlue and the Shadow Brokers leak (Priority: 5/5): The ransomware’s explosive spread is tied to the recently leaked EternalBlue exploit, originally an NSA tool released by the Shadow Brokers and later patched by Microsoft. Security research response and reverse engineering (Priority: 4/5): FireEye, Matt Sweesh, and other researchers raced to analyze the malware, understand its behavior, and identify clues about origin, motive, and propagation. The kill-switch discovery (Priority: 5/5): Marcus Hutchins found a hardcoded domain check that acted as a kill switch; registering the domain dramatically slowed the outbreak, and later variants were also suppressed by researchers. Attribution to North Korea and Lazarus Group (Priority: 5/5): The episode presents the DOJ attribution to North Korea, discusses Park Jin-hyuk’s indictment, and outlines evidence linking the campaign to Lazarus/Bureau 121. Broader lessons on patching and legacy systems (Priority: 4/5): The episode emphasizes that unpatched and hard-to-update systems—especially in healthcare—remain highly vulnerable and require resilient fallback procedures. Cybercrime, espionage, and destructive capability (Priority: 4/5): North Korean operations are framed as a mix of criminal revenue generation, espionage, and politically motivated disruption, with ransomware as an especially effective tool.

Key Arguments: WannaCry succeeded because it combined a powerful freshly leaked exploit with worm-like self-propagation, allowing rapid spread across networks. Healthcare systems were particularly exposed because many devices and workflows could not be quickly patched or taken offline. The NHS’s response showed the importance of low-tech fallback procedures: paper registration, manual lab runs, and standalone machines kept care running. The malware’s payment mechanism appeared unreliable, leading researchers to suspect the campaign may have been partly destructive rather than purely financial. Marcus Hutchins’ registration of the original kill-switch domain effectively halted the first wave of infections. Later WannaCry variants were also slowed or stopped when researchers identified and registered new kill-switch domains. The attack was likely enabled by a chain of events: NSA development, Shadow Brokers release, Microsoft patching, public proof-of-concept code, and rapid weaponization by attackers. US authorities attribute WannaCry to North Korea, specifically to actors tied to Lazarus Group and Park Jin-hyuk. North Korea appears to use hacking as a blended strategy of statecraft: theft, disruption, and intelligence collection. The episode argues that future North Korean cyberattacks may become even more destructive and could eventually cause physical harm.

Data Points: Date of outbreak: May 12, 2017 - The day Dr. Tony Bleetman arrived at work and saw the NHS hospital computers displaying the WannaCry ransom screen. Ransom demand: $300 worth of Bitcoin - The typical ransom message displayed on infected hospital computers. NHS appointments canceled: 6,912 - Appointments canceled because of the attack. Countries affected: 150 - Estimated global spread of WannaCry. Infected computers: 230,000 - Estimated number of computers infected by WannaCry. Ransom payments made: 330 - Only 330 victims reportedly paid the ransom. Revenue generated: $140,000 worth of Bitcoin - Estimated total amount received by the attackers. Hospitals/trusts affected in UK: 45 - UK government estimate shared during the crisis. Windows support exception: Windows XP patch released - Microsoft issued a rare emergency patch for the unsupported OS after WannaCry spread. Kill-switch URL length: 40 characters - Marcus Hutchins found a 40-character gibberish domain used as a kill switch. Timeline from proof-of-concept to outbreak: 3 days - RiskSense published EternalBlue proof-of-concept on May 9, 2017; WannaCry using it appeared three days later. Legacy support status: 2 months earlier - Windows had been patched about two months before the outbreak, making lack of updates a major factor. North Korean defector estimate: 1,800 personnel - Approximate size of Bureau 121 as described by a defector. Email addresses identified: 30 - DOJ investigation found about 30 email addresses tied to the alleged operator. Sanctions timing: July 2020 - EU imposed sanctions on North Korea partly over WannaCry and other cyberattacks.

Pivotal Quotes: "When the technology lets us down in any circumstance, we have to fall back on old-fashioned, well-worn, well-proven, basic medical techniques." — Tony Bleetman: Explaining how the NHS kept operating while its networked systems were crippled. "We had reason to believe it was going to hit even more of our customers." — John Holquist: Describing FireEye’s decision to mobilize a coordinated response to the outbreak. "I thought it was kind of flattering, but I'm French, you know." — Matt Sweesh: Reacting to the Shadow Brokers jokingly referring to him in their tweets.

Implications: The episode shows that unpatched legacy systems can turn a single exploit into a global crisis. It also highlights how small research actions can meaningfully blunt malware outbreaks, while state-backed cybercrime remains a growing threat.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries