Skip to content
EntityQ29916946· pop 20· linked from 248 articles

EternalBlue

Sign in to save

Also known as MS17-010, ms17010

EternalBlue is computer exploit software developed by the U.S. National Security Agency (NSA). It is based on a zero-day vulnerability in Microsoft Windows software that allowed users to gain access to any number of computers connected to a network. The NSA was aware of this vulnerability but did not disclose it to Microsoft for several years, as it intended to use the exploit as part of its offensive cyber operations. In 2017, the NSA discovered that the software had been stolen by a group of hackers known as the Shadow Brokers. Microsoft might have been informed of this and released security

Key facts

Computer virus.common_name
Eternal - Anonymous
Computer virus.technical_name
L** Trojan:Win32/EternalBlue (Microsoft) Rocks Variant TrojanDownloader:Win32/Eterock.[Letter] (Microsoft) W32.Eternalrocks (Symantec) TROJ_ETEROCK.[Letter] (Trend Micro) Mal/Eterocks-[Letter] (Sophos) Troj/Eterocks-[Letter] (Sophos) Synergy Variant Win32/Exploit.Equation.EternalSynergy (ESET)
Computer virus.type
Exploit
Computer virus.author
Equation Group
Computer virus.platform
Windows 95, Windows 98, Windows Me, Windows NT 3.x, Windows NT 4.0, Windows 2000, Windows XP, Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows NT 3.1-2000 Server Editions, Windows Server 2003, Windows Server 2003 R2, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016

via Wikipedia infobox

~8 min read

Encyclopedic overview

10 sections
Contents
  • Details
  • City of Baltimore cyberattack
  • Russian computers hacked
  • Responsibility
  • EternalRocks
  • Infection
  • See also
  • References
  • Further reading
  • External links

EternalBlue is computer exploit software developed by the U.S. National Security Agency (NSA). It is based on a zero-day vulnerability in Microsoft Windows software that allowed users to gain access to any number of computers connected to a network. The NSA was aware of this vulnerability but did not disclose it to Microsoft for several years, as it intended to use the exploit as part of its offensive cyber operations. In 2017, the NSA discovered that the software had been stolen by a group of hackers known as the Shadow Brokers. Microsoft might have been informed of this and released security updates in March 2017 patching the vulnerability. While this was happening, the hacker group attempted to auction off the software, but did not succeed in finding a buyer. EternalBlue was then released publicly on April 14, 2017.

On May 12, 2017, a computer worm in the form of ransomware, nicknamed WannaCry, used the EternalBlue exploit to attack computers using Windows that had not received the latest system updates removing the vulnerability. On June 27, 2017, the exploit was again used to help carry out the 2017 NotPetya cyberattack on more vulnerable computers.

Excerpted from Wikipedia’s “EternalBlue” article, available under the CC BY-SA 4.0 licence.