EternalRocks: Security researchers have just discovered a new worm that spreads via SMB using seven NSA hacking tools instead of the two used by WannaCry.
The discovery was made by security researcher Miroslav Stampar, a member of the Croatian CERT. He discovered the worm when he spotted an infection in an SMB honeypot, as reported by Bleeping Computer.

Stampar named the new worm EternalRocks and found that it uses six NSA tools to infect a computer via SMB ports. The EternalBlue, EternalChampion, EternalRomance, and EternalSynergy exploits, as well as SMBTouch and ArchiTouch, are used in conjunction with DoublePulsar, the well-known NSA tool, which pushes the worm to new vulnerable machines.
In comparison, WannaCry used only EternalBlue and DoublePulsar to spread to around 300,000 devices.
Stampar, comparing EternalRocks to WannaCry, admits that it is much less dangerous, mainly because it does not deliver malicious content. EternalRocks, however, is much more sophisticated than the ransomware that is spreading globally.
How It Works:
Once the worm infects its victim, it uses a two-stage installation process, with the second stage being delayed.
In the first phase, EternalRocks downloads the Tor program and sends a signal to a C&C server on the Dark Web. After 24 hours, the C&C server sends back a response. This delayed response is a method often used by malware to avoid detection, as even security researchers could stop waiting for a response from the server.
EternalRocks does not appear to use files with the same names as the WannaCry worm, nor does it include a kill switch domain.
The installation of the second stage of EternalRocks involves downloading a file called shadowbrokers.zip. The Shadow Brokers, as you may know, are the group that stole classified documents and files from the NSA. The worm does an IP scan and tries to connect to a random address.
At the moment, EternalRocks is not that dangerous. However, it could become a very big threat if attackers decide to weaponize the worm with ransomware, trojans, or anything else.
“EternalRocks, unlike WannaCry, operates in the shadows, both on the machine and on the Dark Web. Infected machines cannot be easily detected as there is no pop-up window asking for bitcoins. The use of leaked exploits gathers information such as credentials, passwords used when accessing websites, personal bank accounts and email accounts,” explains Paul Calatayud, CTO at FireMon.
“To prevent this malware from taking full control, it is important to configure your network to prevent network communications with TOR. Most next-generation firewalls can be configured to block TOR.”
