Guess who’s back… The EternalBlue, the exploit of the NSA that was used to create the infamous WannaCry ransomware, returns, and this time more powerful than ever.
Researcher Ondrej Kubovič emphasizes that although WannaCry attacks have dwindled, EternalBlue remains active and the first months of 2018 brought an increase in the number of attacks that are based on this exploit.
Informationally, EternalBlue is an NSA exploit that was stolen by the hacking group Shadow Brokers in April 2016. Essentially, the exploit leverages the vulnerability in the Windows Server Message Block (SMB) protocol that Microsoft has already attempted to fix.
This doesn't mean that attackers have stopped looking for targets. The researcher says that cybercriminals are scanning the internet for exposed SMB ports and attempting to compromise the compromised system with an exploit.
Kubovič guesses that this increase in the number of attacks based on EternalBlue could have been caused by the ransomware campaign Satan.
With patches already available, attackers can only compromise a Windows host if these updates are not installed. Microsoft were released in March 2017, and modern computers should be protected.
This increasing number of attacks, however, suggests that there are still many systems that have not deployed the updates. Bulletins for the WannaCry ransomware are available, even for Windows XP. Make sure to protect your computers if you haven't already.
