Advertisement
Sections
EternalRocks uses seven NSA tools leaked by the ShadowBrokers, WannaCry just used two
A newly discovered malware, known as EternalRocks exploits the same vulnerability as WannaCry to spread, and may actually be more dangerous.

In the wake of the global attack by the WannaCry ransomware, security researchers are identifying a number of other malware that use the same exploits that were leaked by the ShadowBrokers. The vulnerability used by WannaCry is a Windows Server Message Block remote execution vulnerability. This means that a specially crafted message can be sent to Windows operating systems, that can allow the execution of arbitrary code. Microsoft issued a patch for this vulnerability on 14 March.
The WannaCry ransomware used an exploit of this vulnerability, known as EternalBlue to worm its way into systems. Once the infection had spread, WannaCry used a backdoor, known as DoublePulsar. This would allow remote attackers to execute code on the compromised machines. However, the WannaCry ransomware is not the only malware to use both the exploit, EternalBlue or the backdoor, DoublePulsar. A cryptocurrency miner known as Adylkuzz is minting virtual currencies on infected machines. Another malware spreading through a similar attack vector is known as UIWIX.A newly discovered malware, known as EternalRocks exploits the same vulnerability to spread, and may actually be more dangerous than WannaCry. The original cache of leaked NSA tools includes a number of exploits. Some of these are EmeraldThread, ErraticGopher, EnglishmansDentist, EskimoRoll, EwokFrenzy and ZippyBeer. Along with EternalBlue, EternalChampion, EternalRomance and EternalSynergy are all Server Message Block (SMB) exploits. EternalRocks uses all four of these. EternalRocks also uses the DoublePulsar backdoor, as well as two tools used to scan for SMB vulnerabilities, ArchiTouch and SMBTouch.
The EternalRocks malware is relatively new, and has just been discovered in May. One of the unique features of the malware is that it waits for a period of twenty four hours, before using the backdoor to download additional malware from the command and control server. Cisco's Talos intelligence is actively tracking a number of malware using the leaked NSA tools. Unlike the WannaCry ransomware, whose spread was halted because a security blogger registered a domain, the EternalRocks malware does not have a killswitch.The malware initially appeared to be a copy of the WannaCry ransomware, or a variant. It was using the same process names used by WannaCry to distract investigators, and mask its own activities. The malware is known by a number of names, including DoomsDayWorm and MicroBotMassiveNet. The malware appears to be a worm that is creating a botnet of some sort. At this point of time, EternalRocks does not seem to have a malicious payload, but that just means that it is in a preparatory stage of the attack. Malicious actors can execute code on infected machines remotely.[caption id="attachment_376188" align="aligncenter" width="640"]
A screenshot of a computer infected by WannaCry.[/caption]After the ShadowBrokers allegedly obtained the tools from a secret NSA server, the hacking collective put up the tools for auction. There were no serious buyers, the auction was RickRolled with a series of bitcoin transactions, and the ShadowBrokers publicly released the tools. Microsoft claimed that it had already fixed the vulnerabilities exposed by the hacking group. Some of the affected machines included older operating systems that Microsoft no longer publicly supported. Although it was initially reported that Windows XP systems were the most affected, the malware could not spread through the systems, and the malware was actually so successful because of unpatched Windows 7 systems.Older systems are still vulnerable if unpatched. There are a number of leaked tools that can still be used by malicious actors. Security experts have warned that more attacks similar to the WannaCry attack may follow.
The WannaCry ransomware used an exploit of this vulnerability, known as EternalBlue to worm its way into systems. Once the infection had spread, WannaCry used a backdoor, known as DoublePulsar. This would allow remote attackers to execute code on the compromised machines. However, the WannaCry ransomware is not the only malware to use both the exploit, EternalBlue or the backdoor, DoublePulsar. A cryptocurrency miner known as Adylkuzz is minting virtual currencies on infected machines. Another malware spreading through a similar attack vector is known as UIWIX.A newly discovered malware, known as EternalRocks exploits the same vulnerability to spread, and may actually be more dangerous than WannaCry. The original cache of leaked NSA tools includes a number of exploits. Some of these are EmeraldThread, ErraticGopher, EnglishmansDentist, EskimoRoll, EwokFrenzy and ZippyBeer. Along with EternalBlue, EternalChampion, EternalRomance and EternalSynergy are all Server Message Block (SMB) exploits. EternalRocks uses all four of these. EternalRocks also uses the DoublePulsar backdoor, as well as two tools used to scan for SMB vulnerabilities, ArchiTouch and SMBTouch.
The EternalRocks malware is relatively new, and has just been discovered in May. One of the unique features of the malware is that it waits for a period of twenty four hours, before using the backdoor to download additional malware from the command and control server. Cisco's Talos intelligence is actively tracking a number of malware using the leaked NSA tools. Unlike the WannaCry ransomware, whose spread was halted because a security blogger registered a domain, the EternalRocks malware does not have a killswitch.The malware initially appeared to be a copy of the WannaCry ransomware, or a variant. It was using the same process names used by WannaCry to distract investigators, and mask its own activities. The malware is known by a number of names, including DoomsDayWorm and MicroBotMassiveNet. The malware appears to be a worm that is creating a botnet of some sort. At this point of time, EternalRocks does not seem to have a malicious payload, but that just means that it is in a preparatory stage of the attack. Malicious actors can execute code on infected machines remotely.[caption id="attachment_376188" align="aligncenter" width="640"]
A screenshot of a computer infected by WannaCry.[/caption]After the ShadowBrokers allegedly obtained the tools from a secret NSA server, the hacking collective put up the tools for auction. There were no serious buyers, the auction was RickRolled with a series of bitcoin transactions, and the ShadowBrokers publicly released the tools. Microsoft claimed that it had already fixed the vulnerabilities exposed by the hacking group. Some of the affected machines included older operating systems that Microsoft no longer publicly supported. Although it was initially reported that Windows XP systems were the most affected, the malware could not spread through the systems, and the malware was actually so successful because of unpatched Windows 7 systems.Older systems are still vulnerable if unpatched. There are a number of leaked tools that can still be used by malicious actors. Security experts have warned that more attacks similar to the WannaCry attack may follow.First Published:May 23, 2017, 12:58:28 IST
Advertisement
Advertisement

Why AI notetakers are raising serious privacy and security concerns
AI notetakers promise effortless meeting summaries, but experts warn they could expose confidential conversations, corporate secrets and personal voiceprints. As businesses increasingly adopt AI-powered meeting assistants, questions over data storage, privacy, consent and legal risks are becoming impossible to ignore
5 min read
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
As Chinese firms continue to improve performance while keeping prices low, the AI race is no longer just about building the smartest model—it is increasingly becoming a battle over who can deliver the best value
2 min read
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
How did Instagram run ads promoting child abuse in India?
India has issued a notice to Meta after an investigation alleged that Instagram displayed paid advertisements promoting child sexual abuse material. MeitY ordered Meta to remove such Instagram ads and explain within seven days how they were approved
8 min read
Why has India halted WhatsApp’s username feature before launch?
India has halted WhatsApp’s planned username feature, citing concerns about cybercrime, impersonation, and law enforcement challenges. As Meta races to address security concerns, here’s why MeitY has paused the rollout, what the feature does, and how it could influence privacy and online safety in India
3 min read
Advertisement
Advertisement
