What Was EternalBlue? The Exploit That Leaked, and What Came Through It

In September 2016, a Microsoft engineer published a blog post with a title that did not leave much room for interpretation: "Stop using SMB1."

The post did not build to its point gradually. Its opening line reads, in escalating type:

Stop using SMB1. Stop using SMB1. STOP USING SMB1!

The author was Ned Pyle, Principal Program Manager in Microsoft's Windows Server storage group — which is to say, the man who owned the protocol, asking people to stop using the thing he owned. He described SMB1 as "nearly 30 years old, and like much of the software made in the 80's, it was designed for a world that no longer exists. A world without malicious actors, without vast sets of important data."

He also wrote that running it "is like taking your grandmother to prom: she means well, but she can't really move anymore."

Seven months later, an exploit for SMB1 was published on the open internet, and inside eight weeks it had carried the two most destructive malware campaigns of the decade.

What was EternalBlue?

EternalBlue was an exploit — a piece of code that took advantage of a memory-corruption flaw in the way Windows' kernel-mode SMBv1 file-sharing service handled malformed requests arriving over port 445. Because the vulnerable code ran in the Windows kernel, a successful attack handed over the highest level of control the machine had to give. No password. No user. Nobody clicking anything.

It is attributed to the NSA's Equation Group, and this is worth stating carefully: no US agency has ever acknowledged authorship. What exists is very strong circumstantial evidence — Kaspersky tied the leaked toolkit to Equation Group malware through a distinctive shared crypto implementation, and The Intercept matched a sixteen-character operational identifier in the leaked code to a classified NSA manual from the Snowden archive. The most senior named party ever to assert it outright was not the government. It was Microsoft's own president, writing about "this vulnerability stolen from the NSA."

The thing everyone gets wrong

EternalBlue is not ransomware. It has never been ransomware.

It encrypts nothing, demands nothing, and destroys nothing. It opens a door and steps aside. What walked through the door changed month by month: cryptocurrency miners quietly running before anyone noticed, ransomware in May 2017, a destructive wiper in June, banking trojans in September.

You will constantly read that "EternalBlue hit the NHS" or "EternalBlue cost Maersk $300 million." Those were WannaCry and NotPetya. EternalBlue was how they travelled. The distinction is not pedantry — it is the difference between a burglary and a key.

How it got out

In August 2016 a group calling itself The Shadow Brokers appeared, claiming to have stolen a cache of tools from the Equation Group. They tried to auction them. It went badly — at one point the leading bid was worth about twenty dollars. Over the following months they released tranches: a list of staging servers that October, a set of Windows tools in January 2017 alongside an announcement that they were retiring.

Then on 8 April 2017 they published the password to the original auction archive, framing it as a political protest, making that whole trove free.

And on 14 April 2017 came the dump they named "Lost in Translation": around twenty-three tools, including EternalBlue, a companion implant called DoublePulsar, and a framework for running them.

Within ten days, internet-wide scans were finding machines already carrying the DoublePulsar implant — somewhere between roughly 30,000 and 160,000 of them, depending on whose scan you believed. The researchers argued about the number for weeks and never fully settled it.

The patch that arrived before the leak

Here is the strangest fact in the story. Microsoft patched the flaw as MS17-010 on 14 March 2017 — a full month before the Shadow Brokers published the exploit.

The bulletin covered six vulnerabilities, CVE-2017-0143 through CVE-2017-0148. EternalBlue is most commonly pinned to CVE-2017-0144, though it is worth knowing that Microsoft never officially mapped the individual codenames to individual CVEs, and in its own WannaCry analysis referred to CVE-2017-0145 instead.

So how did Microsoft know a month early?

It has never said. The Washington Post reported in May 2017, citing a former senior administration official, that the NSA had warned Microsoft after realising the tools had been stolen — the intelligence value of an exploit collapses once someone else has it. The NSA declined to comment.

What can be stated as fact rather than reporting is quieter and, in its way, louder: the MS17-010 bulletin's acknowledgments section credits nobody. For a Critical, externally reported flaw, that is unusual to the point of conspicuous. Microsoft thanked no one, because it could not say who.

What came through

Adylkuzz came first, and almost nobody noticed. A cryptocurrency mining campaign was using EternalBlue and DoublePulsar to quietly install Monero miners from around 2 May 2017 — before WannaCry, using the same door, to no headlines whatsoever, because a slow computer is not a news story.

WannaCry arrived on 12 May 2017. Ransomware, spreading as a worm, using EternalBlue to move. Eighty-one NHS trusts, nineteen thousand cancelled appointments, and a global outbreak stopped by a researcher who registered a domain for $10.69.

NotPetya arrived on 27 June 2017 and was worse. It presented itself as ransomware but was built to destroy — there was no working recovery path. Worth noting for accuracy: EternalBlue was only part of how it spread, and not the main part. It got in through a poisoned accounting-software update in Ukraine, then moved laterally using legitimate Windows administration tools as much as the exploit.

Retefe, a banking trojan, picked EternalBlue up that September for moving around inside networks it had already entered.

One clarification, because it is repeated everywhere: in 2019 The New York Times reported that EternalBlue was behind the ransomware attack that crippled Baltimore. The claim was contested almost immediately. A malware analyst who reverse-engineered the ransomware found no EternalBlue code in it and noted it had no ability to spread across networks by itself at all, and both of Maryland's congressional representatives said they had been told the federal assessment was that EternalBlue was not involved. The story was never retracted, and the attribution was never supported.

"Tomahawk missiles"

Two days after WannaCry, Brad Smith — then Microsoft's President and Chief Legal Officer — published a response that was less a security advisory than a shot across the bow of the US intelligence community:

"This attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen."

It remains the sharpest sentence any technology company has aimed at its own government about vulnerability hoarding, and it is the argument the entire debate has orbited ever since. If you build a weapon out of a flaw in software the whole world runs, you have to keep it perfectly. Forever. Nobody keeps anything perfectly forever.

When did it actually get fixed?

Patching MS17-010 fixed the vulnerability. Getting rid of the protocol took longer.

Windows 10 version 1709, shipped in autumn 2017, was the first release where SMBv1 was not installed by default — and even then not cleanly. Home and Pro editions still included the client, which uninstalled itself after fifteen days of disuse. Pro did not fully drop it until version 1809. Windows Server 2019 and Windows 11 ship without it.

Line the dates up and the whole story is in them. Microsoft's own protocol owner publicly begged people to stop using SMB1 in September 2016. The exploit leaked in April 2017. WannaCry in May. NotPetya in June. Microsoft stopped shipping SMB1 by default in autumn 2017 — after all of it.

Why it still matters

EternalBlue is the case study for two arguments that have not been resolved.

The first is about government vulnerability stockpiling. An agency found a flaw in software running on hundreds of millions of machines and chose to keep it rather than report it, reportedly for more than five years. That calculation is defensible right up until the moment the tool goes missing, at which point the same flaw that gave you an advantage is pointed at your own hospitals.

The second is duller and kills more organisations: the gap between knowing and doing. Every element of the defence existed in advance. The protocol was known to be obsolete. Microsoft's own engineer had written the post. The patch shipped a month before the exploit was public and two months before it was used at scale.

None of that mattered, because a patch that has not been installed is just a file on a server somewhere.

Further reading

  • Ned Pyle — Stop using SMB1 (Microsoft, September 2016). Seven months early, and worth reading for the tone alone.
  • Microsoft Security Bulletin MS17-010 (14 March 2017). Note the empty acknowledgments section.
  • Brad Smith — The need for urgent collective action to keep people safe online (Microsoft, 14 May 2017).
  • Sam Biddle — The NSA Leak Is Real, Snowden Documents Confirm (The Intercept, August 2016).
  • Mandiant and Proofpoint's campaign analyses for what actually used the exploit, and when.

EXHIBIT 0005 — ETERNALBLUE

We put it on a shirt. The port, the bulletin, and a protocol that outlived its own obituary by a year.

Most people who see it will read a word that sounds like a colour. A smaller number will see the number 445 and know exactly which door this is.

That's the whole idea.

View the EternalBlue shirt — EXHIBIT 0005

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.