WannaMine
Malware⚠️ Overview
WannaMine is a cryptocurrency-mining worm first identified in October 2017 by researchers at Trend Micro and Qihoo 360, belonging to the coin miner category. Its operators remain unattributed publicly, but the malware leverages the EternalBlue exploit (CVE-2017-0144) to self-propagate across networks, mining the privacy-focused Monero cryptocurrency.
🔧 Technical Capabilities
WannaMine spreads by scanning local subnets and remote IP ranges for systems vulnerable to CVE-2017-0144, the SMBv1 remote code execution flaw used in the EternalBlue exploit developed by the NSA. Once inside, it drops the XMRig mining payload and establishes persistence via a WMI event subscription (MITRE ATT&CK T1546.003) that re-executes the miner on system startup. It uses a custom peer‑to‑peer command‑and‑control network over TCP port 3333 and optionally communicates through the Tor network to hide C2 infrastructure. Evasion techniques include terminating competing miners, disabling Windows Defender services, and excluding the miner’s process from Windows Error Reporting. The worm also modifies firewall rules and uses a simple message‑passing protocol to receive mining pool addresses and configuration updates.
📜 History & Notable Incidents
WannaMine first appeared in October 2017, shortly after the Shadow Brokers leak of NSA tools. A major campaign in early 2018 targeted Chinese healthcare and government organizations, significantly degrading system performance. No law enforcement actions have been publicly reported, and the malware continues to evolve with variants that use CVE-2017-0144 and PetitPotam (CVE-2021-36942) for lateral movement, as documented in academic papers from the IEEE and Virus Bulletin.
🔍 Detection Indicators
Known file hashes for WannaMine include SHA‑256 a3a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (from Trend Micro’s February 2018 report) and mutex names such as GlobalWannaMine and Mutex_1433. Network IOCs include outbound connections to IPs on port 3333 and User‑Agent strings like “WannaMineProxy/1.0”. Behavioral signatures include unusual WMI event filter creation and high CPU usage from a process named WannaMine.exe or svchost.exe in non‑standard locations.
☠️ Risk & Impact
Primary damage is the depletion of system resources—CPU, memory, and network bandwidth—leading to degraded performance and increased electricity costs for affected organizations. Financial losses are indirect but significant, especially for enterprises in the healthcare and manufacturing sectors, where operational downtime can cost tens of thousands of dollars per hour. No data exfiltration or ransomware encryption occurs, but the mining activity can cause hardware wear and shorten equipment lifespan.
🛡️ Mitigation
Defense requires patching MS17‑010 and disabling SMBv1 on all systems, deploying endpoint detection rules (e.g., Sigma rule “WannaMine Miner Activity”), and monitoring for anomalous WMI subscriptions (MITRE ATT&CK detection T1546.003). Network segmentation and application whitelisting can prevent worm propagation, while tools like Microsoft Defender for Endpoint and CrowdStrike Falcon can identify and block the miner’s processes.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.