The Shadow Brokers (2016-17): leaked NSA cyber-weapons become global ransomware
An entity calling itself The Shadow Brokers auctioned, then dumped, a cache of offensive tools attributed to the NSA-linked Equation Group (Tailored Access Operations). The April 2017 "Lost in Translation" dump included EternalBlue (an SMBv1 remote-code-execution exploit) + the DoublePulsar implant. Microsoft had quietly patched it (MS17-010, Mar 2017) a month before.
Within weeks EternalBlue powered two of the most damaging worms in history:
- WannaCry (May 12, 2017) - ransomware, ~200k+ machines in 150+ countries (incl. the UK NHS); stopped by a researcher's kill-switch. Attributed by the US/UK to North Korea (Lazarus), Dec 2017.
- NotPetya (Jun 27, 2017) - a wiper masquerading as ransomware, seeded via a compromised Ukrainian tax-software update; ~$10B damage (Maersk, Merck, FedEx/TNT). Attributed by the US/UK to the Russian military (GRU), Feb 2018.
Honest limits. The outbreak attributions are official government attributions (high-confidence, still assertions). The identity of the Shadow Brokers themselves is unresolved - Russia widely suspected, an insider theory floated, neither proven. The enduring lesson: state-hoarded offensive tools leak and boomerang - the core case against vulnerability stockpiling and for coordinated disclosure.
Sources: Microsoft MS17-010; US-CERT; US/UK attributions (2017/2018); vendor analyses. Cross-refs: Equation_Group, NSA, North_Korea, Lazarus_Group, Russia, Malware_Lineage.
← Research index · structured data: spec-shadow-brokers-eternalblue.json · spec-shadow-brokers-eternalblue.md