Ethical hackers show that Windows 10 isn’t immune to WannaCry

Remember WannaCry? The huge ransomware attack, which caused chaos last month, mainly affected Windows 7 PCs, with the latest Windows release being immune thanks to its beefier security – but that has now changed, as security researchers have ported the malware over to Windows 10.

Well, to be precise, the folks at RiskSense have adapted the central exploit which WannaCry was based on, called EternalBlue, so it can successfully compromise Windows 10 systems.

The ethical hackers (white hats, as they’re known) further honed the exploit, streamlining the code and reducing its footprint, and also doing away with the DoublePulsar backdoor, instead creating what they described as a “stealthier payload mechanism” to deliver a custom payload to the target machine.

As Bleeping Computer reports, the researchers said that this was all in an effort to “[substantiate] the premise that the original exploit's DoublePulsar payload is a red herring for defenders to focus on”.

In other words, security firms should not be searching for this backdoor in their detection efforts, but rather the core exploit itself. And porting the malware across to Windows 10 in this manner is RiskSense’s way of highlighting what security software should be focusing on, and of reminding users of Microsoft’s latest OS that they aren’t immune to the ravages of WannaCry-style attacks.

Exploit evolution

However, there are a couple of things to note here. Firstly, in their report on this matter, the white hats left out key details of their revamped exploit so as not to give malicious types out there a new weapon.

And secondly, the exploit they crafted only works against older versions of Windows 10 (pre-Anniversary Update), but that isn’t really the point. It’s about showing the lines along which these sort of exploits can evolve, and reminding folks not to sit back smugly even when the OS they’re running appears to be bulletproof to a new threat.

As ever, ensuring your software and operating system are always kept fully up-to-date with the latest patches is a critical concern.

Particularly when you consider that the follow-up exploit, EternalRocks, which has already been spotted in the wild (albeit not weaponized), is considerably more dangerous than EternalBlue, which itself is highly sophisticated to begin with.

Plus, there's the fact that Shadow Brokers, the group which leaked NSA exploits such as EternalBlue, has promised more chaos with the release of similar tools this month.

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Windows
A man getting angry with his laptop.
Windows 11 bug deletes Copilot from the OS – is this the first glitch ever some users will be happy to encounter?
Printer
No, your printer isn't possessed: a Windows 11 23H2 bug could be making it print random characters when connected via USB
Man having Windows 11 problems with his laptop
Fed up of adverts creeping into Windows 11? You won’t like Microsoft’s latest update, then, although it does provide some important bug fixes
Acer Aspire 14 AI laptop display showing the Windows 11 login screen
Shock, horror – I’m not going to argue with Microsoft’s latest bit of nagging in Windows 11, as this pop-up is justified
A laptop on a desk with the Windows 11 background on its screen.
Microsoft is adding image editing and compression to its Windows Share feature - and I couldn't be happier
AOC Agon Pro AG276FK gaming monitor tilted slightly to the side, showing the Windows desktop screen
Windows 11 users get ready for more ‘recommendations’ from Microsoft – but I’m relieved to say these suggestions might actually be useful
Latest in News
European Union technical background
EU tech companies push for digital sovereignty, reducing reliance on US and others
Star Wars Knights of the Old Republic
Knights of the Old Republic remake developer Saber Interactive states all its projects are 'still in development'
google nest
Google is slowly phasing out its Assistant helper to make room for Gemini's reign in smartphones - here’s how it’s doing the same for smart home devices
Renault 5 Turbo 3E
Renault unveils its wildest EV to date and it comes with in-wheel motors and a rally-style vertical handbrake for drifting
Circular smart ring
Circular's new smart ring is getting blood pressure and blood glucose monitoring before the Apple Watch
Gemini on a mobile phone.
Worryingly, Google Gemini’s new AI image generation features can be used to remove watermarks from images and I'm concerned