How Leaked NSA Spy Tool ‘EternalBlue’ Became a Hacker …
An elite Russian hacking team, a historic ransomware attack, an espionage group in the Middle East, and countless small time cryptojackers all have one thing in common. Though their methods and objectives vary, they all lean on leaked NSA hacking tool EternalBlue to infiltrate target computers and spread malware across networks.
Leaked to the public not quite a year ago, EternalBlue has joined a long line of reliable hacker favorites. The Conficker Windows worm infected millions of computers in 2008, and the Welchia remote code execution worm wreaked havoc 2003. EternalBlue is certainly continuing that traditionand by all indications it's not going anywhere. If anything, security analysts only see use of the exploit diversifying as attackers develop new, clever applications, or simply discover how easy it is to deploy.
"When you take something thats weaponized and a fully developed concept and make it publicly available youre going to have that level of uptake," says Adam Meyers, vice president of intelligence at the security firm CrowdStrike. "A year later there are still organizations that are getting hit by EternalBluestill organizations that havent patched it."
EternalBlue is the name of both a software vulnerability in Microsoft's Windows operating system and an exploit the National Security Agency developed to weaponize the bug. In April 2017, the exploit leaked to the public, part of the fifth release of alleged NSA tools by the still mysterious group known as the Shadow Brokers. Unsurprisingly, the agency has never confirmed that it created EternalBlue, or anything else in the Shadow Brokers releases, but numerous reports corroborate its originand even Microsoft has publicly attributed its existence to the NSA.
The tool exploits a vulnerability in the Windows Server Message Block, a transport protocol that allows Windows machines to communicate with each other and other devices for things like remote services and file and printer sharing. Attackers manipulate flaws in how SMB handles certain packets to remotely execute any code they want. Once they have that foothold into that initial target device, they can then fan out across a network.
'It's incredible that a tool which was used by intelligence services is now publicly available and so widely used amongst malicious actors.'
Vikram Thakur, Symantec
Microsoft released its EternalBlue patches on March 14 of last year. But security update adoption is spotty, especially on corporate and institutional networks. Within two months, EternalBlue was the centerpiece of the worldwide WannaCry ransomware attacks that were ultimately traced to North Korean government hackers. As WannaCry hit, Microsoft even took the "highly unusual step" of issuing patches for the still popular, but long-unsupported Windows XP and Windows Server 2003 operating systems.
In the aftermath of WannaCry, Microsoft and others criticized the NSA for keeping the EternalBlue vulnerability a secret for years instead of proactively disclosing it for patching. Some reports estimate that the NSA used and continued to refine the EternalBlue exploit for at least five years, and only warned Microsoft when the agency discovered that the exploit had been stolen. EternalBlue can also be used in concert with other NSA exploits released by the Shadow Brokers, like the kernel backdoor known as DarkPulsar, which burrows deep into the trusted core of a computer where it can often lurk undetected.
The versatility of the tool has made it an appealing workhorse for hackers. And though WannaCry raised EternalBlue's profile, many attackers had already realized the exploit's potential by then.
Within days of the Shadow Brokers release, security analysts say that they began to see bad actors using EternalBlue to extract passwords from browsers, and to install malicious cryptocurrency miners on target devices. "WannaCry was a big splash and made all the news because it was ransomware, but before that attackers had actually used the same EternalBlue exploit to infect machines and run miners on them," says Jrme Segura, lead malware intelligence analyst at the security firm Malwarebytes. "There are definitely a lot of machines that are exposed in some capacity."
Even a year after Microsoft issued a patch, attackers can still rely on the EternalBlue exploit to target victims, because so many machines remain defenseless to this day. "EternalBlue will be a go-to tool for attackers for years to come," says Jake Williams, founder of the security firm Rendition Infosec, who formerly worked at the NSA. "Particularly in air-gapped and industrial networks, patching takes a lot of time and machines get missed. There are many XP and Server 2003 machines that were taken off of patching programs before the patch for EternalBlue was backported to these now-unsupported platforms."
At this point, EternalBlue has fully transitioned into one of the ubiquitous, name-brand instruments in every hacker's toolboxmuch like the password extraction tool Mimikatz. But EternalBlue's widespread use is tinged with the added irony that a sophisticated, top-secret US cyber espionage tool is now the people's crowbar. It is also frequently used by an array of nation state hackers, including those in Russia's Fancy Bear group, who started deploying EternalBlue last year as part of targeted attacks to gather passwords and other sensitive data on hotel Wi-Fi networks.
'EternalBlue will be a go-to tool for attackers for years to come.'
Jake Williams, Rendition Infosec
New examples of EternalBlue's use in the wild still crop up frequently. In February, more attackers leveraged EternalBlue to install cryptocurrency-mining software on victim computers and servers, refining the techniques to make the attacks more reliable and effective. "EternalBlue is ideal for many attackers because it leaves very few event logs," or digital traces, Rendition Infosec's Williams notes. "Third-party software is required to see the exploitation attempts."
And just last week, security researchers at Symantec published findings on the Iran-based hacking group Chafer, which has used EternalBlue as part of its expanded operations. In the past year, Chafer has attacked targets around the Middle East, focusing on transportation groups like airlines, aircraft services, industry technology firms, and telecoms.
"It's incredible that a tool which was used by intelligence services is now publicly available and so widely used amongst malicious actors," says Vikram Thakur, technical director of Symantec's security response. "To [a hacker] its just a tool to make their lives easier in spreading across a network. Plus they use these tools in trying to evade attribution. It makes it harder for us to determine whether the attacker was sitting in country one or two or three."
It will be years before enough computers are patched against EternalBlue that hackers retire it from their arsenals. At least by now security experts know to watch for itand to appreciate the clever innovations hackers come up with to use the exploit in more and more types of attacks.
Link:
How Leaked NSA Spy Tool 'EternalBlue' Became a Hacker ...
- Man Accused of Impersonating Chief Justice Roberts, NSA Agent - Bloomberg Law News - August 25th, 2026 [August 25th, 2026]
- I Worked For The NSA For Years. Here's What Happened To My Life After Donald Trump And DOGE Showed Up Last Year. - HuffPost - August 25th, 2026 [August 25th, 2026]
- NSA isnt complying with federal laws on whistleblower protections, IG finds - Federal News Network - August 25th, 2026 [August 25th, 2026]
- NSA Doval says India-China ties 'returning to normalcy' as he holds key talks with Wang Yi on border issue - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- 4 Ways Tim Kosiba and the NSA Are Countering the Chinese Intelligence Threat - GovCon Wire - August 25th, 2026 [August 25th, 2026]
- Man charged with forging Chief Justice John Robertss signature, impersonating NSA agent - Yahoo - August 25th, 2026 [August 25th, 2026]
- NSA Doval to visit China on Monday to attend Special Representatives talks with FM Wang - The Economic Times - August 25th, 2026 [August 25th, 2026]
- Audit Finds Lack of Oversight of NDAs at NSA - FEDweek - August 25th, 2026 [August 25th, 2026]
- Redefining India-China Relations: NSA Dovals Visit to Beijing May Provide the Breakthrough - Raksha Anirveda - August 25th, 2026 [August 25th, 2026]
- NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology - The Record from Recorded Future News - August 25th, 2026 [August 25th, 2026]
- NSA Doval meets Chinese Vice President Han Zheng ahead of border talks - The Tribune - August 25th, 2026 [August 25th, 2026]
- India-China ties normalised by peace on border, says NSA Doval at talks with Wang Yi - Firstpost - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds 25th India-China border talks with Wang Yi - timesofindia.indiatimes.com - August 25th, 2026 [August 25th, 2026]
- NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs - Security Affairs - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval arrives in Beijing, set for border talks with Chinas Wang Yi on August 25 - The Hindu - August 25th, 2026 [August 25th, 2026]
- NSA, FBI Warn of AI-Powered Attacks on Industrial Systems Targeting Siemens PLCs - finance.biggo.com - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds talks with Chinese FM Wang Yi on boundary issue - News On AIR - August 25th, 2026 [August 25th, 2026]
- NSA Doval in Beijing for Talks with Chinese FM - Kashmir Observer - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold India-China boundary talks with Wang Yi in Beijing - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold border talks with Chinese Foreign Minister Wang on Tuesday - The Tribune - August 25th, 2026 [August 25th, 2026]
- Ayitey Powers Arrested Over Alleged Death Threat Against NSA Boss - Modern Ghana - August 25th, 2026 [August 25th, 2026]
- NSA Doval arrives in Beijing for talks with Chinese FM Wang Yi on boundary issue - ThePrint - August 25th, 2026 [August 25th, 2026]
- Police arrest former boxer Ayitey Powers over alleged death threat on NSA boss - Ghanaian Times - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval in Beijing for boundary talks - Awaz The Voice - August 25th, 2026 [August 25th, 2026]
- ID Based on Anonymous Informant, Sudden Reference to 2009 Home Ministry Notification: Why NSA Case Against Satyam Verma Is Unconvincing - TheWire.in - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval: India's Strength Infused with Tolerance Amid Military Actions - India News Network - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval Reveals Operation Sindoor Strategy in New Discovery Docuseries - Daily Pioneer - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval on Operation Sindoor: 'India can hit hard, irrespective of consequences' - wionews.com - August 16th, 2026 [August 16th, 2026]
- Indias generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Op Sindoor - The Tribune - August 14th, 2026 [August 14th, 2026]
- 'Don't mistake India's generosity with weakness': NSA Ajit Doval on Operation Sindoor - The Times of India - August 14th, 2026 [August 14th, 2026]
- India's generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Operation Sindoor - The Hindu - August 14th, 2026 [August 14th, 2026]
- Former NSA Chief Gen. Paul Nakasone: AI Is Changing the Cyber Battlefield - The Cipher Brief - August 14th, 2026 [August 14th, 2026]
- NSA Doval says Indias restraint should not be mistaken for weakness - Awaz The Voice - August 14th, 2026 [August 14th, 2026]
- NSA Ajit Doval says India can hit hard irrespective of consequences in first post-Sindoor interview - The Economic Times - August 14th, 2026 [August 14th, 2026]
- Man claiming to be undercover agent of NSA Ajit Doval arrested in Bihar - The Hindu - August 14th, 2026 [August 14th, 2026]
- Indias tolerance should not be mistaken for weakness; can take risks, hit hard: NSA Doval on Op Sindoor - The Kashmir Horizon - August 14th, 2026 [August 14th, 2026]
- Indias Tolerance Not a Sign of Weakness: NSA Ajit Doval on Operation Sindoor - The CSR Journal - August 14th, 2026 [August 14th, 2026]
- NSA Joins FBI and Others in Releasing Guidance to Defend Against Gunra Ransomware - National Security Agency (NSA) (.gov) - August 12th, 2026 [August 12th, 2026]
- Your router is probably vulnerable to the same attacks the NSA just warned about - MakeUseOf - August 12th, 2026 [August 12th, 2026]
- Trump has to accept hes going to lose Iran war: Former deputy NSA - MS NOW - August 12th, 2026 [August 12th, 2026]
- NSA installs DHS lawyer as new general counsel - The Record from Recorded Future News - August 12th, 2026 [August 12th, 2026]
- Manipur to invoke NSA against NH extortionists: Min - The Times of India - August 12th, 2026 [August 12th, 2026]
- Spymaster United States Joshua Rudd, US special forces officer nursing NSA back to health - Intelligence Online - July 7th, 2026 [July 7th, 2026]
- Capability, Not Compute: NSA Discretion in the Frontier AI EO - The Well News - July 7th, 2026 [July 7th, 2026]
- NSA partners with dog walking app to tackle livestock worrying - Agriland UK - July 1st, 2026 [July 1st, 2026]
- Youth Round Table Discussion: Youth round table discussion held at NSA - Myanmar International TV - July 1st, 2026 [July 1st, 2026]
- NSA welcomes Farming Roadmap 2050 and says farmers are ready to meet the challenge - Meat Management - July 1st, 2026 [July 1st, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - Yahoo Tech - June 22nd, 2026 [June 22nd, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - BeInCrypto - June 22nd, 2026 [June 22nd, 2026]
- Its more than Iran could have ever hoped for: Ex-US NSA John Bolton on US-Iran deal - Firstpost - June 22nd, 2026 [June 22nd, 2026]
- Manipur slaps NSA on youth already held under UAPA. Why HC quashed both cases, ordered his release - ThePrint - June 22nd, 2026 [June 22nd, 2026]
- Algorand Post-Quantum Security by 2027: 3 Years Ahead of NSA - The Cryptonomist - June 22nd, 2026 [June 22nd, 2026]
- China foreign minister set to attend Brics NSA meet in Delhi next week - The Times of India - June 22nd, 2026 [June 22nd, 2026]
- India to host BRICS NSA meet on June 2223: MEA - Awaz The Voice - June 22nd, 2026 [June 22nd, 2026]
- IDR Final Rule updates NSA dispute resolution | United States | Global law firm - Norton Rose Fulbright - June 16th, 2026 [June 16th, 2026]
- Where Is Edward Snowden Now? What to Know About the NSA Whistleblower's Life in Exile, 13 Years Later - People.com - June 16th, 2026 [June 16th, 2026]
- Former NSA official: 'Timing couldn't have been worse' for FISA 702 to expire - WBFF - June 16th, 2026 [June 16th, 2026]
- SHAREHOLDER ALERT: The M&A Class Action Firm Continues to Investigate the Merger--CZNL, NSA, CNBN, and ESQ - PR Newswire - June 16th, 2026 [June 16th, 2026]
- Training, teamwork, and quick action save a life at NSA Philadelphia - MilitaryNews.com - June 12th, 2026 [June 12th, 2026]
- NSA Insurance celebrates 100 years of selling a promise on the East End - The Suffolk Times - June 12th, 2026 [June 12th, 2026]
- Ex Pakistan NSA Moeed Yusuf says fixing ties with India key to economic revival, regional trade ambitions - ThePrint - June 12th, 2026 [June 12th, 2026]
- RSABI's Carol McLaren wins NSA Silver Salver for her work in the industry - The Scottish Farmer - June 12th, 2026 [June 12th, 2026]
- Anthropic's Mythos model is reportedly powering NSA offensive cyber ops against China and Iran - the-decoder.com - June 7th, 2026 [June 7th, 2026]
- NSA taps three officials for top cybersecurity positions - Nextgov/FCW - June 7th, 2026 [June 7th, 2026]
- Anthropic is blacklisted by the Pentagon and being used by the NSA at the same time - TechSpot - June 7th, 2026 [June 7th, 2026]
- NSA said to be readying Anthropics Mythos for use in cyber operations - TechCrunch - June 5th, 2026 [June 5th, 2026]
- Former NSA John Bolton to plead guilty to retaining classified info - MS NOW - June 5th, 2026 [June 5th, 2026]
- Trump executive order on AI gives central role to NSA - Breaking Defense - June 5th, 2026 [June 5th, 2026]
- Anthropic Is Helping the NSA Hack China. It Also Wants Everyone to Pause AI - Yahoo - June 5th, 2026 [June 5th, 2026]
- NSA using Claude Mythos for 'offensive cyber operations,' report claims says 'half-a-dozen' Anthropic engineers embedded inside the agency - Tom's... - June 5th, 2026 [June 5th, 2026]
- NSA selects new leads for key cybersecurity posts - The Record from Recorded Future News - June 5th, 2026 [June 5th, 2026]
- NSA Joins CISA and Partners to Release Guidance on Hardening Automatic Tank Gauge Systems - National Security Agency (NSA) (.gov) - June 5th, 2026 [June 5th, 2026]
- FT: Anthropic staff helping the NSA use Mythos for offensive cyberattacks - Sherwood News - June 5th, 2026 [June 5th, 2026]
- Anthropic Is Helping the NSA Hack China. It Also Wants Everyone to Pause AI - Decrypt - June 5th, 2026 [June 5th, 2026]
- Anthropic Embeds Engineers at NSA to Deploy Mythos AI for Offensive Cyber Operations - MLQ.ai - June 5th, 2026 [June 5th, 2026]
- The NSA has all the equipment and technology needed to track bandits but lacks the political will to do so -Stephen alleges Watch full interview:... - June 5th, 2026 [June 5th, 2026]
- Anthropic aids NSA with Mythos to bolster offensive cyber operations - CHOSUNBIZ - Chosunbiz - June 5th, 2026 [June 5th, 2026]
- NSA warns that cybercriminals are targeting this one critical component that the energy, chemical, food, agriculture, and transportation sectors rely... - June 5th, 2026 [June 5th, 2026]
- Video | Ex-Trump NSA Adviser Pleads Guilty To Classified Info Leak | Zelenskyy Calls For Meet With Putin - NDTV - June 5th, 2026 [June 5th, 2026]
- Former Trump NSA John Bolton to plead guilty over retaining classified documents: Report - WION - June 5th, 2026 [June 5th, 2026]