MKT—KSA / 05

Malware dossiers

Documented technical dossiers covering entry, propagation, targets, impact and defensive action.

ENTRYPROPAGATIONIMPACTDEFENSE
  1. 01
    2017 · Ransomware with a network-worm component

    WannaCry

    Spread automatically through unpatched Windows systems by exploiting SMBv1, causing worldwide disruption across healthcare and essential services.

    Entry
    Exploitation of SMBv1 flaws addressed by MS17-010; network propagation does not require user interaction.
    Impact
    More than 200,000 devices across over 100 countries; thousands of UK health appointments and procedures were cancelled.
    Technical dossier ↗
  2. 02
    2017 · Destructive disk wiper disguised as ransomware

    NotPetya

    Entered through a compromised M.E.Doc update, then moved through networks using SMB and credentials, producing worldwide disruption.

    Entry
    A compromised software supply chain followed by internal propagation through SMB, administrative tools and stolen credentials.
    Impact
    Irrecoverable encryption and global losses in the billions; three documented victims alone lost nearly one billion dollars.
    Technical dossier ↗
  3. 03
    2010 · Industrial-control sabotage worm

    Stuxnet

    Targeted Siemens WinCC, STEP 7 and PLC environments, altering industrial behavior while concealing true process readings.

    Entry
    Initial access remains unresolved; documented propagation included USB, network shares, STEP 7 files and a print-spooler flaw.
    Impact
    Manipulated control commands, damaged centrifuge equipment and displayed misleading operating data.
    Technical dossier ↗
  4. 04
    2012 · Destructive workstation wiper

    Shamoon / Disttrack

    Collected system information and deployed a wiping module that overwrote boot records, partition tables and files, driving major operational disruption.

    Entry
    The initial entry vector was not officially determined; after compromise it propagated through network shares.
    Impact
    Unrecoverable data after wiping and disruption across a large part of a business network.
    Technical dossier ↗
  5. 05
    2014 · Trojan, botnet and malware loader

    Emotet

    Evolved from banking malware into a distribution platform using phishing and hijacked email threads to deliver TrickBot and ransomware.

    Entry
    Phishing attachments or links, including messages inserted into previously trusted email threads.
    Impact
    More than 1.6 million devices and hundreds of millions of dollars in damage, plus delivery of additional payloads.
    Technical dossier ↗
  6. 06
    2016 · Modular, multi-stage banking trojan

    TrickBot

    A flexible platform for credential theft, discovery, lateral movement and delivery of payloads such as Ryuk and Conti.

    Entry
    Spear phishing, spam, malvertising and exposed network weaknesses such as SMB.
    Impact
    Millions of infected devices, financial-information theft and staging for high-impact ransomware.
    Technical dossier ↗
  7. 07
    2018 · Enterprise-targeted ransomware

    Ryuk

    Often arrives after Emotet or TrickBot, surveys the network and attempts to remove backups before encrypting high-value systems.

    Entry
    A later-stage payload in a chain often beginning with a malicious email document and interactive network access.
    Impact
    Broad encryption, service disruption and attempts to destroy recovery paths, with thousands of victims worldwide.
    Technical dossier ↗
  8. 08
    2019 · Ransomware as a service

    LockBit

    An affiliate operation combining intrusion, data theft, encryption and publication pressure for extortion.

    Entry
    Phishing, public-facing application exploits, RDP, stolen accounts and brute force against VPN and RDP.
    Impact
    As of May 2024: more than 2,500 victims in at least 120 countries and payments exceeding $120 million.
    Technical dossier ↗
  9. 09
    2020 · Software supply-chain backdoor

    SUNBURST

    Inserted into signed, trusted SolarWinds Orion updates, giving stealthy access to government agencies and private organizations.

    Entry
    Compromise of the build system and insertion of code into Orion updates released between March and June 2020.
    Impact
    Covert access, credential theft, lateral movement and access to email and cloud environments.
    Technical dossier ↗
  10. 10
    2016+ · Highly targeted commercial spyware

    Pegasus

    Used against high-value phones through exploit links and zero-click chains to access communications, sensors and files.

    Entry
    Targeted exploit links and zero-day chains; later versions used zero-click paths such as FORCEDENTRY.
    Impact
    Access to camera, microphone, messages, files and sensitive data without the user's knowledge.
    Technical dossier ↗