
MKT—KSA / 05
Malware dossiers
Documented technical dossiers covering entry, propagation, targets, impact and defensive action.
- 012017 · Ransomware with a network-worm component
WannaCry
Spread automatically through unpatched Windows systems by exploiting SMBv1, causing worldwide disruption across healthcare and essential services.
- Entry
- Exploitation of SMBv1 flaws addressed by MS17-010; network propagation does not require user interaction.
- Impact
- More than 200,000 devices across over 100 countries; thousands of UK health appointments and procedures were cancelled.
- 022017 · Destructive disk wiper disguised as ransomware
NotPetya
Entered through a compromised M.E.Doc update, then moved through networks using SMB and credentials, producing worldwide disruption.
- Entry
- A compromised software supply chain followed by internal propagation through SMB, administrative tools and stolen credentials.
- Impact
- Irrecoverable encryption and global losses in the billions; three documented victims alone lost nearly one billion dollars.
- 032010 · Industrial-control sabotage worm
Stuxnet
Targeted Siemens WinCC, STEP 7 and PLC environments, altering industrial behavior while concealing true process readings.
- Entry
- Initial access remains unresolved; documented propagation included USB, network shares, STEP 7 files and a print-spooler flaw.
- Impact
- Manipulated control commands, damaged centrifuge equipment and displayed misleading operating data.
- 042012 · Destructive workstation wiper
Shamoon / Disttrack
Collected system information and deployed a wiping module that overwrote boot records, partition tables and files, driving major operational disruption.
- Entry
- The initial entry vector was not officially determined; after compromise it propagated through network shares.
- Impact
- Unrecoverable data after wiping and disruption across a large part of a business network.
- 052014 · Trojan, botnet and malware loader
Emotet
Evolved from banking malware into a distribution platform using phishing and hijacked email threads to deliver TrickBot and ransomware.
- Entry
- Phishing attachments or links, including messages inserted into previously trusted email threads.
- Impact
- More than 1.6 million devices and hundreds of millions of dollars in damage, plus delivery of additional payloads.
- 062016 · Modular, multi-stage banking trojan
TrickBot
A flexible platform for credential theft, discovery, lateral movement and delivery of payloads such as Ryuk and Conti.
- Entry
- Spear phishing, spam, malvertising and exposed network weaknesses such as SMB.
- Impact
- Millions of infected devices, financial-information theft and staging for high-impact ransomware.
- 072018 · Enterprise-targeted ransomware
Ryuk
Often arrives after Emotet or TrickBot, surveys the network and attempts to remove backups before encrypting high-value systems.
- Entry
- A later-stage payload in a chain often beginning with a malicious email document and interactive network access.
- Impact
- Broad encryption, service disruption and attempts to destroy recovery paths, with thousands of victims worldwide.
- 082019 · Ransomware as a service
LockBit
An affiliate operation combining intrusion, data theft, encryption and publication pressure for extortion.
- Entry
- Phishing, public-facing application exploits, RDP, stolen accounts and brute force against VPN and RDP.
- Impact
- As of May 2024: more than 2,500 victims in at least 120 countries and payments exceeding $120 million.
- 092020 · Software supply-chain backdoor
SUNBURST
Inserted into signed, trusted SolarWinds Orion updates, giving stealthy access to government agencies and private organizations.
- Entry
- Compromise of the build system and insertion of code into Orion updates released between March and June 2020.
- Impact
- Covert access, credential theft, lateral movement and access to email and cloud environments.
- 102016+ · Highly targeted commercial spyware
Pegasus
Used against high-value phones through exploit links and zero-click chains to access communications, sensors and files.
- Entry
- Targeted exploit links and zero-day chains; later versions used zero-click paths such as FORCEDENTRY.
- Impact
- Access to camera, microphone, messages, files and sensitive data without the user's knowledge.