SecPod

Learn Search

Search across all Learn content

← Back to Security Research
EternalRocks – The New and More Sophisticated ‘Doomsday’ Worm

EternalRocks – The New and More Sophisticated ‘Doomsday’ Worm

The Blackhats have created a new strain of malware that targets the same vulnerability as the WannaCry ransomware from the first week of May. However, these targeted vulnerabilities can be patched using auto patching.

May 22, 2017By Santosh Elumalai4 min read
ImageSource: Bleeping computers
ImageSource: Bleeping computers

The Blackhats have created a new strain of malware that targets the same vulnerability as the WannaCry ransomware from the first week of May. However, these targeted vulnerabilities can be patched using auto patching.

The Malware is called as EternalRocks, which uses the same flaw in Microsoft’s SMB networking protocol to infect other Windows systems that haven’t yet been patched with MS17-010. However, this new malware is far deadlier than WannaCry. Thus, Vulnerability Management solution can keep these attacks at bay.

WannaCry Ransomware created havoc and tensions around the globe in the first half of May 2017. However, this ransomware just used 2 NSA hacking Tools ETERNALBLUE to compromise a machine and DOUBLEPULSAR to move around the network to find its victim and infect. Hence, Vulnerability Management Tools can resolve these issues. Discovery of this new worm is spreading via SMB.

It uses 7 NSA hacking tools which are leaked by a mysterious group calling themselves Shadow Brokers:

  1. EternalBlue — SMBv1 exploit tool
  2. EternalRomance — SMBv1 exploit tool
  3. EternalChampion — SMBv2 exploit tool
  4. EternalSynergy — SMBv3 exploit tool
  5. SMBTouch — SMB reconnaissance tool
  6. ArchTouch — SMB reconnaissance tool
  7. DoublePulsar — Backdoor Trojan

ETERNALBLUE, ETERNAL CHAMPION, ETERNAL ROMANCE, and ETERNALSYNERGY, which are SMB exploits used to compromise vulnerable computers, while SMBTOUCH and ARCHITOUCH are two NSA tools used for SMB reconnaissance operations are used to scan for active SMB ports.

EternalRocks malware fakes itself as WannaCry to fool security researchers, but instead of dropping ransomware and encrypting the user files, it gains unauthorized control of the affected computer to launch future cyber attacks. The victim is always prey for attacks until the malware is found and taken required steps to eradicate such threats.

Now let’s see how the attack takes place

Infection of EternalRocks malware takes place in two stages.

In the first stage, malware entering a machine downloads necessary .NET components TaskScheduler and SharpZLib from the internet while droppingsvchost.exe and taskhost.exe. Component svchost.exe used for downloading, unpacking, and running Tor from archive.torproject.org along withC&C (ubgdgno5eswkhmpy.onion) communication requesting further instructions.

eternal rocks malware files
eternal rocks malware files

After infection, in the second stage, the malware taskhost.exe downloads after a predefined period (usually 24hrs) from http://ubgdgno5eswkhmpy.onion/updates/download?id=PC and execute. After initial execution, it drops a bunch ofexploits through shadowbrokers.zip and unpacks the directories payloads/, configs/, and bins/. It starts a random scan of opened 445 (SMB) ports on the internet while running contained exploits (available inside bins/) and pushing the first-stage malware through payloads (inside payloads/ – shown in the image below). Also, it expects running the Tor process from the first stage to get further instructions from C&C.

eternal rocks exploits inside payloads folder
eternal rocks exploits inside payloads folder

Once compromised with ETERNALROCKS the system can be used for any future attacks. It may cause damage beyond imagination. Saner will detect this threat easily.

Saner caught this malware with Indicators (as seen in the image below).

Viser eternal rocks indicator
Viser eternal rocks indicator

The threats are detected in Viser.

viser dashboard
viser dashboard

EternalRocks can be weaponized instantly. Because of its larger exploit arsenal, the lack of detection and remediation, and because of its initial inactive state, EternalRocks could pose a serious threat to computers with vulnerable SMB ports exposed to the Internet, if its author would ever decide to weaponize the worm with ransomware, a banking trojan, RATs, or anything else.

Few of the exploits used by the NSA Hacking tools are already fixed in older Microsoft Patch updates

Code Name Solution
“EternalBlue” Addressed by MS17-010
“EmeraldThread” Addressed by MS10-061
“EternalChampion” Addressed by CVE-2017-0146 & CVE-2017-0147
“ErraticGopher” Addressed prior to the release of Windows Vista
“EsikmoRoll” Addressed by MS14-068
“EternalRomance” Addressed by MS17-010
“EducatedScholar” Addressed by MS09-050
“EternalSynergy” Addressed by MS17-010
“EclipsedWing” Addressed by MS08-067

source: Microsoft

Easy remediation of these issues is possible via SecPod Saner. Install Saner to detect these type of threats and stay secure.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026