D
Deleted member 178
Thread author
zoltan from MRG lab said:The video I sent shows that ETERNALBLUE exploit is successful, it can install the DOUBLEPULSAR backdoor. DOUBLEPULSAR can install the PEDDLECHEAP malware payload. Some functionality of PEDDLECHEAP works, some not. E.g. one cannot start a command shell. But one can steal password hashes as far as I remember. And clearly it can steal information from the system. If the NSA is hacking someone with ETERNALBLUE/DOUBLEPULSAR/PEDDLECHEAP where VS installed, they will come up with a way to shutdown VS easily. I had no time to demonstrate this, but it is possible.[
Same happened when VS was configured for white-list mode.
WannaCry Exploit Could Infect Windows 10