The terms 'WannaCry, Petya and EternalBlue' sometimes mentioned in the news recently are related to

Updated 11 Apr 2026 · From UPSC Prelims GS Paper I 2018, Q87

Contents18
UPSC Prelims GS2018Science and Technology
  1. AExoplanets
  2. BCryptocurrency
  3. CCyber attacks
  4. DMini satellites
Show answer

Answer: (C) Cyber attacks

Correct Answer: (c) Cyber attacks

WannaCry, Petya, and EternalBlue are all related to cyber attacks:

  • WannaCry: A massive ransomware attack in May 2017 that affected computers in over 150 countries. It encrypted people's files and demanded ransom in Bitcoin to unlock them. It mainly targeted computers running Microsoft Windows.

  • EternalBlue: A hacking tool/exploit originally developed by the US National Security Agency (NSA). It was leaked by a hacker group and was the vulnerability that WannaCry used to spread from computer to computer.

  • Petya (also called NotPetya): Another ransomware attack in June 2017 that also used the EternalBlue exploit. It initially targeted Ukraine but spread globally.

Why the other options are wrong:

  • Exoplanets = planets outside our solar system.

  • Cryptocurrency = digital currencies like Bitcoin.

  • Mini satellites = small satellites used for research.

REMEMBER: WannaCry and Petya = ransomware attacks. EternalBlue = the exploit/vulnerability they used. All three = cyber attacks in 2017. Ransomware = hackers lock your files and demand money to unlock them.

Why this was asked

WannaCry ransomware in May 2017 infected over 300,000 computers across 150+ countries in just a few days, making it one of the largest cyberattacks in history.

Both WannaCry and Petya used the EternalBlue exploit that was leaked from the US NSA, showing how government hacking tools can be weaponized by criminals.

UPSC is testing whether students can distinguish between different types of technology news - cyber threats versus space technology, cryptocurrency, or satellites.

WannaCry & Petya Ransomware Attacks

Science And Technology WannaCry Petya

WannaCry & Petya: The 2017 Global Ransomware Crisis

Must know

WannaCry (May 2017): Ransomware that hit 150+ countries, encrypted files and demanded Bitcoin ransom

Petya/NotPetya (June 2017): Ransomware that initially targeted Ukraine then spread globally

Both attacks used the EternalBlue exploit to spread rapidly across networks

Ransomware = malware that locks/encrypts files and demands payment to unlock them

What is Ransomware

Ransomware is malicious software that encrypts a victim's files, making them inaccessible. Hackers then demand payment (usually in cryptocurrency like Bitcoin) to provide the decryption key. The 2017 attacks were unprecedented in their global reach and speed of infection.

WannaCry vs Petya Comparison

Aspect

WannaCry

Petya/NotPetya

Date

May 2017

June 2017

Global Impact

150+ countries

Initially Ukraine, then global

Primary Targets

Microsoft Windows systems

Ukrainian infrastructure, then spread

Ransom Demand

$300-600 in Bitcoin

$300 in Bitcoin

Spread Method

EternalBlue exploit

EternalBlue + other methods

Notable Victims

UK's NHS, FedEx, Renault

Chernobyl nuclear facility, airports

Infection Scale

300,000+ computers

Thousands globally

Why These Attacks Were Devastating

Worm-like spread: Unlike typical ransomware, both could spread automatically across networks without user interaction

Critical infrastructure hit: Hospitals (NHS), power plants, airports, and government systems were affected

Attribution debates: Petya was suspected to be state-sponsored rather than purely criminal

Global wake-up call: Exposed how vulnerable interconnected systems are to cyber attacks

Question Context

UPSC tested these terms because the 2017 ransomware attacks were major international news events that highlighted cybersecurity vulnerabilities. The question tests awareness of current cyber threats, not technical details.

Exam traps

Trap: Petya sounds like a space-related term, but it's ransomware named after the antagonist in The Hunger Games

Trap: EternalBlue sounds futuristic/space-related, but it's an NSA hacking tool that was leaked

Confusion: Both attacks demanded Bitcoin ransom, but they are cyber attacks, not cryptocurrency developments

Memory aid: Cry in WannaCry = victims crying over locked files; Petya rhymes with beta (destructive software)

EternalBlue Exploit

Science And Technology EternalBlue

EternalBlue: The NSA Exploit That Enabled Global Cyber Attacks

Must know

EternalBlue = NSA hacking tool that exploited Windows SMB protocol vulnerability

Leaked by Shadow Brokers hacker group in April 2017

Used by both WannaCry and Petya to spread rapidly across networks

Good to know

Microsoft had patched the vulnerability in March 2017, but many systems remained unpatched

What is EternalBlue

EternalBlue is a cyberattack exploit developed by the US National Security Agency (NSA). It targets a vulnerability in Microsoft Windows' Server Message Block (SMB) protocol, allowing attackers to execute code remotely and spread across networks without user interaction.

How EternalBlue Works

%%{init: {"flowchart": {"wrappingWidth": 460}}}%%
flowchart TD
  s1["`**Target Identification**
Scans for Windows systems with **unpatched SMB vulnerability**`"]
  s2["`**Initial Infection**
Exploits SMB flaw to gain **remote code execution** on target system`"]
  s3["`**Lateral Movement**
Uses infected system to scan and attack **other systems on same network**`"]
  s4["`**Payload Delivery**
Installs ransomware (WannaCry/Petya) on newly infected systems`"]
  s5["`**Network Propagation**
Process repeats automatically, spreading **worm-like** across networks`"]
  s1 --> s2
  s2 --> s3
  s3 --> s4
  s4 --> s5

The Shadow Brokers Leak

Shadow Brokers: Mysterious hacker group that leaked NSA's hacking tools in 2016-2017

April 2017 leak: Released EternalBlue and other NSA exploits publicly on the internet

Global impact: Made sophisticated government-grade hacking tools available to criminals

Timeline problem: Microsoft patched the vulnerability in March 2017, but leak came in April 2017

Unpatched systems: Many organizations hadn't updated their systems, leaving them vulnerable

Exam traps

Trap: EternalBlue is NOT a ransomware itself — it's the exploit/vulnerability that ransomware used to spread

Confusion: NSA created EternalBlue for surveillance purposes, not to cause global damage

Key distinction: Exploit (EternalBlue) vs Malware (WannaCry/Petya) — don't mix them up

Ransomware & Cyber Attack Types

Science And Technology Cyber attacks

Understanding Ransomware & Modern Cyber Attack Methods

Must know

Ransomware = malware that encrypts files and demands payment for decryption key

Modern ransomware can spread automatically across networks like worms

Payment usually demanded in cryptocurrency (Bitcoin) for anonymity

Good to know

Cryptoworms like WannaCry combine ransomware with network propagation capabilities

Evolution of Ransomware

Traditional ransomware required users to click malicious links or download infected files. Modern cryptoworms like WannaCry changed the game by combining ransomware with network worm capabilities, allowing automatic spread without human interaction.

Major Cyber Attack Types

Attack Type

Method

Goal

Example

Ransomware

File encryption

Financial extortion

WannaCry, Petya

Phishing

Fake emails/websites

Steal credentials

Email scams

DDoS

Traffic flooding

Service disruption

Website crashes

APT

Long-term infiltration

Data theft/espionage

State-sponsored attacks

Cryptojacking

Unauthorized mining

Cryptocurrency theft

Browser-based mining

Zero-day

Unknown vulnerabilities

System compromise

EternalBlue exploit

Why Ransomware is Effective

Cryptocurrency payments: Bitcoin provides anonymity, making attackers hard to trace

Critical data targeting: Attacks focus on essential files (medical records, business data)

Time pressure: Ransom amounts often increase over time, creating urgency

Backup destruction: Advanced ransomware also targets backup systems

Social engineering: Combines technical attack with psychological pressure

India's Cybersecurity Context

CERT-In: India's Computer Emergency Response Team handles cyber incident response

IT Act 2000: Primary legislation governing cybercrime in India

National Cyber Security Strategy: Framework for protecting critical information infrastructure

Ransomware impact: Indian organizations also affected by global attacks like WannaCry

Cybersecurity Terms in UPSC

Science And Technology

Key Cybersecurity Concepts for UPSC Preparation

Must know

UPSC tests current cybersecurity events that make international headlines

Focus on impact and terminology rather than technical implementation details

Good to know

Attribution (who did the attack) often becomes a geopolitical issue

Cyber attacks can affect critical infrastructure and international relations

UPSC's Cybersecurity Focus

UPSC doesn't test technical cybersecurity details but focuses on awareness of major cyber events that impact global security, economy, or governance. The 2017 ransomware attacks were tested because they affected critical infrastructure worldwide and highlighted cyber vulnerabilities.

Common UPSC Cybersecurity Topics

Major cyber attacks: Global incidents like WannaCry, Stuxnet, Sony hack that make news

State-sponsored cyber warfare: Attacks attributed to nations for geopolitical purposes

Critical infrastructure attacks: Targeting power grids, hospitals, financial systems

Data breaches: Large-scale theft of personal/corporate data from major companies

Cryptocurrency and cybercrime: Bitcoin's role in ransom payments and dark web transactions

Cybersecurity Exam Coverage

# UPSC Cybersecurity Topics
## Major Incidents
- WannaCry 2017
- Stuxnet
- Sony Pictures Hack
- Equifax Breach
## Attack Types
- Ransomware
- Phishing
- DDoS
- APT
- Zero-day
## Geopolitical Angle
- State Sponsorship
- Cyber Warfare
- Attribution Disputes
- International Law
## India Context
- CERT-In
- IT Act 2000
- Digital India Security
- Critical Infrastructure
Exam traps

Trap: Don't confuse cyber attack names with unrelated terms (WannaCry ≠ space/crypto/satellite)

Pattern: UPSC often tests 2-3 year old major cyber incidents when they become 'settled' current affairs

Focus shift: Questions test awareness of events, not technical knowledge of how attacks work

Distractor strategy: Other options often include space, cryptocurrency, or technology terms to confuse