Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The tool most closely associated with the Shadow Brokers’ April 2017 release is EternalBlue, an exploit targeting Windows’ SMB file-sharing service. Microsoft had released a security update addressing the vulnerabilities it used a month earlier. EternalBlue was not the same tool as DoublePulsar, a separate backdoor also found in the leak and later referenced in Microsoft’s account of the WannaCry ransomware attack.

Which tool did the Shadow Brokers release?

EternalBlue is the answer to the headline’s question. The Shadow Brokers published it in a collection of leaked hacking tools on April 14, 2017, according to CERT-EU. Microsoft identified EternalBlue among the tools addressed by its MS17-010 security update in its April 15, 2017 response.

EternalBlue was an exploit: code designed to take advantage of vulnerabilities in Windows’ Server Message Block (SMB) service. That service supports functions such as file and printer sharing. A vulnerable, unpatched system exposed to the exploit could be compromised through specially crafted SMB traffic. It was not a tool that affected every Windows PC automatically; the relevant Windows version, patch status, and network exposure mattered.

How EternalBlue and DoublePulsar differed

Tool Role Connection to WannaCry
EternalBlue An SMB exploit that targeted vulnerable Windows systems. Microsoft said WannaCry used EternalBlue code against unpatched SMBv1 systems.
DoublePulsar A separate backdoor capable of injecting and running code, as described by NHS England Digital. Microsoft said WannaCry’s kernel-level shellcode appeared to be copied from the publicly available DoublePulsar backdoor, with modifications.

The distinction matters: EternalBlue helped exploit a vulnerable system; DoublePulsar was a separate backdoor. They appeared in the same leaked tool set, but the names are not interchangeable. Microsoft’s account of WannaCry describes the relationship between the two in its May 12, 2017 analysis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How the patch and public release lined up

  1. March 14, 2017: Microsoft released MS17-010 to address the relevant SMB vulnerabilities. Microsoft’s WannaCry analysis and CERT-EU advisory give this date.
  2. April 14, 2017: CERT-EU dates the Shadow Brokers’ public release containing EternalBlue to this day.
  3. April 15, 2017: Microsoft publicly mapped EternalBlue, along with EternalChampion, EternalRomance, and EternalSynergy, to fixes in MS17-010. Its MSRC statement said the company had triaged the release.
  4. May 12, 2017: Microsoft reported that WannaCry used EternalBlue code against unpatched SMBv1 systems. It said the initial route of infection had not been confirmed: both social-engineering email and direct exploitation of reachable, unpatched computers were considered possible.

The sequence explains why the leak was dangerous without implying that every computer was still exposed: a fix existed before EternalBlue became public, but systems that had not installed it remained at risk if they were affected and reachable.

What EternalBlue had to do with WannaCry

Microsoft said WannaCry used EternalBlue code to attack unpatched systems running SMBv1. Its analysis describes the exploit triggering against a targeted SMBv1 server with a specially crafted packet and the ransomware spreading worm-like among vulnerable machines. Microsoft also said WannaCry’s shellcode appeared adapted from DoublePulsar. In other words, EternalBlue was part of the exploitation and spread mechanism; DoublePulsar was a separate source of code associated with the attack’s execution chain.

Rank #2
Kensington Upgraded VeriMark Desktop 2.0 USB Fingerprint Reader Supports USB-C and USB-A - Windows Hello with ESS, Windows 11 Fingerprint Scanner for PC, FIDO U2F, FIDO2, TAA Compliant (K64741WW)
  • Certified to Microsoft’s highest fingerprint security standards (ESS & SDCP) for robust, hardware-isolated authentication. Supports next-gen Windows features, including Copilot Recall and Windows Hello with ESS support.
  • Windows Hello ready for fast, password free fingerprint login to Windows and Microsoft 365 accounts
  • On device fingerprint storage keeps biometric data securely within the key. Supports privacy regulations (GDPR, BIPA, CCPA) through on device biometric processing; TAA compliant.
  • Reliable wired USB fingerprint authentication with USB C and USB A compatibility for desktop PCs.
  • Consistent, all condition 360° fingerprint recognition.

CERT-EU reported that more than 200,000 computers worldwide were affected during the May 2017 WannaCry campaign. That is a contemporaneous estimate for that outbreak, not a current count of vulnerable or infected computers.

Were the leaked tools definitely taken from the NSA?

NHS England Digital describes the tools as “reportedly obtained from the NSA.” This supports the cautious description that the tools were reportedly linked to or obtained from the NSA; it does not establish who took them or provide a definitive chain of custody. Microsoft’s public statements identify the tools and the fixes associated with them, but do not resolve those attribution questions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GoTrust Idem Key C USB Security Key NFC FIDO2 L2 Certified
  • Protect accounts with USB-C & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
  • FIDO2 Level 2 certified Security Key. Works with Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Compatible with Chrome, Safari & Edge on all major OS.
  • Plug & play USB-C Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
  • Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication & identity protection.
  • IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise & daily use.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the historical guidance said about protection

In its May 2017 WannaCry response, Microsoft advised installing MS17-010. For systems that could not yet be patched, it recommended disabling SMBv1 or blocking incoming SMB traffic on port 445 to reduce exposure. These are historical recommendations tied to that incident. For current systems, follow the relevant vendor’s up-to-date security guidance rather than treating a 2017 workaround as a complete present-day security plan.

Microsoft’s MSRC lead Phillip Misner wrote in the April 15, 2017 post: “We have long supported coordinated vulnerability disclosure as the most effective means to ensure customers and the computing ecosystem remains protected.”

Best Value
Sale
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
Rank #4
Yoidesu USB Fingerprint Reader for Windows Hello, Plug & Play Security Key
  • Windows Hello for Windows 10/11 - Only works with Windows Hello on Windows 10/11 PCs and laptops. Plug the USB fingerprint reader into your computer and sign in with one touch. Not compatible with Mac, macOS, Linux or Chrome OS.
  • Plug-and-Play Fingerprint Login - No extra app is needed on most genuine Windows systems. Insert the USB fingerprint scanner, set up fingerprint sign-in through Windows Hello, and unlock your PC without typing long passwords every time.
  • Fast 0.5s 360° Recognition - Capacitive fingerprint technology supports quick authentication in about 0.5 seconds. 360° touch recognition helps read your fingerprint from different angles for faster, smoother daily login.
  • Compact Scanner for PC & Laptop + Multi-User Support - Small, lightweight USB design works well for desktops, laptops, office PCs and shared home computers without built-in fingerprint sensors. Supports multiple Windows accounts and up to 10 fingerprints per user account. Smart-ID security helps protect saved passwords and encrypted folders with fingerprint access.
  • Important Notes — Please Read Before Purchase - Support for Win10/11 32/64 bit original system. Not fit for the streamlined version. The Lite version has trimmed the biometric component, the fingerprint login device will not be able to recognize the Hello fingerprint option.It merely supports Windows Hello, does not fit for encrypting USB drives/files, and can merely support Windows system.It is recommended to prioritize plugging into the USB 2.0 interface of the motherboard. USB 3.0 docking stations are prone to power supply/interference and unstable recognition.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.