Researchers from Proofpoint discovered a huge botnet dubbed Smominru (aka Ismo) that is using the EternalBlue exploit (CVE-2017-0144) to infect Windows computers and recruit them in Monero mining activities. The Smominru botnet has been active at least since May 2017 and has already infected more than 526,000 Windows computers. Most of the infected systems are servers distributed worldwide, most of them in Russia, India, and Taiwan.”]
Source: https://securityaffairs.co/wordpress/68494/malware/smominru-botnet.html

