At least 3 different groups have been leveraging the NSA EternalBlue exploit weeks before the WannaCry attacks, heres the evidence. Security experts at Cyphort found evidence on a honeypot server that threat actors in the wild were already exploiting the SMB flaw in early May to deliver a stealth Remote Access Trojan (RAT) instead of ransomware. The malware is delivered from an IP (182.18.23.38) located in China. The malicious code attempts to delete a number of users and terminate and/or delete various files or processes.”]
Source: http://securityaffairs.co/wordpress/59331/malware/eternalblue-exploit.html