Adylkuzz began exploiting a leaked NSA vulnerability several weeks before WannaCry began exploiting it. The malware relies on virtual private servers scanning the Internet on TCP port 445 for distribution. If infection proves successful, it enlists victims in a cryptocurrency-mining botnet. Researchers are concerned there are (and/or will be) others out there exploiting EternalBlue and DoublePulsar. The prospect of additional attack campaigns explains why Microsoft is fed up with governments stockpiling vulnerabilities, Microsoft says.”]
Source: https://grahamcluley.com/cryptocurrency-mining-malware-using-wannacrys-nsa-exploit-weeks/