A security expert discovered a new worm, dubbed EternalRocks, that exploits the EternalBlue flaw in the SMB protocol to spread itself like the popular WannaCry ransomware. Miroslav Stampar, a member of the Croatian Government CERT, discovered the worm after it infected his SMB honeypot. He called the malware DoomsDayWorm The worm uses seven NSA exploits leaked by the Shadow Brokers and its code doesnt include a kill-switch. The worm works in two stages: download the Tor web browser on the affected computers, connect to a C&C server located on the Tor network.”]
Source: http://securityaffairs.co/wordpress/59355/malware/eternalrocks-malware.html