WannaCry didn’t just vanish because someone hit a magic antivirus button. It slowed down because of one strange detail buried in the malware, then security teams scrambled to patch vulnerable Windows machines before things got worse.
The biggest moment landed on May 12, 2017. A researcher known online as MalwareTech noticed WannaCry was trying to reach a long, randomly named web domain. Connection succeeded, the malware stopped. Connection failed, it kept spreading.
The Kill Switch That Nobody Expected
MalwareTech registered that domain, not trying to shut down the whole attack at first, just curious what it actually did. Then infections started slowing fast, since infected machines could now reach the domain and trigger the malware’s built-in stop condition. US cybersecurity officials later confirmed that switch is what stopped the spread.
Why the Kill Switch Worked
The trick sat inside WannaCry itself, before encrypting files and continuing to spread, the malware checked whether that odd domain was reachable. Connection worked, it stopped.
That design choice mattered enormously. But it didn’t fix infected computers, didn’t decrypt anything, didn’t make vulnerable machines safe either. It just interrupted the specific version of WannaCry carrying that check.
Microsoft Had Already Released the Fix
Here’s the part that matters more for long term security. Microsoft released a patch back on March 14, 2017, almost two months before WannaCry exploded. That update fixed the SMB vulnerability WannaCry abused to jump between machines. Computers that had installed it were already protected.
Microsoft also did something unusual, released updates for older systems normally outside mainstream support, Windows XP included, giving organizations another way to close the hole even after the outbreak had already started.
Patching Slowed the Next Wave
After the kill switch disrupted the original strain, there was still plenty of work left. The patch closed the vulnerable SMB hole, antivirus detection caught up quickly, and network teams cut exposure by blocking SMB traffic on port 445 while waiting to patch everything.
That combination is what actually mattered, the kill switch slowed the immediate outbreak, patching and other defenses made it harder for the malware to keep finding fresh targets.
Was WannaCry Completely Stopped?
Not exactly. Other variants showed up after the original outbreak, and the underlying vulnerability stayed a problem for anything that hadn’t been updated. So the famous “kill switch” story gets a little misleading if you picture one person pressing a button and ending everything. More like someone found a loose thread, pulled it, and the runaway part of the attack stumbled. Then thousands of defenders had to keep working anyway.