← Articles
RIPOSTE research · 2026

From Nation-State to Commodity: What Actually Happened to Five Cyber Weapons

When a nation-state builds a new cyber weapon, the instinctive fear is that it is only a matter of time before everyone has it — that today's classified capability is tomorrow's script-kiddie tool. It is a reasonable fear, and it is sometimes exactly right. But not always, and the difference is not random. Here are five real cases, tracked from where they started to where they ended up, that show both outcomes — and what decides which one you get.

The pattern, in one line

Proliferation is real but bounded. When the only thing standing between an elite capability and the commodity market is knowledge — how it works — it tends to collapse to commodity fast, because knowledge cannot be un-published. When something else stays scarce — money, physical access, deep expertise, the organisation to operate it — the capability can stay out of reach for years, even after it has been dissected in public. An attacker is gated by its scarcest input, not its most famous one. The five cases below are the clearest illustrations of that.

EternalBlue — nation-state to teenager in a year

EternalBlue was an exploit built by the NSA's Equation Group against a flaw in Windows file-sharing. In April 2017 a group calling itself the Shadow Brokers leaked it publicly. Within weeks it was powering WannaCry, which hit an estimated 200,000 machines across 150 countries in a single May weekend; a month later it drove NotPetya. Within the year it had been folded into commodity cryptominers run by actors who could never have built it. The only barrier had ever been knowledge, and once that was gone, so was the barrier. Any risk model still treating this as an elite-only capability is telling people they are safe from something a novice can run.

Log4Shell — commodity in hours

If EternalBlue is the year-long slide, Log4Shell is the lower bound. Disclosed in December 2021, this flaw in the ubiquitous Log4j logging library was trivially exploitable and present in an enormous share of the world's software. It went from disclosure to mass, commodity exploitation in hours, not months — CISA and its international partners scrambled to respond to what became one of the most widespread vulnerabilities on record. It is what “no barrier at all” looks like: trivial to use, everywhere, and instantly in everyone's hands.

Mimikatz — commoditised, and still deadly

Mimikatz began in 2011 as genuinely specialist credential-theft tradecraft. Today it is in virtually every commodity attacker's playbook, and has been for years — it was a component of NotPetya. It illustrates a point people miss: commoditisation does not mean obsolescence. Fifteen years on, Mimikatz-style credential theft still works and is still everywhere, because the underlying weakness it targets persists. A capability that has proliferated all the way to commodity is not a lesser threat for being common — often the opposite.

FORCEDENTRY — published in full, still never reproduced

Now the other outcome. FORCEDENTRY was a zero-click iMessage exploit used by the spyware vendor NSO Group — so sophisticated that, as the researchers who dismantled it put it, it effectively built a small virtual computer inside an image-parsing routine. It was captured and documented in forensic detail by Citizen Lab, and Google's Project Zero published a complete technical teardown. By the logic of “once it's public, everyone has it,” it should have proliferated. It has not — not to any lower-tier actor, years later. The barrier was never knowledge; it was the ability to build tradecraft at that level, which reading a teardown does not confer. Deep expertise is a gate publication cannot open.

Stuxnet — both outcomes, in a single weapon

Stuxnet — the US/Israeli operation that sabotaged Iranian uranium enrichment around 2010 — is the most-analysed malware in history, and it settles the argument, because it contains both outcomes at once. One component, a Windows shortcut zero-day, was extracted and commoditised within weeks and ended up in off-the-shelf hacking tools. The other component — the payload that actually reprogrammed industrial control systems to wreck centrifuges — has never proliferated at all, because it required physical access to an air-gapped facility and control-systems engineering expertise that no commodity actor has. Same operation, opposite fates. Proliferation happens per-component, not per-weapon — and it stops wherever a scarce input stands in the way.

What this means for you

The lesson is not that you can ignore cyber weapons — EternalBlue, Log4Shell and Mimikatz are proof of how fast and how far the commodity end of the spectrum moves, and defending against it is the daily work of security. The lesson is that “it exists somewhere” is not the same as “it will reach you.” A capability gated behind resources, access or expertise your realistic adversary does not have is not your risk, however frightening the headline. Working out which capabilities can actually reach an organisation like yours — and keeping that judgement current as the line moves — is exactly what proportionate, intelligence-led security is for, and what our DarkRose intelligence is built to do.

Sources

  1. Indicators Associated With WannaCry Ransomware — CISA (May 2017)
  2. Microsoft Security Bulletin MS17-010 (EternalBlue / SMBv1)
  3. Apache Log4j (Log4Shell) Vulnerability Guidance — CISA
  4. FORCEDENTRY: NSO Group iMessage Zero-Click Exploit Captured in the Wild — The Citizen Lab
  5. A deep dive into an NSO zero-click iMessage exploit — Google Project Zero
  6. W32.Stuxnet Dossier — Symantec (Falliere, O'Murchu, Chien)
About the author

Cameron McCollum — Director & Founder, RIPOSTE. He spent two decades in Australian Army intelligence — serving as Head of Intelligence on operations across the Asia-Pacific and Afghanistan — before building and leading the cyber-risk program at Lexon Insurance. He holds Master's degrees in Cyber Security Operations and Business (UNSW) and is an ISO/IEC 27001 Lead Implementer.

RIPOSTE helps organisations turn analysis like this into action.

Talk to us