WannaCry Ransom Worm Creators Blamed for Two Previous Attacks
Security researchers say its highly likely hackers linked to North Korea were responsible for the recent widespread WannaCry ransomware attack. The same group, dubbed Lazarus, was previously blamed for two other high profile online attacks.
According to security firm Symantec, the WannaCry attacks bore five distinct hallmarks of previous attacks thought to be the work of the Lazarus group. This includes shared code such as that used to spread the malware from machine to machine. Other common factors include the same IP address being used to issue commands to infected machines, and similar techniques being used to try to disguise the malicious code.
The researchers also discovered that the same password was used to encrypt files and that only a few Bitcoin wallets (equivalent to an online account) were used to collect the ransom money. That suggests that unlike some malware, which is shared among cyber crime groups, WannaCry was the work of a single group of hackers.
Windows Bug Led To Worldwide Chaos
Symantec also confirmed that the key to the ransomware being so popular was due to a modified exploit derived from a known SMB vulnerability in Windows. It said this changed it "from a dangerous threat that could only be used in a limited number of targeted attacks to one of the most virulent strains of malware seen in recent years." More than 300,000 computers worldwide were affected by the attack. (Source: symantec.com)
The Lazarus group has previously been labeled responsible for two major attacks. One was on Sony in 2014, which stole personal data about tens of thousands of employees along with internal emails, some of which proved embarrassing. That attack was thought to be influenced by North Korea in response to a Sony movie accused of mocking the country's leadership in the movie "The Interview".
Lazarus was also blamed for an attack on the Bangladesh central bank last year that took more than $100 million through fraudulent online transactions.
Rogue Hacker Could Be Responsible
While both of those attacks had motivations that would be of interest to a government - namely politics and finance - the WannaCry attack sought the relatively "low" ransom of $300 from victims. Symantec says it doesn't believe a nation state was running WannaCry despite the connections to previous attacks. (Source: reuters.com)
One explanation could be that North Korea had simply encouraged those responsible to use WannaCry to cause disruption to other countries. Another is that the North Koreans had nothing to do with it and instead some 'rogue' Lazarus members were simply trying to make some money on the side.
What's Your Opinion?
Do you believe North Korea was behind the WannaCry attacks, either directly or indirectly? If so, should other countries retaliate? Should a cyber attack that compromises infrastructure such as hospital computer networks be treated in the same way as a physical attack?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.