Symantec and FireEye have linked the recent WannaCry ransomware attacks to North Korea:
Cybersecurity researchers at Symantec Corp. and FireEye Inc. have uncovered more evidence tying this month's WannaCry global ransomware attacks to North Korea.
The cyberattack that infected hundreds of thousands of computers worldwide was "highly likely" to have originated with Lazarus, a hacking group linked to the reclusive state, Symantec said. The software used was virtually identical to versions employed in attacks earlier this year attributed to the same agency, the company said in a report late Monday. FireEye on Tuesday agreed WannaCry shared unique code with malware previously linked to North Korea. "The shared code likely means that, at a minimum, WannaCry operators share software development resources with North Korean espionage operators," Ben Read, a FireEye analyst, said in an emailed statement.
[...] The initial attack was stifled when a security researcher disabled a key mechanism used by the worm to spread, but experts said the hackers were likely to mount a second attack because so many users of personal computers with Microsoft operating systems couldn't or didn't download a security patch released in March labeled "critical."
Also at NYT, Reuters, Ars Technica, and The Hill. Symantec blog (appears scriptwalled).
Here's a screenshot of Wana Decrypt0r 2.0. Note the Wikipedia licensing section.
Previously: Security In 2017: Ransomware Will Remain King
"Biggest Ransomware Attack in History" Hits Around 100 Countries, Disrupts UK's NHS
WannaCrypt Ransomware Variant -- Lacking Kill Switch -- Seen in Wild [Updated]
Decryption Utility for WannaCry is Released
(Score: 0) by Anonymous Coward on Tuesday May 23 2017, @11:37PM (3 children)
That thing had the most impact in Russia, a supposed Nork's ally.
(Score: 3, Funny) by takyon on Tuesday May 23 2017, @11:41PM (1 child)
Their Bitcoins are as good as anybody's :D
[SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
(Score: 0) by Anonymous Coward on Wednesday May 24 2017, @12:14AM
I can just imagine the Rusky cybergoons chuckling:
"Damn, gooks, yous pulled a doozy. Give it up - high five!"
(Score: 2) by Jeremiah Cornelius on Wednesday May 24 2017, @03:19PM
Yeah. The attribution method is dubious. It contains more NSA code than NK code. This was cobbled together from available parts.
Symantec is done, as a trustworthy analyst. Bluecoat aquired them and went private. They peddle for various big gov customers. It's a shame, really.
You're betting on the pantomime horse...
(Score: 5, Insightful) by Gaaark on Tuesday May 23 2017, @11:45PM (5 children)
What... is North Korea the American bad guy now, or is Russia? China??
Or was Symantec told to take America's eyes/entertainment lobes off of Russia and put it back onto North Korea???
Man, it's so hard to stay focused on who the bad guy is anymo---
--oooh, look! Kardashians! Heee heee, soooo shiny!!!
--- Please remind me if I haven't been civil to you: I'm channeling MDC. ---Gaaark 2.0 ---
(Score: 4, Insightful) by takyon on Tuesday May 23 2017, @11:48PM (2 children)
The world's superpower can have multiple enemies???!
[SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
(Score: 2) by Gaaark on Wednesday May 24 2017, @12:33AM (1 child)
No: you need to focus the plebs on one enemy at a time! Hence the Jews in Nazi-land... "It's a small Jew world after all, it's a small Jew world uber alles"
It's like marketing: one message hammered home again and again. It's the Jews, or it's the Russians or it's the Chinese, but NEVER all at the same time!
--Yes, this is all sarcasm/joke--
--- Please remind me if I haven't been civil to you: I'm channeling MDC. ---Gaaark 2.0 ---
(Score: 0) by Anonymous Coward on Wednesday May 24 2017, @07:50AM
in their hate, thanks to World 2.0 and the dramatic changes it has offered through digital content production values, Humans v2.0 can now be multi-minded in their ability to hate others! No longer must a single organization, group, race, gender, or religion be hated upon by them, but rather all can be hated upon with the full power of Humans v2.0 via their unique new Time-sharing Hate System (THS (TM)).
Thanks to this unique system, brought about in part by research and development done through years upon years of painstaking R&D and refinements from visits to the Player Hater's Ball, KKK meetings, and Fundamental Synagogues, Churches, and Mosques, we have finally managed to produce people who can multi-facet their hate, providing the full power of their hate at any victim at any time provided a sufficient slice of time.
(Score: 5, Insightful) by kaszz on Tuesday May 23 2017, @11:50PM
Symantec - Mountain View, California, USA
FireEye - Milpitas, California, USA
Add some special letter soup letter.
And you get whatever the master says! :-)
Do I need to say more? :p
(Score: 3, Insightful) by butthurt on Wednesday May 24 2017, @12:59AM
"Oceania was at war with Eastasia. Eurasia was an ally."
(Score: -1, Offtopic) by Anonymous Coward on Tuesday May 23 2017, @11:46PM (4 children)
Unless you've had dealings with these slanteyed godless fucks, you have no idea
just how different they are from decent western people.
The US should have destroyed China, Korea, and all the rest of the hordes of
dog-eating yellow people, while it was possible to do so without nuclear retaliation.
(Score: 3, Insightful) by butthurt on Wednesday May 24 2017, @01:09AM (3 children)
Your wish nearly came true:
-- https://en.wikipedia.org/wiki/Korean_War [wikipedia.org]
--
http://www.airspacemag.com/military-aviation/how-korean-war-almost-went-nuclear-180955324/ [airspacemag.com]
(Score: 3, Informative) by Jeremiah Cornelius on Wednesday May 24 2017, @04:09PM (2 children)
Conventional bombing and incendiaries - under the direction of Curtis LeMay - wiped out 20% of the civilian population of the Korean peninsula. This is a war crime, unfortunately not without parallel, but still in the greatest order of magnitude. The USA is no better than Stalin's USSR in this regard, other than ideological justification for the extermination of tens of millions of innocents.
LeMay, you may note, was responsible for the incineration of the cultural, non-military targets of Dresden and Kyoto. The former made famous by Kurt Vonnegut in "Slaughterhouse 5". LeMay was the great villain of that novel, and portrayed accurately as unrepentant. His airwar was more reprehensible and criminal than Goering's. Yet he never saw a Nuremburg-style prosecution.
When you see a US or UK flag, the proper response should be abject disgust.
You're betting on the pantomime horse...
(Score: 2) by butthurt on Wednesday May 24 2017, @04:23PM (1 child)
You may be thinking of Tokyo.
https://en.wikipedia.org/wiki/Bombing_of_Tokyo_in_World_War_II [wikipedia.org]
Kyoto was considered as an A-bomb recipient but lost out.
https://www.quora.com/Is-it-true-that-Kyoto-Japan-was-nearly-bombed-in-WWII [quora.com]
(Score: 2) by Jeremiah Cornelius on Wednesday May 24 2017, @04:53PM
Yes, you're right. Tokyo. And Ira C Whittaker was LeMay's strategist, responsible for targets and methods in WWI.
You're betting on the pantomime horse...
(Score: 2) by Grishnakh on Wednesday May 24 2017, @03:22AM
This is what people get for using Windows for their critical data.
(Score: 0) by Anonymous Coward on Wednesday May 24 2017, @04:09AM (2 children)
I'm surprised there's not more scrutiny over this sort of incredibly lazy security "analysis" here. False attribution is a regular part of any sort of digital criminal activity. What these "analysts" and the 'it's the Russkies!' crew before them are doing fundamentally comes down to "He said It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness, it was the epoch of belief, it was the epoch of incredulity... therefore it must be Charles Dickens." Oh... he's dead? Oh dear... Well I guess it's POSSIBLE somebody else might have somehow gotten access to his words. Seriously, it's like all you have to do is to keep some string values in Korean and that's enough for these "security experts" to brilliantly declare it must be North Korea.
There's also this constant self contradiction that nobody seems to pick up on. On the one hand the software is often described as sophisticated clearly indicative of a state level entity. And then you have things like them storing a 'kill switch' domain name in plain text in this case or similarly completely amateur issues in former malware or hacks attributed to state level entities.
(Score: 0) by Anonymous Coward on Wednesday May 24 2017, @04:17AM (1 child)
Reminds me of CNN's "security analyst" discussing, Who is this hacker known as 4chan? [youtube.com] "He may have been just a systems administrator who knew his way around and how to hack things."
(Score: 0) by Anonymous Coward on Wednesday May 24 2017, @06:16PM
Its still unbelievable to me that these organizations tried to push a "fake news" meme.
(Score: 1, Insightful) by Anonymous Coward on Wednesday May 24 2017, @08:30AM (2 children)
The dangerous parts were leaked from the NSA. The NSA needed something to "prove" that leaking their exploits helps the enemy rather than helping fixing our own security. What better way than a false flag operation, creating some shoddily written malware that infects a lot of computers.
I expected them to blame Russia (like the recent election), but North Korea makes it even more obvious that it was a false flag operation.
Does anyone here actually believe that malware attacking Windows could come out of a country where computers (all three of them) were invented by Kim Jong Un. As far as I know, Microsoft never ported Windows to Kim Jong Un hardware.
(Score: 0) by Anonymous Coward on Wednesday May 24 2017, @10:39AM
actually, this is not that unbelievable.
the bit with the movie a couple of years ago was just plain stupid, and I doubt North Korea was actually involved, but I do believe the North Koreans would be capable of extortion/"data kidnapping" or whatever you want to call it.
they definitely need the cash, and they have enough resources to develop the capability.
and they don't really have anything to lose.
(Score: 0) by Anonymous Coward on Wednesday May 24 2017, @04:33PM
The elites have cell phones and computers. It's shocking how little americans know about north korea. Which absolutely is a massive threat and who we will probably go to war with.
The irony is that the people first to say "well we don't know what's REALLY going on over there" over and over in an effort to look deep and woke also make the least effort to educate themselves. You could easily google information on north korea and you could just as easily talk to chinese who live on that border to verify such information is correct.
(Score: 2) by sjames on Wednesday May 24 2017, @11:37PM
So, what they're saying is the NSA flubbed so badly that they ended up helping (however inadvertently) the world's biggest kook attack the U.S. and others? Pretty much the opposite of their mission? Short of stubbing a cigar out on the big red button, could they screw up any worse?