austraveller2017-05-17 18:35:48

https://www.bleepingcomputer.com/news/security/3-security-firms-say-wannacry-ransomware-shares-code-with-north-korean-malware/

While initially, we thought this would be a silly and unsubstantiated discovery, the number of security firms claiming they've identified and confirmed connections between the WannaCry ransomware and malware used by the Lazarus Group has now gone up to three.

These somewhat crazy rumors started on Monday when Google security researcher Neel Mehta tweeted the MD5 hashes of two malware samples.

The hashes were for a sample of the WannaCry ransomware (early beta, released in February 2017) and the Contopee backdoor, previously attributed to the Lazarus Group.

If the name sounds familiar it's because this is the codename given to a group of hackers responsible for the Sony hack, the SWIFT bank attacks, and the hacks of various other financial institutions across the world. Experts believe the group is based on North Korea and associated with the official government, mainly because of its historical focus on attacking South Korean organizations and state agencies.

Links between WannaCry and Lazarus Group malware

Two days later after Mehta's tweet, security firms such as Kaspersky LabSymantec, and BAE Systems, have now put their full backing into claims that there might be a connection between North Korea's Lazarus Group and the WannaCry outbreak.

These companies make these connections based on some very skimpy claims, so they should not be taken as universal or conclusive proof that North Korea developed and released WannaCry.

According to the three companies, here are on what they base their claims on:

? 2015 Contopee backdoor sample and February 2017 WannaCry sample use an identical random buffer generator function
? Contopee and WannaCry were written in C++ and compiled using Visual Studio 6.0
? the usage of leet speak inside the code
qlVan2017-05-17 18:38:46
朝鲜有那种叫鸡算鸡网络的那种东西吗?
王伍2017-05-17 18:39:38
要说证据,弄点证据就这么难吗?瞧这:
houtou722017-05-17 18:56:25
开始忙着上浑水漆?前两天还说是老美的什么国家机构首先发现了什么程序的漏洞,一直没吱声。
和事佬2017-05-17 19:38:16
岂止是不吱声,是nsa开发了这次的勒索病毒
laoyu20102017-05-17 21:18:16
c+不就是汇编语言吗?80年代是计算机专业的必修课,怎么意思动汇编就算高科技,太low了吧
人在异乡为异客2017-05-17 21:35:01
越接近机器和底层的计算机语言,可以产生的破坏性越强,汇编语言恰好是这种情况。 :))
有才有财2017-05-17 21:44:32
搞笑。这都不懂就别胡扯八咧了