The US government names North Korea as responsible for the WannaCry ransomware attack that hit globally this year.
Recently announced in a White House briefing, the US government’s latest statement officially blames North Korea for the attack. “We do not make this allegation lightly,” White House National Security Advisor Tom Bossert said. “It is based on evidence. We are not alone with our findings, either. Other governments and private companies agree. The United Kingdom attributes the attack to North Korea, and Microsoft traced the attack to cyber affiliates of the North Korean government.”
At time of publishing, North Korea still denies any association with the WannaCry attacks.
In response, McAfee’s Chief Technology Officer, Steve Grobman has this to say in response to the U.S. Government’s statement:
“The Administration is in a unique position to make this attribution assessment. Technical forensics alone cannot provide strong attribution to a threat’s origin. However, technical forensics combined with information from trusted intelligence or law enforcement agencies can improve confidence on the underlying actor behind a cyber-attack or campaign.
“WannaCry was an abnormal form of ransomware. It lacked a viable payment system essential to any effective ransomware campaign. This suggests that the attackers’ objective was less about extortion and more about disruption and destruction.
“Rather than jumping to conclusions based on an incomplete picture of the WannaCry attacks, the government has leveraged both technical and traditional data to take a responsible approach to attribution.”
The attack this year incapacitated many key operations across various sectors throughout the world, hitting hospitals, financial institutions, manufacturing plants etc. The malware took advantage of a vulnerability in older, unpatched versions of Microsoft, locking files on the machines and demands a ransom paid through bitcoin. The attack halted operations of businesses worldwide, costing hundreds of millions of dollars worth of damage. The attack affected at least 300,000 computers in 150 countries.
Initial reports and assessment attributed the attack to known North Korean cybercrime group Lazarus. The Lazarus Group has been attributed to various big scale attacks including the Sony Picture Entertainment hacks in 2014 that destroyed files and leaked corporate communications online, as well as the SWIFT banking attack in 2015 and 2016, where millions of dollars were stolen from banks with the hardest hit being Southeast Asia.




