WannaCry, arguably the most popular and infamous malware of the year, affected over 200,000 computers in over a 100 countries. Check out my first post about it for more details about what it is.
Now it seems that researchers have found traces of who might have spread the ransomware. A Google researcher found that the WannaCry malware shares code with a 2015 malicious backdoor malware called Contopee. This backdoor was exploited by the Lazarus Group, which wiped almost a terabyte's worth of data from Sony Pictures and siphoned a reported $81 million from the Bangladesh Central Bank last year. Researchers say Lazarus Group carries out hacks on behalf of North Korea.
Researchers at Symantec also provided additional evidence that WannaCry was indeed the work of the Lazarus Group.
The evidence includes:
There similarities make a very strong case that the Lazarus Group was behind this attack, and therefore North Korea.
However, one must also keep in mind that simply sharing some similarities is not 100% proof that this attack was indeed launched by the Lazarus Group or North Korea. The strong evidence points towards that, but one must always keep an open mind as to who did it. It might have been someone who stole software and code from the Lazarus Group, or maybe the Lazarus Group got their code from a distributor who also supplies software to others.