This page was machine-translated and may differ from the original. View original
Highly likely that the group behind the WannaCry ransomware attack is the same one that attacked Sony Pictures
Symantec Confirms Attack on Bangladesh Bank Was Brought About by Lazarus Group
Analysis of the code and infrastructure used in WannaCry confirmed a technical correlation.
Claims have been raised that the 'WannaCry ransomware,' which has recently spread globally, has a high correlation with the cyber attack group Lazarus.
Symantec (www.symantec.co.kr) has analyzed that, following a thorough investigation, the tools and infrastructure used in the WannaCry ransomware attack are significantly similar to the technology used by the Lazarus Group, which carried out the hacking of Sony Pictures and the theft of $81 million from the Central Bank of Bangladesh. Based on this, Symantec is convinced that the attack was carried out by the same group and therefore analyzes that the Lazarus Group is highly likely to be behind the WannaCry attack.
This company first discovered WannaCry on February 10, 2017, and at the time, more than 100 computers in the infected organization were infected within two minutes of the initial infection. According to Symantec's analysis, three of the five malware samples found in the attack were linked to the Lazarus Group.

Two of them were identified as variants of Backdoor.Destover used in the attack on Sony Pictures, and the other as Trojan.Volgmer, which the Lazarus Group used in the past when it carried out attacks targeting South Korea. Subsequently, in the second attack in late March where a new version of WannaCry was discovered, information was confirmed that further proved the connection between WannaCry and the attackers behind the Lazarus Group.
While the WannaCry ransomware in the first and second attacks contained malware traditionally used by the Lazarus Group, the third attack on May 12th deployed a more evolved version of WannaCry that incorporated the "EternalBlue" exploit, which utilized SMB vulnerabilities (CVE-2017-0144 and CVE-2017-0145) in the MS Windows operating system. The new version of WannaCry combined ransomware and a worm, spreading rapidly through networks and the internet, primarily targeting unpatched computers, and possessed destructive power as one of the most powerful malware discovered in recent years.
In addition to the similarities in the tools used to spread WannaCry, there are various connections between the WannaCry attack and Lazarus. WannaCry has been confirmed to share malware with Backdoor.Contopee, which was previously linked to Lazarus. In addition, WannaCry uses code obfuscation similar to Infostealer.Fakepude, a malware associated with Lazarus, and the Alphanc Trojan (Trojan.Alphanc) used to spread WannaCry in March and April is also linked to the Lazarus group.
Yoon Kwang-taek, CTO of Symantec Korea, explained, “Analysis of the WannaCry ransomware revealed a significant technical correlation between the code, infrastructure, and technology used and those employed by the Lazarus Group, which previously attacked Sony Pictures and the Bank of Bangladesh. Therefore, we believe the Lazarus Group is behind the WannaCry ransomware.” He added, “However, the WannaCry attack is analyzed as a typical cybercrime campaign carried out purely for financial gain, rather than for political retaliation or regime disruption as seen in past Lazarus Group attacks.”
Analysis of the code and infrastructure used in WannaCry confirmed a technical correlation.
Claims have been raised that the 'WannaCry ransomware,' which has recently spread globally, has a high correlation with the cyber attack group Lazarus.
Symantec (www.symantec.co.kr) has analyzed that, following a thorough investigation, the tools and infrastructure used in the WannaCry ransomware attack are significantly similar to the technology used by the Lazarus Group, which carried out the hacking of Sony Pictures and the theft of $81 million from the Central Bank of Bangladesh. Based on this, Symantec is convinced that the attack was carried out by the same group and therefore analyzes that the Lazarus Group is highly likely to be behind the WannaCry attack.
This company first discovered WannaCry on February 10, 2017, and at the time, more than 100 computers in the infected organization were infected within two minutes of the initial infection. According to Symantec's analysis, three of the five malware samples found in the attack were linked to the Lazarus Group.
Two of them were identified as variants of Backdoor.Destover used in the attack on Sony Pictures, and the other as Trojan.Volgmer, which the Lazarus Group used in the past when it carried out attacks targeting South Korea. Subsequently, in the second attack in late March where a new version of WannaCry was discovered, information was confirmed that further proved the connection between WannaCry and the attackers behind the Lazarus Group.
While the WannaCry ransomware in the first and second attacks contained malware traditionally used by the Lazarus Group, the third attack on May 12th deployed a more evolved version of WannaCry that incorporated the "EternalBlue" exploit, which utilized SMB vulnerabilities (CVE-2017-0144 and CVE-2017-0145) in the MS Windows operating system. The new version of WannaCry combined ransomware and a worm, spreading rapidly through networks and the internet, primarily targeting unpatched computers, and possessed destructive power as one of the most powerful malware discovered in recent years.
In addition to the similarities in the tools used to spread WannaCry, there are various connections between the WannaCry attack and Lazarus. WannaCry has been confirmed to share malware with Backdoor.Contopee, which was previously linked to Lazarus. In addition, WannaCry uses code obfuscation similar to Infostealer.Fakepude, a malware associated with Lazarus, and the Alphanc Trojan (Trojan.Alphanc) used to spread WannaCry in March and April is also linked to the Lazarus group.
Yoon Kwang-taek, CTO of Symantec Korea, explained, “Analysis of the WannaCry ransomware revealed a significant technical correlation between the code, infrastructure, and technology used and those employed by the Lazarus Group, which previously attacked Sony Pictures and the Bank of Bangladesh. Therefore, we believe the Lazarus Group is behind the WannaCry ransomware.” He added, “However, the WannaCry attack is analyzed as a typical cybercrime campaign carried out purely for financial gain, rather than for political retaliation or regime disruption as seen in past Lazarus Group attacks.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














