In this 2015 photo, Stijn Vanveerdeghem (left), an engineer with Cisco, shows graphics with live wireless traffic to FedEx employee Barry Poole during the RSA Conference in San Francisco, where threat analysts, security vendors and corporate IT administrators gathered to talk about malicious software, spear-phishing and other attacks that can steal money or secrets from companies and consumers. (AP Photo/Marcio Jose Sanchez, File)

In this 2015 photo, Stijn Vanveerdeghem (left), an engineer with Cisco, shows graphics with live wireless traffic to FedEx employee Barry Poole during the RSA Conference in San Francisco, where threat analysts, security vendors and corporate IT administrators gathered to talk about malicious software, spear-phishing and other attacks that can steal money or secrets from companies and consumers. (AP Photo/Marcio Jose Sanchez, File)

Experts see possible North Korea links to global cyberattack

By YOUKYUNG LEE / Associated Press

SEOUL, South Korea — Cybersecurity experts are pointing to circumstantial evidence that North Korea may be behind the global “ransomware” attack: the way the hackers took hostage computers and servers across the world was similar to previous cyberattacks attributed to North Korea.

Simon Choi, a director at South Korean anti-virus software company Hauri Inc. who has analyzed North Korean malware since 2008 and advises the government, said Tuesday that the North is no newcomer to the world of bitcoins. It has been mining the digital currency using malicious computer programs since as early as 2013, he said.

In the attack, hackers demand payment from victims in bitcoins to regain access to their encrypted computers. The malware has scrambled data at hospitals, factories, government agencies, banks and other businesses since Friday, but an expected second-wave outbreak largely failed to materialize after the weekend, in part because security researchers had already defanged it .

Choi is one of a number of researchers around the world who have suggested a possible link between the “ransomware” known as WannaCry and hackers linked to North Korea. Researchers at Symantec and Kaspersky Lab have found similarities between WannaCry and previous attacks blamed on North Korea.

The evidence is still far from conclusive, however. Authorities are working to catch the extortionists behind the global cyberattack, searching for digital clues and following the money.

“We are talking about a possibility, not that this was done by North Korea,” Choi said.

HOW IT WORKED

WannaCry paralyzed computers running mostly older versions of Microsoft Windows in some 150 countries. It encrypted users’ computer files and displayed a message demanding $300 to $600 worth of the digital currency bitcoin to release them; failure to pay would leave the data scrambled and likely beyond repair .

The hackers appeared to have taken control of computers and servers around the world by sending a type of malicious code known as a worm. The worms quickly scanned computers with vulnerability, in this case the older versions of Microsoft Windows, and used those computers as hackers’ command and control centers.

Experts say that the rapid spread of the worm globally suggests it did not rely on phishing, a method whereby an email is sent to people with the aim of having them click on infected documents or links.

Rather, analysts at the European Union cybersecurity agency say the hackers likely scanned the internet for systems that were vulnerable to infection and exploited those computers remotely.

The worm then is likely to have spread through a channel that links computers running Microsoft Windows in a network. The channel is typically used to share files within a network or to link to a printer, for example.

THE NORTH KOREA LINK

This method has been found in previously known North Korean cyberattacks, including the Sony hack in 2014 blamed on North Korea.

“Since a July 2009 cyberattack by North Korea, they used the same method,” Choi said. “It’s not unique in North Korea but it’s also not a very common method.”

Choi also cited an accidental communication he had last year with a hacker traced to a North Korean internet address who admitted development of ransomware.

The Russian security firm Kaspersky Lab has said portions of the WannaCry program use the same code as malware previously distributed by the Lazarus Group, a hacker collective behind the 2014 Sony hack. Another security company, Symantec, has also found similarities between WannaCry and Lazarus tools.

But it’s possible the code was simply copied from the Lazarus malware without any other direct connection.

If North Korea, believed to be training cyber warriors at schools, is indeed responsible for the latest attack, Choi said the world should stop underestimating its capabilities and work together to think of a new way to respond to cyber threats, such as having China pull the plug on North Korea’s internet.

“We have underestimated North Korea so far that since North Korea is poor, it wouldn’t have any technologies. But North Korea has been preparing cyber skills for more than 10 years and its skill is significant. We should never underestimate it,” Choi said.

FOLLOW THE MONEY

Researchers might find some additional clues in the bitcoin accounts accepting the ransom payments. There have been three accounts identified so far, and there’s no indication yet that the criminals have touched the funds.

Although bitcoin is anonymized, researchers can watch it flow from user to user. So investigators can follow the transactions until an anonymous account matches with a real person, said Steve Grobman, chief technology officer with the California security company McAfee.

But that technique is no sure bet. There are ways to convert bitcoins into cash on the sly through third parties. And even finding a real person might be no help if they’re in a jurisdiction that won’t cooperate.

TELL-TALE SIGNS

James Lewis, a cybersecurity expert at the Center for Strategic and International Studies in Washington, said U.S. investigators are collecting forensic information — such as internet addresses, samples of malware or information the culprits might have inadvertently left on computers — that could be matched with the handiwork of known hackers.

Investigators might also be able to extract some information about the attacker from a previously hidden internet address connected to WannaCry’s “kill switch.” That switch was essentially a beacon sending the message “hey, I’m infected” to the hidden address, Weaver said.

That means the very first attempts to reach that address, which might have been recorded by spy agencies such as the NSA or Russian intelligence, could lead to “patient zero” — the first computer infected with WannaCry. That, in turn, might further narrow the focus on possible suspects.

THE PLAYERS

Forensics, though, will only get investigators so far. One challenge will be sharing intelligence in real time to move as quickly as the criminals — a tricky feat when some of the major nations involved, such as the U.S. and Russia, distrust each other.

Even if the perpetrators can be identified, bringing them to justice could be another matter. They might be hiding out in countries that wouldn’t be willing to extradite suspects for prosecution.

“It can take months or even years to gather all the evidence and build a case,” said Costin Raiu, head of Kaspersky’s global research and analysis.

Anick Jesdanun and Barbary Ortutay in New York, Lori Hinnant in Paris and Deb Riechmann in Washington contributed to this story.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

LifeWise local co-directors Darcie Hammer and Sarah Sweeny talk about what a typical classroom routine looks like on Monday, April 14, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Everett off-campus Bible program draws mixed reaction from parents

The weekly optional program, LifeWise Academy, takes children out of public school during the day for religious lessons.

Protesters line Broadway in Everett for Main Street USA rally

Thousands turn out to protest President Trump on Saturday in Everett, joining hundreds of other towns and cities.

An EcoRemedy employee checks a control panel of their equipment at the Edmonds Wastewater Treatment Plant on Thursday, April 17, 2025 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds launches technology to destroy PFAS

Edmonds is the first city in the country to implement… Continue reading

Over a dozen parents and some Snohomish School District students gather outside of the district office to protest and discuss safety concerns after an incident with a student at Machias Elementary School on Friday, April 18, 2025 in Snohomish, Washington. (Olivia Vanni / The Herald)
Parents protest handling of alleged weapon incident at Machias Elementary

Families say district failed to communicate clearly; some have kept kids home for weeks.

Irene Pfister, left, holds a sign reading “Justice for Jonathan” next to another protester with a sign that says “Major Crimes Needs to Investigate,” during a call to action Saturday, April 12, 2025, in Arlington. (Aspen Anderson / The Herald)
Arlington community rallies, a family waits for news on missing man

Family and neighbors say more can be done in the search for Jonathan Hoang. The sheriff’s office says all leads are being pursued.

Mary Ann Karber, 101, spins the wheel during Wheel of Forunte at Washington Oakes on Tuesday, April 1, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Lunch and Wheel of Fortune with some Everett swinging seniors

She’s 101 and he’s 76. At Washington Oakes, fun and friendship are on the menu.

Everett Music Initiative announces Music at the Marina lineup

The summer concert series will take place each Thursday, July 10 to Aug. 28 at the Port of Everett.

Jordan Hoffman-Nelson watches the store cameras for a couple hours each day, often detecting 5 to 10 thefts in a single sitting. (Aspen Anderson / The Herald)
At a Lynnwood thrift store, rising shoplifting mirrors larger retail crime surge

Employees at Bella’s Voice remain alert for theft on a daily basis. They aren’t the only ones.

Connect Casino Road Director Alvaro Gullien speaks at an Everett City Council meeting to share community thoughts regarding affordable housing and preventing displacement of those that live along Casino Road on Wednesday, April 16, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
How will Everett’s comprehensive plan work in Casino Road?

Residents in the diverse, tight-knit neighborhood want “Investment without displacement.” The city’s plan will help achieve that, staff say.

Henry M. Jackson High School’s FIRST Robotics Competition championship robotics Team 2910 Jack in the Bot on Thursday, April 24, 2025 in Mill Creek, Washington. (Olivia Vanni / The Herald)
Mill Creek robotics team celebrates world championship win

The team — known as “Jack in the Bot” — came in first place above about 600 others at a Texas world championship event last week.

Trees and foliage grow at the Rockport State Park on Wednesday, April 3, 2024 in Rockport, Washington. (Annie Barker / The Herald)
Washington Legislature approves hiking Discover Pass price to $45

The price for a Washington state Discover Pass would rise by $15… Continue reading

The Washington state Capitol on April 18, 2025. (Photo by Jacquelyn Jimenez Romero/Washington State Standard)
Parental rights overhaul gains final approval in WA Legislature

The bill was among the most controversial of this year’s session.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.