相似代码露出马脚,攻陷全球的恶意软件中的代码曾被朝鲜黑客组织使用;该组织曾攻破孟加拉银行,盗取近亿美元!

来源: austraveller 2017-05-16 10:07:46 [] [博客] [旧帖] [给我悄悄话] 本文已被阅读: 次 (6958 bytes)
本文内容已被 [ austraveller ] 在 2017-05-16 10:13:39 编辑过。如有问题,请报告版主或论坛管理删除.

http://dailycaller.com/2017/05/16/more-clues-suggest-north-korea-behind-massive-global-cyberattack/

The WannaCry ransomware attack that wreaked havoc on computer systems around the world over the past few days may be the handiwork of North Korea, some early clues suggest.

Google security researcher Neel Mehta sent out a tweet Monday linking two samples of malicious code: One from an early version of WannaCry and the other from the Lazarus Group, a collection of cybercriminals reportedly affiliated with North Korea.

Lazarus launched an attack on the Bangladesh central bank’s account at the Federal Reserve Bank of New York from an IP address in North Korea, according to Kaspersky Lab. The hackers stole $81 million. Lazarus has been active for years, but it wasn’t until recently that researchers discovered a connection to North Korea. The Lazarus Group is also reportedly behind the infamous Sony hack, as well as a breach at a Polish bank.

Kaspersky called Mehta’s discovery “the most significant clue to date regarding the origins of WannaCry.” Acknowledging that more research is required, the director of the global research and analysis team at Kaspersky Lab, Costin Raiu, told Forbes that Mehta “might have found the WannaCry Rosetta Stone.”

The code used in the ransomware attack is noticeably uncommon and has only been used by cybercriminals with ties to North Korea, reports the New York Times.

“At this time, all we have is a temporal link,” Eric Chien, a Symantec investigator told the Times. “We want to see more coding similarities to give us more confidence.”

Simon Choi, a director at South Korean anti-virus software company Hauri Inc. who has analyzed North Korean malware, noted that the demand for victims of the WannaCry attack to pay the ransom in bitcoins is reminiscent of North Korean tactics. He explained to Bloomberg News that North Korea has been mining the digital currency since 2013 using malicious programs.

Choi introduced that he unintentionally contacted a North Korean hacker last year, stumbling onto a plot to develop a type of ransomware. He immediately notified South Korean authorities.

The evidence suggesting that North Korea may be behind the latest attacks is tenuous, but it is the first real lead regarding the origins of the WannaCry attack that plagued hundreds of thousands of computers worldwide.

所有跟帖: 

如果最后做实了此次袭击是朝鲜做的,那后续发展恐怕比朝鲜核实验还严重 -austraveller- 给 austraveller 发送悄悄话 austraveller 的博客首页 (0 bytes) () 05/16/2017 postreply 10:10:42

一般不同人写的代码不可能完全相同,如有相同肯定是一个人或一伙人的作品 -austraveller- 给 austraveller 发送悄悄话 austraveller 的博客首页 (0 bytes) () 05/16/2017 postreply 10:48:22

看上去更像CIA自己干的,自己的代码,熟门熟路的,朝鲜还没low到和CIA相提并论呢 -王伍- 给 王伍 发送悄悄话 (0 bytes) () 05/16/2017 postreply 10:26:04

这次黑客的一些表现,还挺有幽默感的,不像是朝鲜体制内人的风格 -NEWHNAD- 给 NEWHNAD 发送悄悄话 NEWHNAD 的博客首页 (0 bytes) () 05/16/2017 postreply 10:42:59

请您先登陆,再发跟帖!