With the dust now settling after WannaCry, the biggest ransomware attack in history, cybersecurity experts are taking a deep dive into how it was carried out, what can be done to protect computers from future breaches and, trickiest of all, who is really to blame.
p
For many, it seems that last question has already been solved: It was North Korea.
p
But beyond the frequently used shorthand that North Korea was likely behind the attack lies a more complicated == and enlightening == story: the rise of an infamous group of workaholic hackers, collectively known as Lazarus, who may be using secret lairs in northeast China and have created a virtual malware factory that could wreak a lot more havoc in the future.
p
Big caveat here: Lazarus doesn’t reveal much about itself. What little is known about the group is speculative.
p
Nevertheless, extensive forensic research into its activities dating back almost a decade paints a fascinating, if chilling, picture of a hacker collective that is mercenary, tenacious and motivated by what appears to be a mixture of political and financial objectives.
p
Their fingerprints are all over WannaCry.
p
So who, then, are they?
p
subhead
Operation Blockbuster
/subhead
p
On Dec. 19, 2014, just one month after a devastating hack hobbled Sony Pictures Entertainment, the FBI’s field office in San Diego issued a press release stating North Korea was the culprit and saying such cyberattacks pose one of the gravest national security dangers to the United States.
p
The destructive nature of this attack, coupled with its coercive nature, sets it apart, the statement said. North Korea’s actions were intended to inflict significant harm on a U.S. business and suppress the right of American citizens to express themselves. Such acts of intimidation fall outside the bounds of acceptable state behavior.
p
The FBI listed similarities in specific lines of code, encryption algorithms, data deletion methods and compromised networks…