This article is from the source 'guardian' and was first published or seen on . It last changed over 40 days ago and won't be checked again for changes.

You can find the current article at its original source at https://www.theguardian.com/technology/2017/dec/19/wannacry-cyberattack-us-says-it-has-evidence-north-korea-was-directly-responsible

The article has changed 7 times. There is an RSS feed of changes available.

Version 5 Version 6
Facebook action hints at western retaliation over WannaCry attack Facebook action hints at western retaliation over WannaCry attack
(about 1 month later)
Site deletes accounts linked to Lazarus Group, hackers associated with North Korea that UK and US blame for ransomware
Ewen MacAskill and
Alex Hern in London, and
Justin McCurry in Tokyo
Tue 19 Dec 2017 19.14 GMT
First published on Tue 19 Dec 2017 02.33 GMT
Share on Facebook
Share on Twitter
Share via Email
View more sharing options
Share on LinkedIn
Share on Pinterest
Share on Google+
Share on WhatsApp
Share on Messenger
Close
The US and UK may be engaged in cyber-offensives against North Korea in retaliation for attacks such as WannaCry, which caused widespread disruption to public services, companies and homes around the world in May.The US and UK may be engaged in cyber-offensives against North Korea in retaliation for attacks such as WannaCry, which caused widespread disruption to public services, companies and homes around the world in May.
Neither the UK nor the US government will confirm whether they have already mounted revenge cyber-attacks against North Korea. However, a hint that action was already being taken was offered on Tuesday when Facebook said it had recently deleted accounts linked to the Lazarus Group, a hacking entity associated with North Korea that both the US and UK blame for the WannaCry attacks.Neither the UK nor the US government will confirm whether they have already mounted revenge cyber-attacks against North Korea. However, a hint that action was already being taken was offered on Tuesday when Facebook said it had recently deleted accounts linked to the Lazarus Group, a hacking entity associated with North Korea that both the US and UK blame for the WannaCry attacks.
A spokesperson for the UK’s National Cyber Security Centre (NCSC), the public face of the surveillance agency GCHQ, said on Tuesday: “Our assessment has been that North Korean actors known as the Lazarus Group were very likely responsible for the WannaCry attack back in May this year.”A spokesperson for the UK’s National Cyber Security Centre (NCSC), the public face of the surveillance agency GCHQ, said on Tuesday: “Our assessment has been that North Korean actors known as the Lazarus Group were very likely responsible for the WannaCry attack back in May this year.”
Although the White House announced only on Tuesday that it believed North Korea was behind the attack, the same finding was made by the NCSC in June and announced in the UK in October by the Home Office minister Ben Wallace.Although the White House announced only on Tuesday that it believed North Korea was behind the attack, the same finding was made by the NCSC in June and announced in the UK in October by the Home Office minister Ben Wallace.
The US and UK governments went further on Tuesday by suggesting it was highly likely the Lazarus Group was backed by the North Korean government.The US and UK governments went further on Tuesday by suggesting it was highly likely the Lazarus Group was backed by the North Korean government.
The Foreign Office minister for cyber, Tariq Ahmad, said: “We condemn these actions and commit ourselves to working with all responsible states to combat destructive criminal use of cyberspace. The indiscriminate use of the WannaCry ransomware demonstrates North Korean actors using their cyber programme to circumvent sanctions.”The Foreign Office minister for cyber, Tariq Ahmad, said: “We condemn these actions and commit ourselves to working with all responsible states to combat destructive criminal use of cyberspace. The indiscriminate use of the WannaCry ransomware demonstrates North Korean actors using their cyber programme to circumvent sanctions.”
He added: “International law applies online as it does offline. The United Kingdom is determined to identify, pursue and respond to malicious cyber-activity regardless of where it originates, imposing costs on those who wish to attack us in cyberspace. We are committed to strengthening coordinated international efforts to uphold a free, open, peaceful and secure cyberspace.”He added: “International law applies online as it does offline. The United Kingdom is determined to identify, pursue and respond to malicious cyber-activity regardless of where it originates, imposing costs on those who wish to attack us in cyberspace. We are committed to strengthening coordinated international efforts to uphold a free, open, peaceful and secure cyberspace.”
The UK Ministry of Defence and GCHQ have a range of options for mounting offensive cyber-attacks that could create disruption in North Korea.The UK Ministry of Defence and GCHQ have a range of options for mounting offensive cyber-attacks that could create disruption in North Korea.
The defence secretary, Gavin Williamson, told the Evening Standard that Britain would “never hesitate to deal with aggression and threats”.The defence secretary, Gavin Williamson, told the Evening Standard that Britain would “never hesitate to deal with aggression and threats”.
Two Royal Navy warships are heading to join the US in the region. Williamson said: “North Korea is a massive threat. They are a real danger to this country.”Two Royal Navy warships are heading to join the US in the region. Williamson said: “North Korea is a massive threat. They are a real danger to this country.”
Tom Bossert, a White House homeland security adviser, said on Tuesday: “Facebook took down accounts and stopped the operational execution of ongoing cyber-attacks and Microsoft acted to patch existing attacks, not just the WannaCry attack initially.”Tom Bossert, a White House homeland security adviser, said on Tuesday: “Facebook took down accounts and stopped the operational execution of ongoing cyber-attacks and Microsoft acted to patch existing attacks, not just the WannaCry attack initially.”
A Facebook spokesman said on Tuesday the company had deleted accounts associated with Lazarus last week “to make it harder for them to conduct their activities”. It had also notified individuals in contact with these accounts to suggest they consider enhancing their account security.A Facebook spokesman said on Tuesday the company had deleted accounts associated with Lazarus last week “to make it harder for them to conduct their activities”. It had also notified individuals in contact with these accounts to suggest they consider enhancing their account security.
Lazarus is widely believed by security researchers and US officials to have been responsible for the 2014 hack of Sony Pictures Entertainment. The hack destroyed files, leaked corporate communications online and led to the departure of several executives.Lazarus is widely believed by security researchers and US officials to have been responsible for the 2014 hack of Sony Pictures Entertainment. The hack destroyed files, leaked corporate communications online and led to the departure of several executives.
Facebook said it had acted with Microsoft “and other members of the security community” to disrupt the group’s activities. “Our companies have a history of sharing threat information and working together to protect our users and the web as a whole.”Facebook said it had acted with Microsoft “and other members of the security community” to disrupt the group’s activities. “Our companies have a history of sharing threat information and working together to protect our users and the web as a whole.”
The US administration has publicly identified North Korea as the biggest threat to the US, mainly because of progress Pyongyang is making in developing a nuclear warhead and ballistic missile system capable of hitting the US mainland.The US administration has publicly identified North Korea as the biggest threat to the US, mainly because of progress Pyongyang is making in developing a nuclear warhead and ballistic missile system capable of hitting the US mainland.
The administration signalled on Monday it could revise its national strategy to make cyber-attacks a new category that could prompt retaliation with a nuclear strike.The administration signalled on Monday it could revise its national strategy to make cyber-attacks a new category that could prompt retaliation with a nuclear strike.
Bossert said those responsible for carrying out cyber-attacks would be held accountable, but he did not mention specific action Washington was considering taking against Pyongyang.Bossert said those responsible for carrying out cyber-attacks would be held accountable, but he did not mention specific action Washington was considering taking against Pyongyang.
In spite of warlike rhetoric from Donald Trump, his security advisers are focused mainly on trying to put pressure on China to deal with North Korea. The US hope is that such rhetoric will alarm Beijing sufficiently to press the North Korean leader, Kim Jong-un, to abandon the nuclear weapons programme in favour of negotiations.In spite of warlike rhetoric from Donald Trump, his security advisers are focused mainly on trying to put pressure on China to deal with North Korea. The US hope is that such rhetoric will alarm Beijing sufficiently to press the North Korean leader, Kim Jong-un, to abandon the nuclear weapons programme in favour of negotiations.
News reports quoted a senior Trump administration official as saying the public shaming of North Korea was designed to hold the regime accountable for its actions and “erode and undercut their ability to launch attacks”.News reports quoted a senior Trump administration official as saying the public shaming of North Korea was designed to hold the regime accountable for its actions and “erode and undercut their ability to launch attacks”.
Bossert said the US would “publicly attribute” WannaCry to North Korea. He described the attack as “cowardly, costly and careless”.Bossert said the US would “publicly attribute” WannaCry to North Korea. He described the attack as “cowardly, costly and careless”.
“We do not make this allegation lightly,” he wrote in an op-ed in the Wall Street Journal. “It is based on evidence. We are not alone with our findings, either. Other governments and private companies agree. The United Kingdom attributes the attack to North Korea, and Microsoft traced the attack to cyber-affiliates of the North Korean government.”“We do not make this allegation lightly,” he wrote in an op-ed in the Wall Street Journal. “It is based on evidence. We are not alone with our findings, either. Other governments and private companies agree. The United Kingdom attributes the attack to North Korea, and Microsoft traced the attack to cyber-affiliates of the North Korean government.”
Bossert added: “North Korea has acted especially badly, largely unchecked, for more than a decade, and its malicious behaviour is growing more egregious.”Bossert added: “North Korea has acted especially badly, largely unchecked, for more than a decade, and its malicious behaviour is growing more egregious.”
He called on governments and businesses to work together to reduce the risks of cyber-attacks and for harsher punishments for the groups and individuals behind them. “Malicious hackers belong in prison, and totalitarian governments should pay a price for their actions,” he said.He called on governments and businesses to work together to reduce the risks of cyber-attacks and for harsher punishments for the groups and individuals behind them. “Malicious hackers belong in prison, and totalitarian governments should pay a price for their actions,” he said.
While North Korea is believed to run a sophisticated cyberwarfare operation that has traditionally targeted South Korea, the regime has repeatedly denied it was behind WannaCry.While North Korea is believed to run a sophisticated cyberwarfare operation that has traditionally targeted South Korea, the regime has repeatedly denied it was behind WannaCry.
WannaCry was notable for being one of the first examples of ransomware that was also a worm, meaning it could move automatically from computer to computer. That enabled its rapid spread throughout the world before it was stopped thanks to the accidental discovery of a “killswitch” hidden in its code.WannaCry was notable for being one of the first examples of ransomware that was also a worm, meaning it could move automatically from computer to computer. That enabled its rapid spread throughout the world before it was stopped thanks to the accidental discovery of a “killswitch” hidden in its code.
The malware infected computer systems at NHS hospitals in Britain, forcing thousands of patients to reschedule appointments. FedEx was among the hardest hit of corporate targets, saying it expected a $300m hit to profits as a result of the attack.The malware infected computer systems at NHS hospitals in Britain, forcing thousands of patients to reschedule appointments. FedEx was among the hardest hit of corporate targets, saying it expected a $300m hit to profits as a result of the attack.
..
North KoreaNorth Korea
CyberwarCyberwar
CybercrimeCybercrime
Asia PacificAsia Pacific
MalwareMalware
newsnews
Share on FacebookShare on Facebook
Share on TwitterShare on Twitter
Share via EmailShare via Email
Share on LinkedInShare on LinkedIn
Share on PinterestShare on Pinterest
Share on Google+Share on Google+
Share on WhatsAppShare on WhatsApp
Share on MessengerShare on Messenger
Reuse this contentReuse this content