42. Early linguistic analysis by Flashpoint indicated a Chinese connection: of the 28 languages in which the ransom notice was written, only the Chinese (both Simplified and Traditional) and English versions were written by humans instead of machinetranslated, and only the Chinese notice appears to have been written by a fluent speaker; the other messages, including the Korean message, were apparently translated from the English note using Google Translate. See Jon Condra, John Costello & Sherman Chu, “Linguistic Analysis of WannaCry Ransomware Messages Suggests Chinese-Speaking,” Flashpoint, (25 May 2017), at https:// www.flashpoint-intel.com/blog/linguisticanalysis-wannacry-ransomware/. However, more in-depth and nuanced forensic analyses points to criminals from North Korea; that said, no connection to the North Korea state itself had been demonstrated. The cybersecurity service firm Symantec showed “strong links” to Lazarus group, a hacking group based in Pyongyang and closely associated with the North Korean government. See Symantec Security Response, “WannaCry: Ransomware Attacks Show Strong Links to Lazarus Group,” Symantec Official Blog, (22 May 2017), at https://www. symantec.com/connect/blogs/wannacryransomware-attacks-show-strong-linkslazarus-group. That analysis has been since supported by an investigation led by Britain’s National Cyber Security Centre (NCSC) and supported by the US-CERT. See, e.g., Gordon Corera, “NHS CyberAttack Was ‘Launched from North Korea,” BBC News, (16 Jun. 2017), at http://www. bbc.com/news/technology-40297493. Lazarus group has been blamed for the 2014 cyberattack on Sony and the theft of US$81m from Bangladesh’s central bank. “More Evidence for WannaCry ‘Link’ to North Korean Hackers,” BBC News, (23 May 2017), at http://www.bbc.com/news/ technology-40010996. As already noted, such matters are beyond the scope of the Toolkit. See supra § 1 A. 43. MalwareTech, “How to Accidentally Stop a Global Cyber Attacks,” MalwareTech Blog, (13 May 2017), at https://www. malwaretech.com/2017/05/how-toaccidentally-stop-a-global-cyber-attacks. html. The researcher noted that the malware attempted to contact a specific web address each time it infected a new system; the address not being registered, he did so himself, allowing him to see where computers were being affected and unexpectedly triggering a part of the code that told the ransomware to stop spreading. Ibid. Page 59 | Chapter 1 | End Notes 44. Speaking to the BBC, MalwareTech said, “There’s a lot of money in this, there is no reason for them to stop. It’s not much effort for them to change the code and start over.” Chris Foxx, “Global Cyber-attack: Security Blogger Halts Ransomware ‘by Accident’,” BBC News, (14 May 2017), at http://www.bbc.com/ news/technology-39907049. 45. Dave Lee, “Global Cyber-Attack: How Roots Can be Traced to the US,” BBC News, (13 May 2017), at http://www.bbc. com/news/technology-39905509. The NSA has neither confirmed nor denied as much. It is not known who conducted the attacks. It has been suggested that the NSA may have created the tool. Id.; Bill Chappell, “WannaCry Ransomware: Microsoft Calls Out NSA For ‘Stockpiling’ Vulnerabilities,” NPR, (15 May 2017), at http://www.npr.org/sections/thetwoway/2017/05/15/528439968/wannacryransomware-microsoft-calls-out-nsafor-stockpiling-vulnerabilities; Thomas Fox-Brewster, “An NSA Cyber Weapon Might Be Behind A Massive Global Ransomware Outbreak,” Forbes, (12 May 2017), at http://www.npr.org/sections/ thetwo-way/2017/05/15/528439968/ wannacry-ransomware-microsoft-calls-outnsa-for-stockpiling-vulnerabilities. 46. Andy Greenberg, “Major Leak Suggests NSA Was Deep in Middle East Banking System,” Wired, (14 Apr. 2017), at https:// www.wired.com/2017/04/major-leaksuggests-nsa-deep-middle-east-bankingsystem/. 47. Bill Chappell, “WannaCry Ransomware: What We Know Monday,” NPR, (15 May 2017), at http://www.npr.org/sections/ thetwo-way/2017/05/15/528451534/ wannacry-ransomware-what-we-knowmonday. 48. “WannaCry: Are You Safe?,” Kaspersky Labs, (13 May 2017), at https:// blog.kaspersky.com/wannacryransomware/16518/; “Kaspersky Lab’s Notice to Customers about the Shadow Brokers’ Publication from April 14,” Kaspersky Labs, (14 Apr. 2017), at https:// support.kaspersky.com/shadowbrokers. 49. US policy had been understood to be one of disclosing identified vulnerabilities to vendors and others so that they can be patched. See Kim Zetter, “Obama: NSA Must Reveal Bugs Like Heartbleed, Unless They Help the NSA,” Wired, (15 Apr. 2014), at https://www.wired. com/2014/04/obama-zero-day/. Such being the case, it is not clear why the vulnerabilities identified had not been released. See Brad Smith, “The Need for Urgent Collective Action to Keep People Safe Online: Lessons from Last Week’s Cyberattack,” Official Microsoft Blog, (14 May 2017), at https://blogs.microsoft. com/on-the-issues/2017/05/14/needurgent-collective-action-keep-peoplesafe-online-lessons-last-weeks-cyberattac k/#oHaqtHbEYodLhwLl.99. See also Matt Day, “Microsoft Criticizes Government Creation of Hacking Tools Used in Global Cyberattack,” Seattle Times, (14 May 2017), at http://www.seattletimes.com/ business/microsoft/microsoft-criticizesgovernment-creation-of-hacking-toolsused-in-global-cyberattack/. 50. “Next Cyber-attack Could Be Imminent, Warn Experts,” BBC News (14 May 2017), at http://www.strategic-culture.org/ news/2017/05/14/international-cyberattack-roots-traced-us-national-securityagency.html; Victoria Woollaston, “Wanna Decryptor Ransomware Appears to Be Spawning and This Time It May Not Have a Kill Switch,” Wired, (16 May 2017), at http://www.wired.co.uk/article/wannadecryptor-ransomware. 51. In March 2017, Microsoft released a patch for the vulnerability in question. Microsoft, Security Bulletin MS17-010, (14 Mar. 2017), at https://technet.microsoft.com/en-us/ library/security/ms17-010.aspx. Following the attacks in May, Microsoft released a separate patch for users of older and unsupported operating systems, such as Windows XP. 52. MSRC Team, “Customer Guidance for WannaCrypt Attacks,” Microsoft Official Blog, (12 May 2017), at https://blogs. technet.microsoft.com/msrc/2017/05/12/ customer-guidance-for-wannacryptattacks/. 53. 2017 Data Breach Investigations Report, 10th ed., Verizon, (27 Apr. 2017), at http:// www.verizonenterprise.com/verizoninsights-lab/dbir/2017/. 54. See, e.g., Dave Lee, “Global CyberAttack: How Roots Can Be Traced to the US,” BBC News, (13 May 2017), at http://www.bbc.com/news/ technology-39905509. Table of Contents

Select target paragraph3