42. Early linguistic analysis by Flashpoint
indicated a Chinese connection: of the 28
languages in which the ransom notice was
written, only the Chinese (both Simplified
and Traditional) and English versions were
written by humans instead of machinetranslated, and only the Chinese notice
appears to have been written by a fluent
speaker; the other messages, including
the Korean message, were apparently
translated from the English note using
Google Translate. See Jon Condra, John
Costello & Sherman Chu, “Linguistic
Analysis of WannaCry Ransomware
Messages Suggests Chinese-Speaking,”
Flashpoint, (25 May 2017), at https://
www.flashpoint-intel.com/blog/linguisticanalysis-wannacry-ransomware/. However,
more in-depth and nuanced forensic
analyses points to criminals from North
Korea; that said, no connection to
the North Korea state itself had been
demonstrated. The cybersecurity service
firm Symantec showed “strong links” to
Lazarus group, a hacking group based
in Pyongyang and closely associated
with the North Korean government. See
Symantec Security Response, “WannaCry:
Ransomware Attacks Show Strong Links
to Lazarus Group,” Symantec Official
Blog, (22 May 2017), at https://www.
symantec.com/connect/blogs/wannacryransomware-attacks-show-strong-linkslazarus-group. That analysis has been
since supported by an investigation led by
Britain’s National Cyber Security Centre
(NCSC) and supported by the US-CERT.
See, e.g., Gordon Corera, “NHS CyberAttack Was ‘Launched from North Korea,”
BBC News, (16 Jun. 2017), at http://www.
bbc.com/news/technology-40297493.
Lazarus group has been blamed for the
2014 cyberattack on Sony and the theft of
US$81m from Bangladesh’s central bank.
“More Evidence for WannaCry ‘Link’ to
North Korean Hackers,” BBC News, (23
May 2017), at http://www.bbc.com/news/
technology-40010996. As already noted,
such matters are beyond the scope of the
Toolkit. See supra § 1 A.
43. MalwareTech, “How to Accidentally Stop
a Global Cyber Attacks,” MalwareTech
Blog, (13 May 2017), at https://www.
malwaretech.com/2017/05/how-toaccidentally-stop-a-global-cyber-attacks.
html. The researcher noted that the
malware attempted to contact a specific
web address each time it infected a new
system; the address not being registered,
he did so himself, allowing him to see
where computers were being affected
and unexpectedly triggering a part of the
code that told the ransomware to stop
spreading. Ibid.
Page 59 | Chapter 1 | End Notes
44. Speaking to the BBC, MalwareTech
said, “There’s a lot of money in this,
there is no reason for them to stop. It’s
not much effort for them to change the
code and start over.” Chris Foxx, “Global
Cyber-attack: Security Blogger Halts
Ransomware ‘by Accident’,” BBC News,
(14 May 2017), at http://www.bbc.com/
news/technology-39907049.
45. Dave Lee, “Global Cyber-Attack: How
Roots Can be Traced to the US,” BBC
News, (13 May 2017), at http://www.bbc.
com/news/technology-39905509. The
NSA has neither confirmed nor denied
as much. It is not known who conducted
the attacks. It has been suggested that
the NSA may have created the tool. Id.;
Bill Chappell, “WannaCry Ransomware:
Microsoft Calls Out NSA For ‘Stockpiling’
Vulnerabilities,” NPR, (15 May 2017), at
http://www.npr.org/sections/thetwoway/2017/05/15/528439968/wannacryransomware-microsoft-calls-out-nsafor-stockpiling-vulnerabilities; Thomas
Fox-Brewster, “An NSA Cyber Weapon
Might Be Behind A Massive Global
Ransomware Outbreak,” Forbes, (12 May
2017), at http://www.npr.org/sections/
thetwo-way/2017/05/15/528439968/
wannacry-ransomware-microsoft-calls-outnsa-for-stockpiling-vulnerabilities.
46. Andy Greenberg, “Major Leak Suggests
NSA Was Deep in Middle East Banking
System,” Wired, (14 Apr. 2017), at https://
www.wired.com/2017/04/major-leaksuggests-nsa-deep-middle-east-bankingsystem/.
47. Bill Chappell, “WannaCry Ransomware:
What We Know Monday,” NPR, (15 May
2017), at http://www.npr.org/sections/
thetwo-way/2017/05/15/528451534/
wannacry-ransomware-what-we-knowmonday.
48. “WannaCry: Are You Safe?,” Kaspersky
Labs, (13 May 2017), at https://
blog.kaspersky.com/wannacryransomware/16518/; “Kaspersky Lab’s
Notice to Customers about the Shadow
Brokers’ Publication from April 14,”
Kaspersky Labs, (14 Apr. 2017), at https://
support.kaspersky.com/shadowbrokers.
49. US policy had been understood to be
one of disclosing identified vulnerabilities
to vendors and others so that they can
be patched. See Kim Zetter, “Obama:
NSA Must Reveal Bugs Like Heartbleed,
Unless They Help the NSA,” Wired,
(15 Apr. 2014), at https://www.wired.
com/2014/04/obama-zero-day/. Such
being the case, it is not clear why the
vulnerabilities identified had not been
released. See Brad Smith, “The Need for
Urgent Collective Action to Keep People
Safe Online: Lessons from Last Week’s
Cyberattack,” Official Microsoft Blog,
(14 May 2017), at https://blogs.microsoft.
com/on-the-issues/2017/05/14/needurgent-collective-action-keep-peoplesafe-online-lessons-last-weeks-cyberattac
k/#oHaqtHbEYodLhwLl.99. See also Matt
Day, “Microsoft Criticizes Government
Creation of Hacking Tools Used in Global
Cyberattack,” Seattle Times, (14 May
2017), at http://www.seattletimes.com/
business/microsoft/microsoft-criticizesgovernment-creation-of-hacking-toolsused-in-global-cyberattack/.
50. “Next Cyber-attack Could Be Imminent,
Warn Experts,” BBC News (14 May 2017),
at http://www.strategic-culture.org/
news/2017/05/14/international-cyberattack-roots-traced-us-national-securityagency.html; Victoria Woollaston, “Wanna
Decryptor Ransomware Appears to Be
Spawning and This Time It May Not Have
a Kill Switch,” Wired, (16 May 2017), at
http://www.wired.co.uk/article/wannadecryptor-ransomware.
51. In March 2017, Microsoft released a patch
for the vulnerability in question. Microsoft,
Security Bulletin MS17-010, (14 Mar. 2017),
at https://technet.microsoft.com/en-us/
library/security/ms17-010.aspx. Following
the attacks in May, Microsoft released
a separate patch for users of older and
unsupported operating systems, such as
Windows XP.
52. MSRC Team, “Customer Guidance for
WannaCrypt Attacks,” Microsoft Official
Blog, (12 May 2017), at https://blogs.
technet.microsoft.com/msrc/2017/05/12/
customer-guidance-for-wannacryptattacks/.
53. 2017 Data Breach Investigations Report,
10th ed., Verizon, (27 Apr. 2017), at http://
www.verizonenterprise.com/verizoninsights-lab/dbir/2017/.
54. See, e.g., Dave Lee, “Global CyberAttack: How Roots Can Be Traced
to the US,” BBC News, (13 May
2017), at http://www.bbc.com/news/
technology-39905509.
Table of Contents