WannaCry and Lazarus Group – the missing link?

2017-05-15 Kaspersky

https://securelist.com/wannacry-and-lazarus-group-the-missing-link/78431/

Thumbnail for WannaCry and Lazarus Group – the missing link?

Kaspersky reported that a February 2017 WannaCry cryptor sample shared code with a February 2015 Lazarus APT backdoor sample highlighted by Neel Mehta. The researchers treated the finding as a significant clue about WannaCry’s origins, while noting that more research into older variants was needed and that false-flag reuse was theoretically possible but considered improbable. The excerpt connects the early WannaCry sample to the May 2017 encryptor through shared targeted file-extension lists, with later versions adding more extensions and changing some targets. The body also places Lazarus in the context of prior operations including Sony Pictures, the Bangladesh Bank heist, and DarkSeoul, and provides a YARA rule based on the shared-code finding.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9c7c7149387a1c79679a87dd1ba755bc 2017-05-15 2025-02-04
HASH ac21c8ad899727137c4b94458d7aa8d8 2017-05-15 2025-02-04
YARA lazaruswannacry 2017-05-15 2017-05-15

Related Actors

Related Reports

« Back