WannaCry - Links to Lazarus Group
2017-05-15 • Comae •
https://www.comae.com/posts/wannacry-links-to-lazarus-group/
Comae examined reported code similarities between a February 2017 WannaCry sample and a 2015 Contopee sample that Symantec had previously attributed to Lazarus Group. The excerpt cites Neel Mehta's initial comparison, Kaspersky's shared suspicion, and Symantec's later statement that it also found similarities, while presenting hashes and appendix material for the compared samples. The author frames the finding as potential evidence that WannaCry may have been developed by Lazarus Group, but keeps the conclusion conditional on validation. If confirmed, the linkage would connect global ransomware activity with a threat actor previously associated in the excerpt with financially motivated intrusions and would imply use of leaked offensive capabilities in a disruptive campaign.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9c7c7149387a1c79679a87dd1ba755bc | 2017-05-15 | 2025-02-04 |
| HASH | ac21c8ad899727137c4b94458d7aa8d8 | 2017-05-15 | 2025-02-04 |
| HASH | 3e6de9e2baacf930949647c399818e7… | 2017-05-15 | 2020-03-09 |
| HASH | 766d7d591b9ec1204518723a1e5940f… | 2017-05-15 | 2020-03-09 |