Cyber security researchers have found technical evidence they said could link North Korea with the global WannaCry “ransomware” cyberattack that has infected more than 300,000 computers in 150 countries since Friday.
Symantec and Kaspersky Lab said on Monday that some code in an earlier version of the WannaCry software had also appeared in programs used by the Lazarus Group, which researchers from many companies have identified as a North Korea-run hacking operation.
Both firms said it was too early to tell whether North Korea was involved in the attacks, based on the evidence that was published on Twitter by Google security researcher Neel Mehta. The attacks, which slowed on Monday, are among the fastest-spreading extortion campaigns on record.
The research will be closely followed by law enforcement agencies around the world, including Washington, where President Donald Trump’s homeland security adviser said on Monday that both foreign nations and cyber criminals were possible culprits.
The two security firms said they needed to study the code more and asked for others to help with the analysis. Hackers do reuse code from other operations, so even copied lines fall well short of proof.
U.S. and European security officials told Reuters on condition of anonymity that it was too early to say who might be behind the attacks, but they did not rule out North Korea as a suspect.