4 ms·
It's not been fully confirmed/established that Lazarus group == DPRK: see "false flag" from Kaspersky researchers https://www.wired.com/2017/05/wannacry-ransomw
by cottsak 9y ago
It's not been fully confirmed/established that Lazarus group == DPRK: see "false flag" from Kaspersky researchers https://www.wired.com/2017/05/wannacry-ransomware-link-suspected-north-korean-hackers/ https://www.wired.com/2017/05/wannacry-ransomware-link-suspe...
- openasocket 9y agoIn that link they only raise doubts about Lazarus being behind WannaCry, not Lazarus being associated with the DPRK. And the Kapersky researchers' quote says that this being a false flag is "possible" but "improbable"
- cottsak 9y agoAgreed, confirming that there is no public evidence which hard links Lazarus to DPRK. Just want everyone to know the facts.
- deleted 9y ago[deleted]
- openasocket 9y agoWhat would a "hard link" be? A signed confession from the head of the DPRK military? Under the circumstances, barring classified intelligence (like the NSA may have), we are as sure as we can be.
- quakeguy 9y agoSo we are unsure.
- openasocket 9y agoOut of curiosity, what evidence would convince you?
- tracked24x7 9y agoCollin Powell got quite a lot of tonnage I mean mileage out of a cartoon drawing. Just draw him a picture.
- boomboomsubban 9y agoAbsolute certainty that this would not be used as an excuse to launch military attacks would be a start.
- Sacho 9y agoI don't know - isn't this an issue with the erosion of trust towards the administration and "domain experts", something they can only blame themselves for? More importantly, why do you want people to be convinced of this? What difference does it make? If it is used as some sort of justification for (more?) economic sanctions or an attack, then I don't think any realistic hacking attempt is going to be enough. If you just want this attributed to NK, what is the point? If people don't know enough about the situation to be sure, and they have no trust in any authority on the subject, then the way forward would be for an authority to build up trust with those people and then claim it is attributed to NK.
- mirimir 9y agoWho is "we" here? There are many levels of bullshit between knowledgeable folk at NSA and me. Far too many for me to be sure of anything.
- mirimir 9y agoPeople are discounting, I think, the lulz factor in pretending to be working for NK. Just sayin'.
- mc32 9y agoYeah, I don't know. People tend to believe the narrative story they want to believe. When someone claims "the Russians" hacked the DNC and other operatives, there is very little "false flag" ("how do you know it really was the Russians?") claims (and for good reason), but when something does not fit their belief systems then it's "oh, false flag" despite reputable researchers putting their reputation on the line.
- losteric 9y agoIt's about broader context, or a lack thereof. The DNC hack is self-consistent and aligned with known motives of suspected actors, so the public sees a false flag as possible but improbable. WannaCry came seemingly out of nowhere using a mixed bag of tricks from unfamiliar actors... absent context, the public will entertain any explanation.
- mc32 9y agoThat's a logical and plausible explanation for rational thinkers --I don't think I'm going out on a limb saying if it fit people's narrative preference, they'd say that "it fit too well", how can the Russians, so capable, leave so obvious trails, it must have been the Ukranians (or some other realistically unlikely but fitting a narrative). The N Korea thing was the same even under Obama (the Sony hack) people wanted to believe the US was just trying to make the N Koreans "look bad" or create excuses for something (as if N KOrea needed any help in that regard).
- meowface 9y ago>In its blog post, Kaspersky acknowledged that the repetition of the code could be a "false flag" meant to mislead investigators and pin the attack on North Korea. After all, the WannaCry authors cribbed techniques from the NSA as well. The ransomware leverages an NSA exploit known as EternalBlue that a hacker group known as Shadow Brokers made public last month. >Kaspersky called that false flag scenario "possible" but "improbable." This is more a standard disclaimer of any intelligence analyst than a serious qualification in this case. When trying to attribute something that allows easy copycats, an investigator will obviously constantly be thinking "is this clue genuine or intentionally placed to suggest a different origin"? And without an incredible amount of evidence, it's hard to definitively say certain malware or tools were written or used by a particular entity.
- mythrwy 9y agoI don't see false flag being reasonable in this case. The public sentiment gains from drumming up a case against NK aren't measurably enhanced by this enough to justify the effort. I wouldn't think. But one never knows.