Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Virulent WCry ransomware worm may have North Korea’s fingerprints on it (arstechnica.com)
4 points by nyolfen on May 15, 2017 | hide | past | favorite | 1 comment


Oh yeah, this is exactly how the Lazarus Group — one of the most sophisticated hacking outfits — would have designed their ransomware. Zero code obfuscation, just 3 Bitcoin addresses, and hardcoded kill switches. I never imagined I would be able to hex-edit cyber-espionage-grade malware. Times are a changing.

Claiming that a few generic code routines are identical to Lazarus hacking tools is like calling every malware that uses RC4 or RC5 an NSA cyber-weapon.

This is just some hype created by Kaspersky's PR.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: