WannaCry: End of Year Retrospective
blog.kryptoslogic.com
blog.kryptoslogic.com
This whole story only missed Secretary of State Colin Powell holding a model vial of anthrax and we could roll tanks onto North Korean soil already!
The infosec industry are extremely skeptical of attribution especially coming from government - it took a long time for a higher-certainty attribution to be established in the Sony and Bangladesh reserve bank cases, and there are still open cases of attribution in other incidents
Along with technical evidence, Wannacry also fits the North Korea m.o of financial incentive but also incentive to sow chaos[12], as well as how their attackers operate in Singapore and China and outsource some components.
On the contrary there is little to no evidence pointing anywhere else - meaning the second best probability of attribution for Wannacry is much further down the list.
The key difference there is that during the Iraq invasion there was zero corroborative evidence, the actual weapons inspectors said there was no evidence.
Further - the USA doesn't need a made-up pretext for war with North Korea. They're technically still at war and North Korea are in violation of UN Security Council resolutions and treaties (they routed around the UN for Iraq)
North Korea has sunk a ship[4], downed an airliner[5], attacked South Korean islands[6], tested nuclear weapons, developed a missile program, fired across the DMZ[7] (as recently again as today[8]), assassinated foreigners on foreign soil[9], been caught attempting to sell weapons of mass destruction[10], sold arms to Syria and others in violation of sanctions[11] and more. Either one of those is a stronger and not made-up pretext for an act of war - and one that would have much broader support than Iraq ever did.
[0] https://twitter.com/neelmehta/status/864164081116225536?lang...
[1] https://www.symantec.com/connect/blogs/wannacry-ransomware-a...
[2] https://blog.comae.io/wannacry-links-to-lazarus-group-dcea72...
[3] https://securelist.com/wannacry-and-lazarus-group-the-missin...
[4] https://en.wikipedia.org/wiki/ROKS_Cheonan_sinking
[5] https://en.wikipedia.org/wiki/Korean_Air_Flight_858
[6] https://en.wikipedia.org/wiki/Bombardment_of_Yeonpyeong
[7] http://edition.cnn.com/2017/11/21/asia/north-korea-defector/...
[8] http://www.bbc.com/news/world-asia-42435798
[9] https://en.wikipedia.org/wiki/Kim_Jong-nam
[10] http://www.smh.com.au/nsw/alleged-north-korean-agent-arreste...
[11] https://qz.com/962995/the-war-in-syria-has-been-great-for-no...
So, it's either a North Korean group, or a group shielding their identities pretending to be North Korean.
Given the lack of publicly available evidence linking the group to NK, and the sophistication of the majority of the things attributed to them, I personally have a very difficult time believing that NK would be capable of these things.. as this would mean extremely talented computer skills, which to develop would require unfettered access to the entire internet for extremely long periods of time, knowledge of several languages, and a host of skill sets that are not usually you'd associate with living in an oppressive regime that can barely keep the power on.
I'm going to go with Occam's razor on this one because it's far more likely that it's easier to pretend to be from NK than for NK to do what they are being accused of.
For all the hot air about "analysis" and "evidence" and crimes NK committed when Kim was a baby five presidents ago, it's extremely easy to know North Korea wasn't responsible for this:
Because the idea that any nation state could function in any capacity while simultaneously being so broke that a puny act of organized crime involving Bitcoins could make any difference is utterly beyond the realm of absurdity.
Nobody with even moderate critical faculties can seriously believe such a ridiculous premise, and the only thing anyone does by arguing it, sincerely or otherwise, is reduce their own credibility.
It's so bad for North Korea that they "sell" large groups of laborers to friendly countries to work in remote areas for the sole purpose of bringing exportable cash back to the country. https://www.vice.com/en_us/article/kwnw3w/north-korean-labor...
It's so bad for North Korea that for many years they operated a factory town on the border with their active enemy South Korea that used low payed North Korean workers to make goods to sell back to South Korea, under South Korean management for the sole purpose of bringing cash into the country. https://en.wikipedia.org/wiki/Kaesong_Industrial_Region
The list goes on.
The GDP of North Korea is estimated to be about $30 billion with the per capita income being around $1,000 per person. North Korea is deeply cash strapped, has few trading partners, and produces very little that anybody would want anyways. It doesn't take much money to move the needle. To not be aware of this is to not posses even remotely moderate critical faculties.
The list of what? Different ways in which the North Korean economy legitimately functions?
However "weird" you or the Washington Post think running a restaurant and remitting money back home is (or are they fronts for money laundering? the story can't seem to decide), or a country sending its workers abroad (look up the population of the UAE sometime), or operating a factory (?), all of those things are legitimate, legal and commonplace around the world, and in no way analogous to a Bitcoin ransomware attempt.
> The GDP of North Korea is estimated to be about $30 billion [...] It doesn't take much money to move the needle.
The amount made by WannaCry wouldn't even move the needle in the Bitcoin economy, never mind the economy of a nation state. Hell it wouldn't move the needle for some posters to HN.
If North Korea was that interested in acquiring cryptocurrency they could make far more simply running darknet markets or Bitcoin exchanges.
But - no - according to some people it makes far more sense to enact a convoluted and easily killswitched extortion scam with flashing neon arrows pointing straight back at them.
SMH
What are some examples of what you would consider evidence?
The only evidence available right now is code reuse tying similar attacks together, and since people aren't willing to assume that the Sony attack could have been anyone other than North Korea, the rest of these attacks and electronic bank heists 'must be them too'.
Call me skeptical, but this is too large of a pill for me to swallow at face value. We're talking about a country that is purchasing refrigerators but hasn't figured out how to reliably power them yet. [0]
[0] https://qz.com/95219/north-koreas-new-rich-love-buying-refri...
Marcy Wheeler just published this: https://www.emptywheel.net/2017/12/19/the-moneyless-attribut...
I am less concerned about ICBMs and more concerned about Tactical Nuclear Devices falling into the wrong hands. If the government of North Korea falls or weakens they could still fall into the wrong hands. (Same goes for Pakistan etc.)
And even if the government doesn't fall, they've already shown a willingness to help others get nukes:
Where are you getting this from? According to Wikipedia, every member of the UN is a party the GC, and North Korea has additionally ratified protocol I, something the USA refuses to do.
https://en.wikipedia.org/wiki/List_of_parties_to_the_Geneva_...
Pakistan is a different beast. I'm not an expert on the middle east by any means, but it seems to me a lot of nations around it could theoretically start the fight. I believe that would cause a US/Indian/China intervention, if not on behalf of Pakistan (in the case of Chinese and Indian territorial disputes), then in defense of their own interests in the region (the territory).
NK != North Korea
NK == Naughty Kids