Skip to main content

WannaCry Ransomware Hackers Are Most Likely From China


WANNACRY RANSOMWARE CHINA
Since the arrival of WannaCry ransomware, the researchers have been unable to find the exact forces behind the attack. A new analysis by Flashpoint highlights the possibility of WannaCry’s affiliation to Chinese hackers. The firm performed a linguistic analysis of
ransom notes in WannaCry samples and arrived at this conclusion.
There are some things we know about WannaCry ransomware for sure. It was created by cyber criminals using an exploit that was the part of NSA’s exploit leaked by a group named The Shadow Brokers. The ransomware went on to affect hundreds of thousands of computers running Windows 7, Vista, and XP.
It’s possible that we may never know about the exact creators of this ransomware who locked the PCs of innocent users and demanded ransom. But, a recent research from the security firm Flashpoint points a finger towards a Chinese connection.
In a blog post, Flashpoint has listed the results of its linguistic analysis of WannaCry ransomware messages. The team analyzed the ransom notes individually for content, accuracy, and style.
Flashpoint found that WannaCry samples had language configuration files with translated message in different languages. It was found that almost all notes were translated using Google Translate. Only one English and two Chinese notes were likely to have been written by a human. It was also found that the English note was used as the source text for other translation and its writer could’ve been non-native.WANNACRY RANSOMWARE CHINA
Coming back to the two Chinese notes, they were different from each other in format, content, and tone. Google Translate also fails in Chinese-English and English-Chinese conversion tests.
The analysis revealed certain unique characteristics that indicate that a Chinese expert wrote it. A specific typo made it clear that the note was written using a Chinese-input system. The Chinese note also used proper grammar, punctuation, and syntax.
The text has certain terms that narrow things down to Southern China. A compelling indicator was the lengthiness of the Chinese note.
While Flashpoint underlines the possibility of a China-based force, they don’t forget to mention that such hints were intentionally included to mislead. You can read about the research in detail here.
Did you find this update on WannaCry Ransomware helpful? Don’t forget to share your views.

Comments

Follow Us

WHAT'S HOT

Fedora Project Finally Releases Fedora 27 Beta And “Rock Solid” FreeBSD 10.4

After a few hiccups and delays, the Fedora Project has finally shipped the beta release for Fedora 27 Linux distro. This is a major milestone before the final version ships later this year in

How To Connect Android or iOS Phone To Windows 10

The  Continue on PC  feature is currently available to Windows Insiders, but it’ll arrive for regular users once the update starts landing on their PCs. If you’re running an Insider build, you can use the steps mentioned in this post to connect your phone to Windows 10 PC.

Android Oreo Update Will Arrive On All Nokia Android Smartphones

While there seems to be a suspense regarding  which devices would get the Android Oeo update , HMD Global has raised the curtain from their fleet of smartphones.

Extratorrent Brought Back From The Dead By Fans, Now Running On A New Domain

I t was merely a couple of days back when the shutdown of the torrent website  Extratorrent.cc was announced . Now, a group of uploaders and Extratorrent admins claim to have revived the torrent site on a new domain  Extratorrent.cd .