US declares North Korea was behind huge WannaCry cyberattack
The attack originally looked like a ransomware campaign. Some experts later concluded the ransom threat may have been a distraction intended to disguise a more destructive intent
The United States has officially accused North Korea of carrying out the massive WannaCry attack that infected some 300,000 computers in 150 countries earlier this year.
North Korea was widely suspected of being behind the computer virus and ransomware, which demanded payment to restore access. It has been denounced as such by Britain, but the United States had yet to follow suit.
Homeland Security Advisor Tom Bossert made the announcement in a Wall Street Journal op-ed, and was expected to provide more details in a briefing with reporters early Tuesday.
“The attack was widespread and cost billions, and North Korea is directly responsible,” he wrote.
“We do not make this allegation lightly. It is based on evidence.”
Bossert said Facebook and Microsoft helped in thwarting the North Korean attacks.
“Facebook took down accounts that stopped the operational execution of ongoing cyber attacks and Microsoft acted to patch existing attacks, not just the WannaCry attack initially,” White House homeland security adviser Tom Bossert said on Tuesday.
Bossert did not provide details on the actions by the two American tech heavyweights but said the US government was calling on other companies to cooperate in cyber security defence.
“North Korea has acted especially badly, largely unchecked, for more than a decade, and its malicious behavior is growing more egregious. WannaCry was indiscriminately reckless.”
He said Washington must lead efforts to cooperate with other governments and businesses to “mitigate cyber risk and increase the cost to hackers,” and thus improve internet security and resilience.
Among the infected computers were those at Britain’s National Health Service (NHS), Spanish telecoms company Telefonica and US logistics company FedEx.
“These disruptions put lives at risk,” Bossert wrote.
“When we must, the US will act alone to impose costs and consequences for cyber malfeasance,” Bossert added.
US President Donald Trump “has already pulled many levers of pressure to address North Korea’s unacceptable nuclear and missile developments, and we will continue to use our maximum pressure strategy to curb Pyongyang’s ability to mount attacks, cyber or otherwise.”
Watch: IT expert who cracked virus says he’s no hero
The WannaCry attack spread rapidly around the globe using a security flaw in Microsoft’s Windows XP operating system, an older version that is no longer given mainstream tech support by the US giant.
Ransomware, which can be used on PCs as well as tablets and smartphones, is malicious software which locks computer files and forces users to pay the attackers a designated sum in the virtual bitcoin currency to regain access to the files.
The Washington Post cited a US official as saying Trump’s administration would be urging allies to counter North Korea’s cyberattack capabilities and implement all “relevant” UN Security Council sanctions.
It said the CIA had already laid blame on North Korea for the attack in November, though the assessment was classified and had not yet been previously reported.