advertisement

Huge cyberattack ebbs as investigators work to find culprits

NEW YORK (AP) - The global cyberattack that took computer files hostage appeared to slow on Monday as authorities worked to catch the extortionists behind it - a difficult task that involves searching for digital clues and following the money.

Among their findings so far: The first suggestions of a possible link between the "ransomware" known as WannaCry and hackers linked to North Korea. Those findings remain quite tentative; one firm advancing them described them as intriguing but still "weak."

Experts had warned that WannaCry might wreak renewed havoc on Monday, particularly in Asia, which was closed for business on Friday when the malware scrambled data at hospitals, factories, government agencies, banks and other businesses.

But while there were thousands of additional infections there, the expected second-wave outbreak largely failed to materialize, in part because security researchers had already defanged it .

Mikko Hypponen, chief research officer for the Finnish security company F-Secure, said the perpetrators of WannaCry made one crucial mistake.

"The malware became too successful," Hypponen said. "When you are a cybercriminal gang and your mission is to make money, you don't want to infect 200,000 work stations. You don't want to end up on the covers of magazines. There will be no shortage of investigation."

ABOUT THAT NORTH KOREA LINK

WannaCry paralyzed computers running mostly older versions of Microsoft Windows in some 150 countries. It encrypted users' computer files and displayed a message demanding $300 to $600 worth of the digital currency bitcoin to release them; failure to pay would leave the data scrambled and likely beyond repair .

The Russian security firm Kaspersky Lab said Monday that portions of the WannaCry program use the same code as malware previously distributed by the Lazarus Group, a hacker collective behind the 2014 Sony hack blamed on North Korea.

But it's possible the code was simply copied from the Lazarus malware without any other direct connection. Kaspersky said "further research can be crucial to connecting the dots."

Another security company, Symantec, has also found similarities between WannaCry and Lazarus tools, and said it's "continuing to investigate for stronger connections."

FOLLOW THE MONEY

Researchers might find some additional clues in the bitcoin accounts accepting the ransom payments. There have been three accounts identified so far, and there's no indication yet that the criminals have touched the funds. But what good is money just sitting there as digital bits?

Although bitcoin is anonymized, researchers can watch it flow from user to user. So investigators can follow the transactions until an anonymous account matches with a real person, said Steve Grobman, chief technology officer with the California security company McAfee.

But that technique is no sure bet. There are ways to convert bitcoins into cash on the sly through third parties. And even finding a real person might be no help if they're in a jurisdiction that won't cooperate.

Another possible slip-up: Nicholas Weaver, who teaches networking and security at the University of California, Berkeley, said good ransomware usually generates a unique bitcoin address for each payment to make tracing difficult. That didn't seem to happen here.

TELL-TALE SIGNS

James Lewis, a cybersecurity expert at the Center for Strategic and International Studies in Washington, said U.S. investigators are collecting forensic information - such as internet addresses, samples of malware or information the culprits might have inadvertently left on computers - that could be matched with the handiwork of known hackers.

Investigators might also be able to extract some information about the attacker from a previously hidden internet address connected to WannaCry's "kill switch." That switch was essentially a beacon sending the message "hey, I'm infected" to the hidden address, Weaver said.

That means the very first attempts to reach that address, which might have been recorded by spy agencies such as the NSA or Russian intelligence, could lead to "patient zero" - the first computer infected with WannaCry. That, in turn, might further narrow the focus on possible suspects.

THE PLAYERS

Forensics, though, will only get investigators so far. One challenge will be sharing intelligence in real time to move as quickly as the criminals - a tricky feat when some of the major nations involved, such as the U.S. and Russia, distrust each other.

Even if the perpetrators can be identified, bringing them to justice could be another matter. They might be hiding out in countries that wouldn't be willing to extradite suspects for prosecution, said Robert Cattanach, a former U.S. Justice Department attorney and an expert on cybersecurity.

On the other hand, the WannaCry attack hit - and annoyed - many countries. Russia was among the hardest, and Britain among the most high-profile, and both have "some pretty good investigative capabilities," Cattanach said.

___

Lori Hinnant in Paris and Deb Riechmann in Washington contributed to this story.

FILE - In this May 13, 2017 file photo, a screenshot of the warning screen from a purported ransomware attack, as captured by a computer user in Taiwan, is seen on laptop in Beijing. Global cyber chaos is spreading Monday, May 14, as companies boot up computers at work following the weekend's worldwide "ransomware" cyberattack. The extortion scheme has created chaos in 150 countries and could wreak even greater havoc as more malicious variations appear. The initial attack, known as "WannaCry," paralyzed computers running Britain's hospital network, Germany's national railway and scores of other companies and government agencies around the world. (AP Photo/Mark Schiefelbein, File) The Associated Press
A patient takes a nap on her wheelchair as she waits with others at the registration desk at Dharmais Cancer Hospital in Jakarta, Indonesia, Monday, May 15, 2017 as the hospital's information system is in trouble by cyberattack. Global cyber chaos was spreading Monday as companies booted up computers at work following the weekend's worldwide "ransomware" cyberattack. The extortion scheme created chaos in 150 countries and could wreak even greater havoc as more malicious variations appear. (AP Photo/Dita Alangkara) The Associated Press
Patients wait at the registration desks at Dharmais Cancer Hospital in Jakarta, Indonesia, Monday, May 15, 2017. Global cyber chaos was spreading Monday as companies booted up computers at work following the weekend's worldwide "ransomware" cyberattack. The extortion scheme created chaos in 150 countries and could wreak even greater havoc as more malicious variations appear. (AP Photo/Dita Alangkara) The Associated Press
People walk in front of the headquarters building of Hitachi Ltd., center, in Tokyo, Monday, May 15, 2017. The global "ransomware" cyberattack hit computers at 600 locations in Japan, but appeared to cause no major problems as Japanese started their workday Monday even as the attack caused chaos elsewhere. Hitachi spokeswoman said emails were slow or not getting delivered, and files could not be opened. The company believes the problems are related to the ransomware attack, although no ransom appears to have been demanded so far. They were installing software to fix the problems. (AP Photo/Shizuo Kambayashi) The Associated Press
FILE - In this May 11, 2017 file photo, the emblem of a Nissan car is seen at its showroom in Tokyo. Japan has fallen victim of a global "ransomware" cyberattack that has created chaos in 150 countries. Nissan Motor Co. confirmed Monday, May 15, 2017, some units had been targeted, but there was no major impact on its business. (AP Photo/Eugene Hoshiko, File) The Associated Press
Patients wait near a banner informing about the delay in service put up at the registration desks at Dharmais Cancer Hospital in Jakarta, Indonesia, Monday, May 15, 2017. Dozens of the hospital's computer were hit by the global "ransomware" cyberattack on Saturday causing disruption to services and making patients had to wait longer while staff had to work with paper records. Writings on the banner read: "Currently there is a trouble on the hospital's information system caused by virus. We apologize to patients and visitors for the inconvenience caused. The problem is being resolved at the moment." (AP Photo/Dita Alangkara) The Associated Press
Article Comments
Guidelines: Keep it civil and on topic; no profanity, vulgarity, slurs or personal attacks. People who harass others or joke about tragedies will be blocked. If a comment violates these standards or our terms of service, click the "flag" link in the lower-right corner of the comment box. To find our more, read our FAQ.