Skip to content
Search

Latest Stories

Google researcher links ransomware attack to North Korea

An security researcher with Google has found evidence suggesting that North Korean hackers may have carried out the "unprecedented" ransomware cyberattack that hit over 150 countries, including India.

Neel Mehta has published a code which a Russian security firm has termed as the "most significant clue to date", the BBC reported today.


The code, published on Twitter, is exclusive to North Korean hackers, researchers said.

Researchers have said that some of the code used in Friday's ransomware, known as WannaCry software, was nearly identical to the code used by the Lazarus Group, a group of North Korean hackers who used a similar version for the devastating hack of Sony Pictures Entertainment in 2014 and the last years hack of Bangladesh Central Bank.

Security experts are now cautiously linking the Lazarus Group to this latest attack after the discovery by Mehta.

Mehta has found similarities between code found within WannaCry and other tools believed to have been created by the Lazarus Group in the past, BBC reported.

Security expert Prof Alan Woodward said that time stamps within the original WannaCry code are set to UTC +9 - China's time zone - and the text demanding the ransom uses what reads like machine-translated English, but a Chinese segment apparently written by a native speaker, the report said.

"As you can see it is pretty thin and all circumstantial. However, it is worth further investigation," Woodward said.

"Neel Mehta's discovery is the most significant clue to date regarding the origins of WannaCry," said Russian security firm Kaspersky, but noted a lot more information is needed about earlier versions of WannaCry before any firm conclusion can be reached, it reported.

"We believe it is important that other researchers around the world investigate these similarities and attempt to discover more facts about the origin of WannaCry," it said.

Attributing cyberattacks can be notoriously difficult - often relying on consensus rather than confirmation, the report said.

North Korea has never admitted any involvement in the Sony Pictures hack - and while security researchers, and the US government, have confidence in the theory, neither can rule out the possibility of a false flag, it said.

Skilled hackers may have simply made it look like it had origins in North Korea by using similar techniques.

In the case of WannaCry, it is possible that hackers simply copied code from earlier attacks by the Lazarus Group.

"There's a lot of ifs in there. It wouldn't stand up in court as it is. But its worth looking deeper, being conscious of confirmation bias now that North Korea has been identified as a possibility," Woodward said.

Its the strongest theory yet as to the origin of WannaCry, but there are also details that arguably point away from it being the work of North Korea.

First, China was among the countries worst hit, and not accidentally - the hackers made sure there was a version of the ransom note written in Chinese. It seems unlikely North Korea would want to antagonise its strongest ally. Russia too was badly affected, the report said.

Second, North Korean cyber-attacks have typically been far more targeted, often with a political goal in mind.

In the case of Sony Pictures, hackers sought to prevent the release of The Interview, a film that mocked North Korean leader Kim Jong-Un. WannaCry, in contrast, was wildly indiscriminate - it would infect anything and everything it could, the report said.

Finally, if the plan was simply to make money, its been pretty unsuccessful on that front too - only around $60,000 has been paid in ransoms, according to analysis of Bitcoin accounts being used by the criminals.

With more than 200,000 machines infected, its a terrible return, the report said.

On Friday, Europol Director Rob Wainwright said: "The global reach is unprecedented. The latest count is over 200,000 victims in at least 150 countries and those victims many of those will be businesses including large corporations".

The most disruptive attacks were reported in the UK, where hospitals and clinics were forced to turn away patients after losing access to computers.

More For You

Labour Rift Deepens as MPs Prepare for Crucial Welfare Bill Vote

People take part in a protest against disability welfare cuts on June 30, 2025 in London. (Photo: Getty Images)

Getty Images

MPs to vote on welfare bill amid Labour divisions

DOZENS of Labour MPs are expected to vote against the government’s welfare reforms despite recent concessions aimed at easing opposition.

The government had initially planned to tighten eligibility for Personal Independence Payment (Pip) but later said the stricter rules would only apply to new claimants from November 2025.

Keep ReadingShow less
We The Women makes UK debut with stories of courage and truth

Sudha Murthy and Karan Johar

Image Credits: Barkha Dutt / We The Women / Mojo Story

We The Women makes UK debut with stories of courage and truth

Mahesh Liloriya

The acclaimed women-led festival We The Women, curated by veteran journalist Barkha Dutt, made its powerful UK debut on June 29 at London’s Riverside Studios. Presented in partnership with Vedanta, the event brought together transformative voices from India and the British-Indian diaspora, showcasing unfiltered, emotional, and often raw storytelling.

Among the standout moments was Rashmika Mandanna’s candid discussion on her values-first approach to fame. The actor received thunderous applause when she shared, “I’ve said no to scripts because they required me to smoke. If I don’t feel good about something, I won’t do it.” Her firm stance echoed the festival’s core ethos, prioritising authenticity over popularity.

Keep ReadingShow less
Telangana-blast-Reuters

Rescue workers look for survivors after an explosion and fire at a chemical factory, in Sangareddy, Telangana, India, June 30, 2025. (Photo: Reuters)

Reuters

India chemical factory blast death toll rises to 39, probe underway

THE DEATH toll from the explosion and fire at the Sigachi Industries chemical factory in Sangareddy, Telangana, has risen to at least 39, officials said on Tuesday, as rescue teams continued clearing debris for a second day.

The explosion occurred on Monday and turned large parts of the building into rubble. State authorities confirmed the toll had risen to 39, Reuters reported. Thirty-four others were injured in the incident, according to officials.

Keep ReadingShow less
Covid inquiry begins probe into care home deaths

FILE PHOTO: A mother and daughter sit atop the Covid memorial wall on September 9, 2024 in London, England. (Photo by Carl Court/Getty Images)

Covid inquiry begins probe into care home deaths

THE Covid inquiry has started examining how the pandemic affected care services for older and disabled people, with families describing the crisis as one of the worst failures of the pandemic.

Nearly 46,000 care home residents died with Covid in England and Wales between March 2020 and January 2022, with many deaths happening in the first weeks of the outbreak.

Keep ReadingShow less
Starmer and Glastonbury condemn anti-Israel chants by Bob Vylan

Keir Starmer speaks to members of the media during a visit to RAF Valley, on Anglesey in north-west Wales, on June 27, 2025. PAUL CURRIE/Pool via REUTERS

Starmer and Glastonbury condemn anti-Israel chants by Bob Vylan

PRIME MINISTER Keir Starmer and Glastonbury organisers said on Sunday (29) they were appalled by on-stage chanting against the Israeli military during a performance at the festival by Punk-rap duo Bob Vylan.

During their show on Saturday (28), the duo chanted "Death, death, to the IDF" in reference to the Israel Defense Forces, the formal name of the Israeli military.

Keep ReadingShow less