Neel Mehta has published a code which a Russian security firm has termed as the "most significant clue to date", BBC reported today.
The code, published on Twitter, is exclusive to North Korean hackers, researchers said.
Researchers have said that some of the code used in Friday's ransomware, known as WannaCry software, was nearly identical to the code used by the Lazarus Group, a group of North Korean hackers who used a similar version for the devastating hack of Sony Pictures Entertainment in 2014 and the last year's hack of Bangladesh Central Bank.
Mehta has found similarities between code found within WannaCry and other tools believed to have been created by the Lazarus Group in the past, BBC reported.
Security expert Prof Alan Woodward said that time stamps within the original WannaCry code are set to UTC +9 - China's time zone - and the text demanding the ransom uses what reads like machine-translated English, but a Chinese segment apparently written by a native speaker, the report said.
"As you can see it is pretty thin and all circumstantial. However, it is worth further investigation," Woodward said.
"We believe it is important that other researchers around the world investigate these similarities and attempt to discover more facts about the origin of WannaCry," it said.
Attributing cyberattacks can be notoriously difficult - often relying on consensus rather than confirmation, the report said.
North Korea has never admitted any involvement in the Sony Pictures hack - and while security researchers, and the US government, have confidence in the theory, neither can rule out the possibility of a false flag, it said.
In the case of WannaCry, it is possible that hackers simply copied code from earlier attacks by the Lazarus Group.
"There's a lot of ifs in there. It wouldn't stand up in court as it is. But it's worth looking deeper, being conscious of confirmation bias now that North Korea has been identified as a possibility," Woodward said.
It's the strongest theory yet as to the origin of WannaCry, but there are also details that arguably point away from it being the work of North Korea.
Second, North Korean cyber-attacks have typically been far more targeted, often with a political goal in mind.
In the case of Sony Pictures, hackers sought to prevent the release of The Interview, a film that mocked North Korean leader Kim Jong-Un. WannaCry, in contrast, was wildly indiscriminate - it would infect anything and everything it could, the report said.
With more than 200,000 machines infected, it's a terrible return, the report said.
On Friday, Europol Director Rob Wainwright said, "The global reach is unprecedented. The latest count is over 200,000 victims in at least 150 countries and those victims many of those will be businesses including large corporations".
The most disruptive attacks were reported in the UK, where hospitals and clinics were forced to turn away patients after losing access to computers.
Disclaimer: No Business Standard Journalist was involved in creation of this content
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
