WannaCry ended up being one of the biggest ransomware messes the world’s seen. Started spreading May 12, 2017, hit computers across dozens of countries almost overnight. Hospitals got hit hard, which is a big reason it felt so serious so fast. So who actually did it?

Short answer, the Lazarus Group. Widely tied to North Korea. The US made it official in December 2017, blamed North Korea directly. UK said the same thing. Researchers had already been landing on similar conclusions just from poking at the malware itself.

The Group Behind WannaCry

Lazarus is basically the name people use for a big cyber-espionage and cybercrime operation connected to North Korea. Tied to a bunch of major attacks over the years, WannaCry being maybe the most famous, though who actually wrote every piece of the code, nobody’s fully sure.

Worth pausing on that. North Korea being blamed doesn’t mean someone found one guy at a keyboard. Lazarus is thought to involve multiple people, multiple operations, all loosely tied to state interests.

Why Investigators Pointed to Lazarus

Researchers spotted similarities between WannaCry and older malware already linked to Lazarus. Some early WannaCry samples even had code that looked like stuff from earlier attacks tied to the group.

None of that proves anything by itself. Code habits, certain techniques, reused chunks, it’s circumstantial. But stack enough of it together and it builds a case.

The Role of the EternalBlue Exploit

WannaCry spread through a Windows flaw called EternalBlue, reportedly built by the NSA, later leaked by the Shadow Brokers. Microsoft had already patched it before WannaCry blew up. Plenty of machines just never got the update. So the attack didn’t happen because EternalBlue existed somewhere, Lazarus allegedly grabbed a leaked exploit and used it to make WannaCry spread way faster than ransomware normally does.

Was North Korea Proven to Be Behind It?

Attribution’s solid, but cyberattacks don’t come with receipts. US and UK both pointed at North Korea publicly, researchers found technical threads back to Lazarus, North Korea denied it, obviously.

Why the Attribution Still Matters

What’s actually interesting is how many pieces had to line up. Someone wrote the ransomware. Someone grabbed a leaked exploit. A mountain of unpatched machines sat there waiting. Then it all moved fast, faster than anyone expected. That speed’s the part people remember, one unpatched computer and suddenly it’s part of something way bigger than its owner ever realized.

Eventually a researcher stumbled onto a kill switch buried in the code and things slowed down. Didn’t undo what already happened though. WannaCry had already shown just how fast one attack could jump across borders.