A recent strain of ransomware, called VHD, can be linked to an unusual source: The Lazarus Group APT. Researchers from Kaspersky say VHD has only been deployed in a handful of instances. VHD is written in C++ and encrypts files on all connected disks, the analysis determined. It also deletes any folder called System Volume Information (which are linked to Windows restore point feature) Researchers were able to observe a backdoor used in a series of attacks involving the MATA malware.
Source: https://threatpost.com/lazarus-group-apt-tactics-ransomware/157815/