North Korean hacking group behind WannaCry apparently expanding into ransomware, Kaspersky says. Lazarus Group has also carried out online bank and cryptocurrency heists on behalf of the government of North Korea. VHD Ransomware appears to be the work of the Lazarus Group, the security firm says. The VHD ransomware uses a framework called MATA to deliver the final payload to encrypt files, the report says. It also uses techniques that enable it to move laterally across a network – techniques similar to those found in other malware deployed by Lazarus Group.”]
Source: https://www.databreachtoday.com/lazarus-group-reportedly-now-wielding-ransomware-a-14731