Live data from Hacker News

Countering threats from North Korea

blog.google

11–20 of 172 posts

Re: Countering threats from North Korea

#12
post #11

Quoted post unavailable.

I think you misunderstood - they’re saying the links served nothing, presumably because it’s a Chrome-specific exploit.

Or potentially there were exploits but they weren't able to encounter them due to the various protection measures the attackers used.

Re: Countering threats from North Korea

#13
post #2

> Careful to protect their exploits, the attackers deployed multiple safeguards to make it difficult for security teams to recover any of the stages. These safeguards included: * Only serving the iframe at specific times, presumably when they knew an intended target would be visiting the site. * In some email campaigns the targets received links with unique IDs. This was potentially used to enforcea one-time-click po…

Much of it seems like normal ad-tech practice to identify individuals and discourage click-farming. Unique keys sent in an email campaign? Oh my scaaary stuff.

Re: Countering threats from North Korea

#16

I am so fucking done with the internet turning into a trash pile of scams and exploits.

Countries have been doing terrible things to people since long before the internet

True but before the internet it was limited to the locality. The internet feels like a public park that gets trashed by folks all across the world and not just by the neighbors. (Just to be clear, I sympathize with your point as well)

Re: Countering threats from North Korea

#19
post #4

Earlier quoted context omitted.

We see some of this with just normal spear phishing against companies. The "single click" thing is reasonably common, it makes things a bit harder to catch as often the clickthrough will change to whatever is being spoofed in the first place. A homophone ycornbinator.com would serve the malware first time, then next time it would send a permanent redirect. Unique IDs you'll see in things like spam SMS, both to work a…

I am receiving increased SMS spam past week. Is connected to this exploit? Msgs are all different domains with unique ID appended.

Me too, receiving spam job offers with bit.ly links.

Re: Countering threats from North Korea

#20
post #2

> Careful to protect their exploits, the attackers deployed multiple safeguards to make it difficult for security teams to recover any of the stages. These safeguards included: * Only serving the iframe at specific times, presumably when they knew an intended target would be visiting the site. * In some email campaigns the targets received links with unique IDs. This was potentially used to enforcea one-time-click po…

For targeted ones I think it is. The details that emerged around SolarWinds were quite sophisticated in terms of execution, timing, hiding, and cleanup.
Post reply on HN