Live data from Hacker News

Countering threats from North Korea

blog.google

31–40 of 172 posts

Re: Countering threats from North Korea

#31
post #4

Earlier quoted context omitted.

We see some of this with just normal spear phishing against companies. The "single click" thing is reasonably common, it makes things a bit harder to catch as often the clickthrough will change to whatever is being spoofed in the first place. A homophone ycornbinator.com would serve the malware first time, then next time it would send a permanent redirect. Unique IDs you'll see in things like spam SMS, both to work a…

Thanks for the input. A nit, sorry, but maybe relevant to readers learning a little about anti-phishing: homophones sound the same ('-phone' refers to sound, like telephone) but differ in meaning, such as 'write' and 'right'. I don't know the term for ycombinator.com / ycornbinator.com, which is a real problem, of course.

It's a homoglyph https://en.m.wikipedia.org/wiki/Homoglyph

Typically used via poorly named idn homograph attacks https://en.m.wikipedia.org/wiki/IDN_homograph_attack

Re: Countering threats from North Korea

#32
post #11

Earlier quoted context omitted.

I think you misunderstood - they’re saying the links served nothing, presumably because it’s a Chrome-specific exploit.

Or potentially there were exploits but they weren't able to encounter them due to the various protection measures the attackers used.

Either way, I find it very hard to believe that they haven’t coordinated with Apple and Mozilla on this CVE.

Re: Countering threats from North Korea

#35
post #6

What evidence do they have that suggests these threats are coming from North Korea?

A statement from Google.

And even when knowing how a country or particular state-backing is identified, there is nothing preventing other hackers from adding the same markers to their own software

Re: Countering threats from North Korea

#36

Quoted post unavailable.

Because of the various safeguards:

> Only serving the iframe at specific times, presumably when they knew an intended target would be visiting the site.

> In some email campaigns the targets received links with unique IDs. This was potentially used to enforce a one-time-click policy for each link and allow the exploit kit to only be served once.

> The exploit kit would AES encrypt each stage, including the clients’ responses with a session-specific key.

> Additional stages were not served if the previous stage failed.

it was hard to collect the exploits. They only managed to collect the Chrome one.

Compare this to Pegasus, malware that attacks both iOS and Android. So far researchers have only been able to collect iOS versions.

I think it's a little funny that you're complaining that a Google security group (TAG in this case) is publicly reporting vulnerabilities in a Google product, but not others. With Project Zero (a different Google security group), people usually complain in the opposite way, and say that it's bad for Google to publicly report a lot of vulnerabilities in competitor products, because it makes competitors look bad and is just done for publicity reasons.

Disclosure, I work at Google, but not on anything related to this.

Re: Countering threats from North Korea

#37

Earlier quoted context omitted.

Thanks for the input. A nit, sorry, but maybe relevant to readers learning a little about anti-phishing: homophones sound the same ('-phone' refers to sound, like telephone) but differ in meaning, such as 'write' and 'right'. I don't know the term for ycombinator.com / ycornbinator.com, which is a real problem, of course.

It's a homoglyph https://en.m.wikipedia.org/wiki/Homoglyph Typically used via poorly named idn homograph attacks https://en.m.wikipedia.org/wiki/IDN_homograph_attack

Technically ycornbinator.com is just a lookalike.

Homographs look exactly the same.

(And of course "homograph" ["same writing" or "same picture"] is a better name than "homoglyph" ["same carving"].)

Re: Countering threats from North Korea

#38

Earlier quoted context omitted.

A statement from Google.

I'm actually surprised Google would say this is from the DPRK government without also saying it had has been verified by US federal government authorities. Usually they leave it for others to deal with statements at that level.

No post body was provided.

Re: Countering threats from North Korea

#39

Earlier quoted context omitted.

It's a homoglyph https://en.m.wikipedia.org/wiki/Homoglyph Typically used via poorly named idn homograph attacks https://en.m.wikipedia.org/wiki/IDN_homograph_attack

Technically ycornbinator.com is just a lookalike. Homographs look exactly the same. (And of course "homograph" ["same writing" or "same picture"] is a better name than "homoglyph" ["same carving"].)

That's fair I'm not really one for jargon and whatnot (I think it can actually become less useful if the goal is just to communicate something to a person), but the first line in wiki says:

> a homoglyph is one of two or more graphemes, characters, or glyphs with shapes that appear identical or very similar.

"Very similar" and "two or more" being the key words.

As for homograph I found homoglyph by reading the wiki and it saying homoglyph is more appropriate.

(Insert obligatory "wiki it's not always accurate etc etc"). Overall I'd take either one and personally don't care. Just trying to match what you're saying with what I'm reading and make sense of where the truth is.

Re: Countering threats from North Korea

#40

Earlier quoted context omitted.

Countries have been doing terrible things to people since long before the internet

True but before the internet it was limited to the locality. The internet feels like a public park that gets trashed by folks all across the world and not just by the neighbors. (Just to be clear, I sympathize with your point as well)

[deleted]
Post reply on HN