Countering threats from North Korea
161–170 of 172 posts
Re: Countering threats from North Korea
#162> Careful to protect their exploits, the attackers deployed multiple safeguards to make it difficult for security teams to recover any of the stages. These safeguards included: * Only serving the iframe at specific times, presumably when they knew an intended target would be visiting the site. * In some email campaigns the targets received links with unique IDs. This was potentially used to enforcea one-time-click po…
For CVEs? No. CVEs are awarded for things as (relatively) little as static keys being packaged with APKs. What is unusual is that NK used a sophisticated attack chain to successfully pwn a hardened industry (notably, fintech). At this point I think it’s safe to say that NK is a significant competitor to FVEY in terms of cyber warfare capabilities.
Re: Countering threats from North Korea
#163Earlier quoted context omitted.
For CVEs? No. CVEs are awarded for things as (relatively) little as static keys being packaged with APKs. What is unusual is that NK used a sophisticated attack chain to successfully pwn a hardened industry (notably, fintech). At this point I think it’s safe to say that NK is a significant competitor to FVEY in terms of cyber warfare capabilities.
I would say this isn’t necessarily unusual for NK. As far as I know, they’re the only nation state actor known to hack for profit and they’ve committed several of the largest cyber bank robberies ever. Nation state actors have an _incredible_ amount of time, resources, and motivation.
Re: Countering threats from North Korea
#164Earlier quoted context omitted.
I don’t work in this field, but my impression has been that groups tend to share techniques and code patterns that can help tie them back to where they came from.
But how do you know the origin?
Re: Countering threats from North Korea
#165Re: Countering threats from North Korea
#166Will WebAssembly save us from this kind of CVEs? assuming it has capabilities to support "modern" web
Re: Countering threats from North Korea
#167Re: Countering threats from North Korea
#168Earlier quoted context omitted.
When I have a spammer/scammer on the phone (and I actually picked up), I usually just put my phone on mute and stop talking to them. They waste a bit more time that way before they hang up (without more effort from me).
I try to help them out by letting them know that I have been trying to reach them about their car's extended warranty.
Re: Countering threats from North Korea
#169Earlier quoted context omitted.
I live in Germany and I get a lot of spam calls and spam SMS. It's always in waves. Some days I stop answering calls if I don't recognise the number, because its one of these days where Interpol has informwd me already three times that my identity was stolen and I have to give them all my details to fix this ..... They're very patient at Interpol, I keep hanging up on them and they never give up.
When I have a spammer/scammer on the phone (and I actually picked up), I usually just put my phone on mute and stop talking to them. They waste a bit more time that way before they hang up (without more effort from me).
Re: Countering threats from North Korea
#170Earlier quoted context omitted.
Only in the US (or whole NANP?) Mobile numbers are non-geographic everywhere else that I know of.
Well, depends. For example, Singapore's numbers are 'non-geographic' in that sense. But Singapore itself is small enough.