Live data from Hacker News

Countering threats from North Korea

blog.google

161–170 of 172 posts

Re: Countering threats from North Korea

#162
post #2

> Careful to protect their exploits, the attackers deployed multiple safeguards to make it difficult for security teams to recover any of the stages. These safeguards included: * Only serving the iframe at specific times, presumably when they knew an intended target would be visiting the site. * In some email campaigns the targets received links with unique IDs. This was potentially used to enforcea one-time-click po…

For CVEs? No. CVEs are awarded for things as (relatively) little as static keys being packaged with APKs. What is unusual is that NK used a sophisticated attack chain to successfully pwn a hardened industry (notably, fintech). At this point I think it’s safe to say that NK is a significant competitor to FVEY in terms of cyber warfare capabilities.

I would say this isn’t necessarily unusual for NK. As far as I know, they’re the only nation state actor known to hack for profit and they’ve committed several of the largest cyber bank robberies ever. Nation state actors have an _incredible_ amount of time, resources, and motivation.

Re: Countering threats from North Korea

#163

Earlier quoted context omitted.

For CVEs? No. CVEs are awarded for things as (relatively) little as static keys being packaged with APKs. What is unusual is that NK used a sophisticated attack chain to successfully pwn a hardened industry (notably, fintech). At this point I think it’s safe to say that NK is a significant competitor to FVEY in terms of cyber warfare capabilities.

I would say this isn’t necessarily unusual for NK. As far as I know, they’re the only nation state actor known to hack for profit and they’ve committed several of the largest cyber bank robberies ever. Nation state actors have an _incredible_ amount of time, resources, and motivation.

Indeed. The amount of skill they've demonstrated as Lazarus (Lazarus Leaks (Vault 7), the Bangladesh Bank Heist, and Dark Seoul) is certainly notable and this seems to fit well within their MO.

Re: Countering threats from North Korea

#164

Earlier quoted context omitted.

I don’t work in this field, but my impression has been that groups tend to share techniques and code patterns that can help tie them back to where they came from.

But how do you know the origin?

By connecting multiple details such as ip addresses, connection/flow logs, known CnC servers, etc. You seem to be expecting some magic simple answer but the reality is the same as other investigative work: doing the work in the details as a professional. Just because this work is difficult and inherently has some ambiguity doesn't mean you can just dismiss every attribution from your armchair.

Re: Countering threats from North Korea

#165
post #158

Earlier quoted context omitted.

Why do you have to prefix your question with, "Here’s a question I expect you’ll never answer"?

I don’t have to, it just makes me look good when he never answers.

No, it does not.

Re: Countering threats from North Korea

#166

Will WebAssembly save us from this kind of CVEs? assuming it has capabilities to support "modern" web

I'm not sure WASM buys you anything you couldn't already get by just running your whole entire app in a VM. And if walling an app off in a VM makes it not useful (i.e. it's not useful if all it has access to is network & sandboxed storage) then using WASM in a browser would have similar issues. Or if a VM adds too much performance penalty then WASM probably does too.

Re: Countering threats from North Korea

#168
post #140

Earlier quoted context omitted.

When I have a spammer/scammer on the phone (and I actually picked up), I usually just put my phone on mute and stop talking to them. They waste a bit more time that way before they hang up (without more effort from me).

I try to help them out by letting them know that I have been trying to reach them about their car's extended warranty.

That's fun, when you have the time and want to spend it.

Re: Countering threats from North Korea

#169
post #140

Earlier quoted context omitted.

I live in Germany and I get a lot of spam calls and spam SMS. It's always in waves. Some days I stop answering calls if I don't recognise the number, because its one of these days where Interpol has informwd me already three times that my identity was stolen and I have to give them all my details to fix this ..... They're very patient at Interpol, I keep hanging up on them and they never give up.

When I have a spammer/scammer on the phone (and I actually picked up), I usually just put my phone on mute and stop talking to them. They waste a bit more time that way before they hang up (without more effort from me).

Side anecdote, I was taking to some sales people and they mentioned this concept of "ringless voicemails" ugh idk why people have no shame.

Re: Countering threats from North Korea

#170
post #141
post #100

Earlier quoted context omitted.

Only in the US (or whole NANP?) Mobile numbers are non-geographic everywhere else that I know of.

Well, depends. For example, Singapore's numbers are 'non-geographic' in that sense. But Singapore itself is small enough.

I mean non-geographic within the country. As far as I know, the US practice of assigning mobile numbers to 'area codes' is unique.
Post reply on HN