They say that a worker downloading (and presumably viewing) a PDF (fake job offer) allowed spyware in. Which PDF viewer was exploited?
A fake job offer took down Axie Infinity
11–20 of 364 posts
Re: A fake job offer took down Axie Infinity
#12Did he get the job? because i guess he was fired from the previous one.
Re: A fake job offer took down Axie Infinity
#13They say that a worker downloading (and presumably viewing) a PDF (fake job offer) allowed spyware in. Which PDF viewer was exploited?
Re: A fake job offer took down Axie Infinity
#14They say that a worker downloading (and presumably viewing) a PDF (fake job offer) allowed spyware in. Which PDF viewer was exploited?
You can easily embed arbitrary javascript into any PDF, and you can obfuscate it pretty well enough to get past most endpoint security tools on the market.
Re: A fake job offer took down Axie Infinity
#15Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.
Re: A fake job offer took down Axie Infinity
#16Re: A fake job offer took down Axie Infinity
#17Desktop PDF viewers like acrobat are gaping security holes... Don't use them!
Re: A fake job offer took down Axie Infinity
#18Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
Re: A fake job offer took down Axie Infinity
#19And remember, it wasn't just that one dev - it was everything running on his computer - think of the probably tens of thousands of developers who wrote the code that runs as root on his PC, much of it unreviewed.