Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

31–40 of 364 posts

Re: A fake job offer took down Axie Infinity

#31
This is an important social engineering attack vector that all companies should be aware of. These kind of targeted attacks (often spoofing valid contacts that employees would legitimately exchange documents with) were common since I can remember the space, but using job applications is particularly disingenuous because employees are naturally going to be a bit secretive about those.

Re: A fake job offer took down Axie Infinity

#32

I think the media and tech writes overestimate the efficacy of spear phishing attacks. There is tons of research involved in finding suitable targets and then planning out the attack, such as the exploit, fake websites, fake emails, and other ingredients.

Huh? Don't understand your point. When the potential bounty is $540 million, seems like investment well spent.

Just another reason crypto is a godsend for bad guys (obviously other financial crimes occur, e.g. with convincing folks to send fake wires) but there aren't many better ways to steal half a billion dollars I think. But, yeah yeah, "HN is so mean and hates crypto!!!"

Re: A fake job offer took down Axie Infinity

#33

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

Some in the security community demonstrated this with Robin Sage, circa 2009: https://en.wikipedia.org/wiki/Robin_Sage

It introduces the idea of "transitive trust" where person A might not know person B but if the two have a bunch of contacts in common, the odds of A trusting B goes up. When there's a profile with tens or hundreds of shared connections, it looks real by all accounts.

I wrote about this is an intel gathering/attack vector way back in the day but it's 100x better now because connecting is second nature and people trust more now: https://caseysoftware.com/blog/open-source-intelligence-link...

Re: A fake job offer took down Axie Infinity

#35

Earlier quoted context omitted.

Personally I don't update my LinkedIn until I start looking for a new job. There is absolutely no need for anyone to know where I work (or at least for me to share that far and wide publically) and I'm not interested in cold emails/cold linkedin messages. My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (T…

> Personally I don't update my LinkedIn until I start looking for a new job. Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it…

Yeah, though I'd get dinged by that either way since I normally update my bio to include recent projects/tech I've worked with. This way I can hide behind plausible deniability "Oh, I just got around to adding X company to my LinkedIn" if I need to, whereas updating an existing entry is harder to justify (without giving away you are looking). Though I also try not to work for companies that I would need to worry about that.

Re: A fake job offer took down Axie Infinity

#36

Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.

Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-pdfs-revealing-te... I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni... . To some extent, the PDF viewer/OS doesn't matter. A ded…

I know that document-rendering is much more complex than what it appears on the surface, but surely in this day and age there should be document viewers that don't run scripts and are exploit free.

Re: A fake job offer took down Axie Infinity

#37

I think the media and tech writes overestimate the efficacy of spear phishing attacks. There is tons of research involved in finding suitable targets and then planning out the attack, such as the exploit, fake websites, fake emails, and other ingredients.

I think this is instead a good reminder that no matter how complicated / unlikely a specific attack vector seems, if the bounty is large enough you better assume that someone is going to do it.

Re: A fake job offer took down Axie Infinity

#40

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

On (1), I have seen employees get spear-phishing texts (Welcome X! This is the CEO of Y. I need you to do a small favor…) within hours of updating their LinkedIn. I assume there are robots crawling it constantly looking for fresh candidates for account takeovers or other scams.
Post reply on HN