A fake job offer took down Axie Infinity
31–40 of 364 posts
Re: A fake job offer took down Axie Infinity
#32I think the media and tech writes overestimate the efficacy of spear phishing attacks. There is tons of research involved in finding suitable targets and then planning out the attack, such as the exploit, fake websites, fake emails, and other ingredients.
Just another reason crypto is a godsend for bad guys (obviously other financial crimes occur, e.g. with convincing folks to send fake wires) but there aren't many better ways to steal half a billion dollars I think. But, yeah yeah, "HN is so mean and hates crypto!!!"
Re: A fake job offer took down Axie Infinity
#33Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
It introduces the idea of "transitive trust" where person A might not know person B but if the two have a bunch of contacts in common, the odds of A trusting B goes up. When there's a profile with tens or hundreds of shared connections, it looks real by all accounts.
I wrote about this is an intel gathering/attack vector way back in the day but it's 100x better now because connecting is second nature and people trust more now: https://caseysoftware.com/blog/open-source-intelligence-link...
Re: A fake job offer took down Axie Infinity
#34Re: A fake job offer took down Axie Infinity
#35Earlier quoted context omitted.
Personally I don't update my LinkedIn until I start looking for a new job. There is absolutely no need for anyone to know where I work (or at least for me to share that far and wide publically) and I'm not interested in cold emails/cold linkedin messages. My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (T…
> Personally I don't update my LinkedIn until I start looking for a new job. Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it…
Re: A fake job offer took down Axie Infinity
#36Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.
Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-pdfs-revealing-te... I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni... . To some extent, the PDF viewer/OS doesn't matter. A ded…
Re: A fake job offer took down Axie Infinity
#37I think the media and tech writes overestimate the efficacy of spear phishing attacks. There is tons of research involved in finding suitable targets and then planning out the attack, such as the exploit, fake websites, fake emails, and other ingredients.
Re: A fake job offer took down Axie Infinity
#38Re: A fake job offer took down Axie Infinity
#39https://blog.google/threat-analysis-group/new-campaign-targe...
Re: A fake job offer took down Axie Infinity
#40Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…