Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

111–120 of 364 posts

Re: A fake job offer took down Axie Infinity

#111
post #79

I've got to say, this is an incredibly cyberpunk article. > Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed. It's not in William Gibson's style, sounds more like Bruce Ster…

Cyberpunk is now, just sans the 80s fashion inspirations :)

The future is already here. It's just not evenly distributed yet” - maybe W. G.

Re: A fake job offer took down Axie Infinity

#112
post #67

For those that don't want to read the whole thing, (supposedly) the attackers reached out on linkedin to a bunch of employees asking them to apply to a fake company. One of them did it, went through a bunch of fake interviews, and then got a fake offer, in the form of a PDF. They opened the PDF and that installed a keylogger on their system (it doesn't explain how). The attackers then used that engineer's credentials…

It’s honestly impressive. I work in security in fintech and it can be frustrating to have our work deprioritized against product features. These examples help underscore why having robust security controls is existential.

Re: A fake job offer took down Axie Infinity

#113

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

Also, don't use a company device for personal business. If you use your own device then do company work in a VM.

Opening the pdf wasn't "company work", so maybe everything should be done in a VM? (Not the same VM!)

Re: A fake job offer took down Axie Infinity

#114
post #48

Earlier quoted context omitted.

Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-pdfs-revealing-te... I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni... . To some extent, the PDF viewer/OS doesn't matter. A ded…

The right move here would have been to have separate work/personal computers so that this PDF never landed on a system with access to the Ronin network. I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.

what would stop a developer from checking personal email on a work machine?

Re: A fake job offer took down Axie Infinity

#115
post #68

The other major cause of the failure was that one dev had access to 5 signing keys. That shouldn't have happened, because than that one dev could have run off with $540 Million... And remember, it wasn't just that one dev - it was everything running on his computer - think of the probably tens of thousands of developers who wrote the code that runs as root on his PC, much of it unreviewed.

> In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.” The company fully blames the employee. I wish so…

Airlines would behave the same way if there wasn't an aggressive government regulatory body forcing them to learn from failures.

Re: A fake job offer took down Axie Infinity

#116

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

Personally I don't update my LinkedIn until I start looking for a new job. There is absolutely no need for anyone to know where I work (or at least for me to share that far and wide publically) and I'm not interested in cold emails/cold linkedin messages. My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (T…

Meanwhile, my company actively gives us hints on how to spruce up our resumes with marketing bullshit that impresses nobody but middle managers who think that keyword searches with word soups like "Innovator. Thought-Haver. Bringer of Boys To the Yard." are their paths to big league success.

Re: A fake job offer took down Axie Infinity

#117

Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.

Likely this was a standalone PDF reader hack (rather than a browser), since those can have many more features and a much larger attack surface.

It says it was an offer letter, so my guess is that opening it in the browser came up with an error like "to be able to digitally sign this offer letter, please open it in a desktop PDF reader with full scripting support enabled :)"

Re: A fake job offer took down Axie Infinity

#118
post #68

The other major cause of the failure was that one dev had access to 5 signing keys. That shouldn't have happened, because than that one dev could have run off with $540 Million... And remember, it wasn't just that one dev - it was everything running on his computer - think of the probably tens of thousands of developers who wrote the code that runs as root on his PC, much of it unreviewed.

> In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.” The company fully blames the employee. I wish so…

It is called dodging.

Re: A fake job offer took down Axie Infinity

#119

They say that a worker downloading (and presumably viewing) a PDF (fake job offer) allowed spyware in. Which PDF viewer was exploited?

im guessing it was the ol' ".pdf.exe" trick.

This sounds way too sophisticated for them to risk it with a "Offer.pdf.exe". Especially if it was state-backed. If the victim notices it, and the bar isn't high, you'd basically spook him away and alert the entire company.

Re: A fake job offer took down Axie Infinity

#120

Earlier quoted context omitted.

Yeah, though I'd get dinged by that either way since I normally update my bio to include recent projects/tech I've worked with. This way I can hide behind plausible deniability "Oh, I just got around to adding X company to my LinkedIn" if I need to, whereas updating an existing entry is harder to justify (without giving away you are looking). Though I also try not to work for companies that I would need to worry abou…

I doubt they'd actually ask you about it (and thus give you a chance to "explain" yourself), HR would just note you down and you'd be more likely to be laid off, less likely to get promotions approved, etc.

I know this is off topic but I'm always confused by the attitude you've mentioned where companies don't actively work to retain staff.

I wonder if there are any courses for managers to train them to think logically about this and not switch into bad decisions based on emotion.

Companies waste so much money on hiring and then deciding to react very slowly to changes in market conditions. If businesses treated their staff like they treat their clients...

Post reply on HN