Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

151–160 of 364 posts

Re: A fake job offer took down Axie Infinity

#151
post #67

For those that don't want to read the whole thing, (supposedly) the attackers reached out on linkedin to a bunch of employees asking them to apply to a fake company. One of them did it, went through a bunch of fake interviews, and then got a fake offer, in the form of a PDF. They opened the PDF and that installed a keylogger on their system (it doesn't explain how). The attackers then used that engineer's credentials…

I'm trying to imagine a setup at any company whose primary business is controlling extremely valuable digital assets having a security setup that could be entirely undone with keyloggers, and it's difficult. No necessary VPNs, keys on devices, or other non-password authentication? One engineer's password should not be the keys to the kingdom.

Sounds like a bad RPG plot. "Because of its danger, we broke the Obsidian Key into 9 pieces and divided them across the realm, each protected by a powerful, mystic dungeon. Also, Dave can access them any time he says the secret word."

Re: A fake job offer took down Axie Infinity

#152
post #106

Earlier quoted context omitted.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

I travel with a HP Spectre x360 for personal stuff. It is barely a weight or bulk addition compared to my work machine.

When I was on the road all the time I also had separate phones to ensure I never got stuck with a dead phone.

Re: A fake job offer took down Axie Infinity

#153

Earlier quoted context omitted.

kinda disgusting he got fired for this if that was the case. Its a very sophisticated attack and I think its conversion rate would be rather high.

The article says they are no longer employed. It is possible that this exploit was only possible because of breaking other security policies. At least, I hope that any reasonable organization doesn't secure $600+ million dollars by relying on the endpoint security of a device used to access LinkedIn

> reasonable organization

Re: A fake job offer took down Axie Infinity

#154
post #106
post #99

Earlier quoted context omitted.

The main problem was using a machine that had access to half a billion dollars to also browse the web and do stuff like applying for jobs. If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

I suppose that sending it during business hours and, who knows, maybe the final offer would be in the PDF and the poor guy couldn't wait to open it. The rest is history.

Re: A fake job offer took down Axie Infinity

#155
post #65

Earlier quoted context omitted.

Same, although my perception is that LinkedIn has moved past its peak usefulness, and it would be better to spend time on other platforms than creating a LI account. All I hear about LinkedIn these days is spam.

which other platform?

There's a lot of platforms that do sort of related things, so it's a hard thing to answer. For "finding a job" I've been looking at HN, remoteok, and a bunch of others. For professional networking I use various tools run by former coworkers (mostly Slack and Google Groups). For "blogs" I use HN and Reddit. etc. I don't think LinkedIn does any of those better (my perception, I'm not a current user).

Personally, I'm probably not interested in a LI clone for many of the reasons I stopped using LI. I deleted my LI account maybe 8 years ago, after getting too much spam (and I think some security issue?)

Re: A fake job offer took down Axie Infinity

#156

Earlier quoted context omitted.

Also, don't use a company device for personal business. If you use your own device then do company work in a VM.

Opening the pdf wasn't "company work", so maybe everything should be done in a VM? (Not the same VM!)

He opened it on a company device I assume

Re: A fake job offer took down Axie Infinity

#157

Seems like there would be market demand for a super locked down PDF viewer that basically ignores all the silly extensions/additions that Adobe has added to the format over the decades. The vast majority of documents don't need Turing complete code capabilities or embedded videos or interactive 3D models. Something that safely (using sandboxing and other methods) turns the document into totally static pixel data that…

FoxIt has out of the box GPO controls that are quite easy to use. It's probably got a lot of tweaking to really lock it down, but I think you could get pretty far before having to stop for lunch.

Re: A fake job offer took down Axie Infinity

#158
LN has now become a dumping ground for spammers, scammers, and a social network site. It's lost its appeal, and I am getting more scammers all the time.

I'm beginning to contemplate what value LN provides as LN has focused on more aggressive marketing tactics, and it's starting to feel like Instagram with the engagements metrics...

Oh yea, I'm still perplexed on how anyone would ever go into an interview w/out doing any homework on the company...even the smallest of start-ups have a presence on the net. They better damn-well have a pitch deck for new capital and employees.

Re: A fake job offer took down Axie Infinity

#160
post #67

For those that don't want to read the whole thing, (supposedly) the attackers reached out on linkedin to a bunch of employees asking them to apply to a fake company. One of them did it, went through a bunch of fake interviews, and then got a fake offer, in the form of a PDF. They opened the PDF and that installed a keylogger on their system (it doesn't explain how). The attackers then used that engineer's credentials…

I'm trying to imagine a setup at any company whose primary business is controlling extremely valuable digital assets having a security setup that could be entirely undone with keyloggers, and it's difficult. No necessary VPNs, keys on devices, or other non-password authentication? One engineer's password should not be the keys to the kingdom. Sounds like a bad RPG plot. "Because of its danger, we broke the Obsidian K…

Agreed. The article doesn't mention keylogger at all. I was definitely picturing a remote control exploit.
Post reply on HN