I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)
North Korean campaign targeting security researchers
71–80 of 302 posts
Re: North Korean campaign targeting security researchers
#72Earlier quoted context omitted.
Why tf would you post an unsanitized link to a malware executable here? edit: nice edit to the parent. the original was a github link to the .exe file.
Because we assume our fellow users here are not morons and aren't going to download a file from virus total.com that says "2 security vendors flagged this file as malicious" and run it and get infected. You'll note that the github.com link was also published upthread, and is even more malicious. In linking to the binary, I can download it and run it through radare2/ghidra/idapro and do some static analysis on it for…
Re: North Korean campaign targeting security researchers
#73Not really shocking or new but kind of interesting. Why would they use 0days on security researchers. My guess is it's a test with upside. On the one hand if it works on a security researcher, you can go "live" because you got a good one and on the other hand you estimate that in the long run you'll get 1+x 0days out of the deal from said researcher. As a security researcher it also presents an interesting situation.…
Or just be after the accesses the targets have...
Re: North Korean campaign targeting security researchers
#74Earlier quoted context omitted.
those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.
[flagged]
Re: North Korean campaign targeting security researchers
#75I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…
"How do Linux/Mac package managers solve this?" By building their binaries from source and hosting them on their servers?
Re: North Korean campaign targeting security researchers
#76Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.
> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.
There are a few reasons that interlock.
- The DPRK government is a mob family with sovereign status and nukes. Most folks in western countries don't have a strong sense of what that means - looking through the lens of mostly free nations, it is hard to imagine the realities on the ground, and they fill in the blanks with what they know about bureaucratic states.
- Lots of western folks, but USians in particular, are extremely ignorant and incurious about Asia and asian cultures. This amplifies the above problems and tends to lead to ridiculous ideas being believable.
- DPRK's propaganda encourages some of this. Their interests are served when people in the west are thinking about their nukes and ignoring the hacking that pays for them. A side order of "we're so mean and crazy we starve our people" helps stoke the mad-man authoritarian archetype.
Re: North Korean campaign targeting security researchers
#77I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…
Re: North Korean campaign targeting security researchers
#78I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)
Re: North Korean campaign targeting security researchers
#79Earlier quoted context omitted.
> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.
> I don't understand why the media downplays them so heavily. And I don't understand why the media upplays them so heavily, as some kind of peer threat capable of meaningful force projection. (Well, I do understand it, someone needs to keep pounding the drum to keep this country on a forever-war footing.)
Re: North Korean campaign targeting security researchers
#80Earlier quoted context omitted.
"SoUrCe?" This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles. This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.
Attributing cybercrime is never a slam dunk unless you have physical evidence: devices, people, etc. /var/log/*/access.conf is not that. Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal. WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chines…
I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to (I guess that's how the OP got to see those NK-related IP blocks) Western government agencies that handle this sort of stuff.