Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

71–80 of 302 posts

Re: North Korean campaign targeting security researchers

#71

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

Does github have that on any repos? If so, I’ve never stumbled across it.

Re: North Korean campaign targeting security researchers

#72

Earlier quoted context omitted.

Why tf would you post an unsanitized link to a malware executable here? edit: nice edit to the parent. the original was a github link to the .exe file.

Because we assume our fellow users here are not morons and aren't going to download a file from virus total.com that says "2 security vendors flagged this file as malicious" and run it and get infected. You'll note that the github.com link was also published upthread, and is even more malicious. In linking to the binary, I can download it and run it through radare2/ghidra/idapro and do some static analysis on it for…

The link was edited, the original was to the .exe with little commentary and the link was cut off so the filetype wasn't apparent.

Re: North Korean campaign targeting security researchers

#73
post #25

Not really shocking or new but kind of interesting. Why would they use 0days on security researchers. My guess is it's a test with upside. On the one hand if it works on a security researcher, you can go "live" because you got a good one and on the other hand you estimate that in the long run you'll get 1+x 0days out of the deal from said researcher. As a security researcher it also presents an interesting situation.…

> Why would they use 0days on security researchers. My guess is it's a test with upside

Or just be after the accesses the targets have...

Re: North Korean campaign targeting security researchers

#74

Earlier quoted context omitted.

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

Video evidence snuck out of the country frequently shows obviously malnourished people, even military soldiers, who are supposed to get special privileges and access to food look pale and show obvious signs of malnourishment. That said, they're a model for carbon footprint reduction.

Re: North Korean campaign targeting security researchers

#75

I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…

"How do Linux/Mac package managers solve this?" By building their binaries from source and hosting them on their servers?

Wouldn't help if the source code already has the backdoor in there though. Most people would just download and build a tool off GitHub if it has 200 stars and does what they need.

Re: North Korean campaign targeting security researchers

#76

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

> I don't understand why the media downplays them so heavily.

There are a few reasons that interlock.

- The DPRK government is a mob family with sovereign status and nukes. Most folks in western countries don't have a strong sense of what that means - looking through the lens of mostly free nations, it is hard to imagine the realities on the ground, and they fill in the blanks with what they know about bureaucratic states.

- Lots of western folks, but USians in particular, are extremely ignorant and incurious about Asia and asian cultures. This amplifies the above problems and tends to lead to ridiculous ideas being believable.

- DPRK's propaganda encourages some of this. Their interests are served when people in the west are thinking about their nukes and ignoring the hacking that pays for them. A side order of "we're so mean and crazy we starve our people" helps stoke the mad-man authoritarian archetype.

Re: North Korean campaign targeting security researchers

#77

I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…

If I don't see a github action I'll usually pass on downloading. But what do you mean by "random person's site"? It's ffmpeg.org - is that not a reliable source?

Re: North Korean campaign targeting security researchers

#78

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

there is an open issue that warns about this

Re: North Korean campaign targeting security researchers

#79
post #14

Earlier quoted context omitted.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

> I don't understand why the media downplays them so heavily. And I don't understand why the media upplays them so heavily, as some kind of peer threat capable of meaningful force projection. (Well, I do understand it, someone needs to keep pounding the drum to keep this country on a forever-war footing.)

Feels like a weird post to make in the comments section of an article in which NK performed an active attack campaign...

Re: North Korean campaign targeting security researchers

#80
post #56
post #49

Earlier quoted context omitted.

"SoUrCe?" This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles. This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.

Attributing cybercrime is never a slam dunk unless you have physical evidence: devices, people, etc. /var/log/*/access.conf is not that. Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal. WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chines…

> It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution.

I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to (I guess that's how the OP got to see those NK-related IP blocks) Western government agencies that handle this sort of stuff.

Post reply on HN