Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

11–20 of 302 posts

Re: North Korean campaign targeting security researchers

#11
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

Total speculation, but:

> North Korean threat actors used social media sites like X (formerly Twitter) to build rapport with their targets. In one case, they carried on a months-long conversation, attempting to collaborate with a security researcher on topics of mutual interest. After initial contact via X, they moved to an encrypted messaging app such as Signal, WhatsApp or Wire. Once a relationship was developed with a targeted researcher, the threat actors sent a malicious file that contained at least one 0-day in a popular software package.

In the past, actors would release something, watch it spread, and see what reports back. Sometimes detonation would be limited to certain IP ranges or institution types, but broad deployment would quickly put itself on the radar of security researchers and someone would sound the alarm.

I'm thinking this targeted approach works like doctor-shopping: you find the most paranoid people you can and see if you're able to exploit them. If you pull one over on them, then the unsuspecting won't stand a chance. If they do catch on, you run away, iterate on your approach, and try it against another researcher who doesn't know you're making the rounds doing this.

Re: North Korean campaign targeting security researchers

#12
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

I'm thinking they are hoping to find exploits that the security researcher(s) are working on, and may not be known to others (use a 0-day to steal other 0-days).

I'd presume that a decent security researcher's laptop would have much more valuable things on it, compared to Bob the Waiter's laptop.

Educated guess. Grain of salt, etc...

Re: North Korean campaign targeting security researchers

#13

This is doubly concerning: Not only for researchers, but also for the public. I always imagined the North Koreans to be at a technical level where they would be the ones consuming published exploits more so than imagining their own. This article means that they are advanced enough to focus on suppressing knowledge rather than consuming what is publicly available.

You should certainly update your perception of NK then. They stole more crypto than anyone else in 2022. [1]

1 - https://www.reuters.com/technology/record-breaking-2022-nort...

Re: North Korean campaign targeting security researchers

#14

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

> I don't understand why the media downplays them so heavily.

And I don't understand why the media upplays them so heavily, as some kind of peer threat capable of meaningful force projection.

(Well, I do understand it, someone needs to keep pounding the drum to keep this country on a forever-war footing.)

Re: North Korean campaign targeting security researchers

#15
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

also the research they are doing; I would guess most researchers know of vulnerabilities counter parties would be very interested in weaponizing

Re: North Korean campaign targeting security researchers

#16
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

Total speculation, but: > North Korean threat actors used social media sites like X (formerly Twitter) to build rapport with their targets. In one case, they carried on a months-long conversation, attempting to collaborate with a security researcher on topics of mutual interest. After initial contact via X, they moved to an encrypted messaging app such as Signal, WhatsApp or Wire. Once a relationship was developed wi…

[deleted]

Re: North Korean campaign targeting security researchers

#19

This is doubly concerning: Not only for researchers, but also for the public. I always imagined the North Koreans to be at a technical level where they would be the ones consuming published exploits more so than imagining their own. This article means that they are advanced enough to focus on suppressing knowledge rather than consuming what is publicly available.

There is an interesting podcast called Lazarus Heist that covers this stuff.

Re: North Korean campaign targeting security researchers

#20
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

Do you understand why [foreign government] would want to spy on Raytheon, Lockheed, General Dynamics?
Post reply on HN