Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

101–110 of 302 posts

Re: North Korean campaign targeting security researchers

#101
post #80
post #56

Earlier quoted context omitted.

Attributing cybercrime is never a slam dunk unless you have physical evidence: devices, people, etc. /var/log/*/access.conf is not that. Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal. WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chines…

> It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution. I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to…

Given it's an official Google blog post related to a nation-state threat actor, somebody asking for valid attribution could be a way attackers try to:

1) Derail the conversation 2) Find out ways to further cloak their footprint

IMO if you've worked in the field, you know it's a dumb question meant to invoke something.

"Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!"

Sadly, I am a nobody who happened to see DPRK not tunnel to a VPN.

Re: North Korean campaign targeting security researchers

#102
post #86

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

I'm really curious where the 0-day is in the code of the project honestly

This "UpdateCheckThread" code looks pretty funky, [0]. It downloads some stuff from a URL, writes a file to disk, and creates a process to run it.

0: https://github.com/dbgsymbol/getsymbol/blob/cb4bdedc1a85c308...

Re: North Korean campaign targeting security researchers

#103

Evidence for attribution to North Korea?

> The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits. At minimum the payload.

1. DPRK does an actual cybercrime, shellcode/payload eventually gets discovered and disseminated among researchers

2. Script kid acquires said code, makes slight modifications

3. Script kid deploys the malware

4. Cybersec person @ Google is promoted for uncovering major APT operation, big news story

How do you prove that this is sufficiently implausible?

Re: North Korean campaign targeting security researchers

#104

Earlier quoted context omitted.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

>I don't understand why the media downplays them so heavily. Because in the same way as morale can be a force multiplier, an extreme lack of it can be a force divider. Combine that with their (very likely) inability to sustain even a regional war for more than a few weeks, their antiquated equipment, and their largely unsuccessful domestic military developments, and it's not hard to write them off as largely a non-th…

I’d bet they’re prepared to do a ton of damage to South Korea via cyberarms more than traditional weaponry too. Eg cut power to the country for days on end. They’ve clearly got 0days and aren’t afraid to use them.

Re: North Korean campaign targeting security researchers

#105
post #75

Earlier quoted context omitted.

"How do Linux/Mac package managers solve this?" By building their binaries from source and hosting them on their servers?

Wouldn't help if the source code already has the backdoor in there though. Most people would just download and build a tool off GitHub if it has 200 stars and does what they need.

[deleted]

Re: North Korean campaign targeting security researchers

#106
post #34

Earlier quoted context omitted.

> third-world living conditions [...] I know that the phrase has gained an orthogonal meaning since the cold war, but if we use the original one it's funny to call what's arguably the only remaining second-world country "third-world".

I mean if we're going by the original definitions, I think Laos, Vietnam, and Cuba are also still second-world though none of them are bizarrely neo-Stalinist the way North Korea is.

Are they really Stalinists? I would have guess Maoists, but then again, I wouldn't know the difference.

Re: North Korean campaign targeting security researchers

#107
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

Total speculation, but: > North Korean threat actors used social media sites like X (formerly Twitter) to build rapport with their targets. In one case, they carried on a months-long conversation, attempting to collaborate with a security researcher on topics of mutual interest. After initial contact via X, they moved to an encrypted messaging app such as Signal, WhatsApp or Wire. Once a relationship was developed wi…

Super common spear phishing in modern times, back a few decades-ish chinese plants would attend military convferences, or would monitor those from the US who went to said conferences, then would "follow-up" with an email talking about how they met and talked about "some program or weapon that person was in the know of" on a superficial level and stroke their ego a bit... then phish them with malware based on that supposed meeting and ego stroking...

Re: North Korean campaign targeting security researchers

#108

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

[flagged]

So what IS the threat from North Korea to Americans or anyone not sharing a border with them exactly? They won't launch nukes at anything outside their own borders unless Kim wants his country turned into a smoldering crater. The only real threat anyone should worry about is cyber attacks, which could be an issue if targeted at infrastructure, but not something i stay awake at night worrying about.

I find it interesting that 2 years ago people like you would be moaning about how COVID-19 is being used to "scare" people, and we should ignore US "propaganda" about death rates in the US and worldwide. But now apparently North Korea IS a threat and we should all be scared of Kim starting a nuclear war.

The last couple of years drove a lot of people to conspiracy theory channels, and it's affects are starting to show.

Re: North Korean campaign targeting security researchers

#109
Complete conjecture, but new macOS security update just went up, which includes this tidbit:

> Impact: Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

https://support.apple.com/en-us/HT213906

Not a betting man, but I'd guess that's the vulnerability being discussed.

Re: North Korean campaign targeting security researchers

#110

Earlier quoted context omitted.

Even better, do it to their children, and literally everybody else who is important in their lives.

Probably more carrot than stick. NK hackers who can bring in millions to the state from crypto hacking, ransom etc likely live more comfortably than manual laborers.

Probably way less comfortably than if they could move to a civilized country though.
Post reply on HN