Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

141–150 of 302 posts

Re: North Korean campaign targeting security researchers

#141
post #101
post #80

Earlier quoted context omitted.

> It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution. I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to…

Given it's an official Google blog post related to a nation-state threat actor, somebody asking for valid attribution could be a way attackers try to: 1) Derail the conversation 2) Find out ways to further cloak their footprint IMO if you've worked in the field, you know it's a dumb question meant to invoke something. "Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!" Sadly,…

If it matters I didn't mean to direct my comment at you personally (obviously, as I don't know you), but instead it was meant to target the generic security person who says that he/she has gotten in the "vicinity" of such state-sponsored attacks.

Back to the subject at hand, and taking a more general view, trusting a big Pentagon-contractor [1] (and not only) such as Alphabet on the subject of other countries' cyber-attacks against the US (and its Western allies) is just futile.

[1] https://www.reuters.com/technology/pentagon-awards-9-bln-clo...

Re: North Korean campaign targeting security researchers

#142
post #125

How did they determine the threat is coming from North Korea?

From the article: "The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits."

Got it. Missed that part. Thank you. Looks like a pure assumption. According to CyberProof [1] and CloudFlare [2], the majority of attacks originate from China and the United States. North Korea is not even making it to Top 10. That's why I asked.

[1] https://blog.cyberproof.com/blog/which-countries-are-most-da...

[2] https://blog.cloudflare.com/ddos-attack-trends-for-2021-q4/

Re: North Korean campaign targeting security researchers

#143

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

It looks like it just got taken offline

Yep. Page Not Found now.

I just had a look at it like 30 minutes ago and it was still there then.

Here are archives of what it looked like

http://web.archive.org/web/20230907185609/https://github.com...

http://web.archive.org/web/20230907193333/https://github.com...

http://web.archive.org/web/20230907193402/https://github.com...

Re: North Korean campaign targeting security researchers

#145
post #14

Earlier quoted context omitted.

> I don't understand why the media downplays them so heavily. And I don't understand why the media upplays them so heavily, as some kind of peer threat capable of meaningful force projection. (Well, I do understand it, someone needs to keep pounding the drum to keep this country on a forever-war footing.)

Feels like a weird post to make in the comments section of an article in which NK performed an active attack campaign...

Not weird when you consider what is, and what is not a proportionate mitigation of a threat.

When someone gets mugged on your street, you can consider taking precautions. If your response is to roll out half a mile of barbed wire, electric fencing, and landmines all through the perimeter of your property, I would say that is absolutely 'upplaying' the actual level of threat.

Most Americans' understanding of the actual threat posed to the US by NK is ludicrously upplayed. NK is a credible offensive threat to SK, but that's a very limited problem for anyone living in Nashville, Tennessee.

Re: North Korean campaign targeting security researchers

#146
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

More often than you'd think.

Young infosec practitioners are encouraged to get certifications, OSCP, eJPT, etc. A lot of these cert mills require that you pwn known boxes. This gives rise to discord servers where you can "help eachother". Some of this help is in the form of binaries or obfuscated source code.

They run it on their pentest job laptop, you know, the one with the SSH keys to their report writing box. They get pwnd, and now DPRK has access to a bunch of US civilian corporate data and weaknesses.

I may have actually witnessed this.

Re: North Korean campaign targeting security researchers

#147

Earlier quoted context omitted.

[flagged]

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

How does anyone know the average heights in NK?

Re: North Korean campaign targeting security researchers

#148
post #145

Earlier quoted context omitted.

Feels like a weird post to make in the comments section of an article in which NK performed an active attack campaign...

Not weird when you consider what is, and what is not a proportionate mitigation of a threat. When someone gets mugged on your street, you can consider taking precautions. If your response is to roll out half a mile of barbed wire, electric fencing, and landmines all through the perimeter of your property, I would say that is absolutely 'upplaying' the actual level of threat. Most Americans' understanding of the actua…

I mean, the response here was a blog post, which doesn't feel particularly upplayed. I also virtually never hear about NK from anyone or fear of NK from anyone day to day, nor do I hear about it particularly often from policy makers. No one is campaigning on fear of NK that I have seen.

Perhaps TN is just a radically different world, I'd frankly believe it, but I haven't seen anything too significant at all. The last time people were really concerned about NK for like... 3 days, I think it was ~2012 or so.

Re: North Korean campaign targeting security researchers

#149
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

[deleted]

Re: North Korean campaign targeting security researchers

#150

Earlier quoted context omitted.

1. DPRK does an actual cybercrime, shellcode/payload eventually gets discovered and disseminated among researchers 2. Script kid acquires said code, makes slight modifications 3. Script kid deploys the malware 4. Cybersec person @ Google is promoted for uncovering major APT operation, big news story How do you prove that this is sufficiently implausible?

As shown in the Snowden leaks, The United States was in development of exactly this capacity and its essentially impossible to attribute attacks to nations like this. Anyone who claims to be able to is either ignorant or lying.

Marble Framework, if anyone is interested
Post reply on HN