Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

151–160 of 302 posts

Re: North Korean campaign targeting security researchers

#151
post #125

Earlier quoted context omitted.

From the article: "The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits."

Got it. Missed that part. Thank you. Looks like a pure assumption. According to CyberProof [1] and CloudFlare [2], the majority of attacks originate from China and the United States. North Korea is not even making it to Top 10. That's why I asked. [1] https://blog.cyberproof.com/blog/which-countries-are-most-da... [2] https://blog.cloudflare.com/ddos-attack-trends-for-2021-q4/

North Korea is a nice foil, because then you don't have to cast aspersions onto trading partners.

"Look, see? NK. We even copied some Korean words into the comments."

Re: North Korean campaign targeting security researchers

#152
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

Security 101 is that everyone will fuck up at some point. _Everyone_.

If the security researcher's environment isn't well designed (which absolutely happens, whether it's via budget or inattentiveness,) then the attacker can get to a delicious creamy filling very fast.

Re: North Korean campaign targeting security researchers

#154
What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English.

How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

Re: North Korean campaign targeting security researchers

#155
post #109

Complete conjecture, but new macOS security update just went up, which includes this tidbit: > Impact: Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. https://support.apple.com/en-us/HT213906 Not a betting man, but I'd guess that's the vulnerability being discussed.

Good thing I'm not a betting man because I'd have lost:

https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zer...

Re: North Korean campaign targeting security researchers

#156

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

They probably see the crazy shit the western propaganda machine pumps out about them and are reassured. That is not to say NK is absolved of wrongdoing, however.

Re: North Korean campaign targeting security researchers

#157
post #75

Earlier quoted context omitted.

"How do Linux/Mac package managers solve this?" By building their binaries from source and hosting them on their servers?

Wouldn't help if the source code already has the backdoor in there though. Most people would just download and build a tool off GitHub if it has 200 stars and does what they need.

It's extremely hard to sneak backdoors in open-source code.

Which is one of the reasons why a lot of people promote that openness.

Re: North Korean campaign targeting security researchers

#158
post #109

Complete conjecture, but new macOS security update just went up, which includes this tidbit: > Impact: Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. https://support.apple.com/en-us/HT213906 Not a betting man, but I'd guess that's the vulnerability being discussed.

There was a just announced discovery of a new NSO zero click exploit in the wild. It's probably for that.

Re: North Korean campaign targeting security researchers

#159

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

You have people living in the free world believing everything around them is a lie. Finding yourself an interpretational perspective as an observer that would spare you from reconsidering core values comes relatively easy.

Re: North Korean campaign targeting security researchers

#160

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

They probably do, but I don't think there is much they can do if they care about their family's well being
Post reply on HN