Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

161–170 of 302 posts

Re: North Korean campaign targeting security researchers

#161

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

I don't think there are many options here:

- They can't get to X freer country as that's just difficult for all North Koreans

- They likely can't just stop hacking for carrot and/or stick reasons. They are likely closely monitored.

- Maybe some people drink the kool-aid. I'm sure these people are very well compensated.

Re: North Korean campaign targeting security researchers

#162

Earlier quoted context omitted.

This is absolutely because NK doesn't want to pay market rate for 0days.

What is market rate for a 0-day?

check the zerodium pricelist for a general guide: https://zerodium.com/program.html

Re: North Korean campaign targeting security researchers

#163
post #104

Earlier quoted context omitted.

I’d bet they’re prepared to do a ton of damage to South Korea via cyberarms more than traditional weaponry too. Eg cut power to the country for days on end. They’ve clearly got 0days and aren’t afraid to use them.

If 'cyberarms' are as potent as you think they are, then how come Russian cyberarms haven't done much damage to Ukraine?

Since 2014, nations with a strong vested interest in Ukraine not falling threw a lot of resources at strengthening the country's infosec.

Also, during a kinetic conflict where you're invading, it's often more strategically valuable to lie dormant in their networks than it is to scorch them, a la America sitting inside of Iraq's phone networks and just listening.

There's a lot of work being done now to change it [1], but I've heard from multiple cybersecurity grunts in critical infrastructure that they just assume foreign APTs are in their networks. Strategically, why in the world wouldn't they be? There's basically no downside other than burning TTPs. We should damn well expect the NSA to have their fingers in every foreign pot they can reach.

[1] To be fair, there was a lot of work before too. But now people are more scared.

Re: North Korean campaign targeting security researchers

#164
post #75

Earlier quoted context omitted.

Wouldn't help if the source code already has the backdoor in there though. Most people would just download and build a tool off GitHub if it has 200 stars and does what they need.

It's extremely hard to sneak backdoors in open-source code. Which is one of the reasons why a lot of people promote that openness.

Into a popular repository yes, but into a small tool like that it would most likely be very possible.

Re: North Korean campaign targeting security researchers

#166

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

The state tightly controls who gets internet access. The agents would be thoroughly vetted, and/or given a life they could not otherwise have and an implicit threat to their family's well being if they were to misbehave. They probably do have some idea of what life is like outside their country, but are either conditioned to look down on it or terrified of trying to escape.

Re: North Korean campaign targeting security researchers

#167

Earlier quoted context omitted.

The source code itself looks relatively clean; there's autoupdate functionality but it looks like it's gated behind a confirmatory dialog box. It's much more likely that the binary releases and/or autoupdate binaries are backdoored. If someone compiles their own version, and then clicks to accept the autoupdate, they could be infected. The binary is 15+MB in size, which is far more than enough to hide a small backdoo…

It's the auto-update functionality from a now-suspect URL. The repo has since been taken down, but here's the suspect file: https://github.com/dbgsymbol/getsymbol/blob/cb4bdedc1a85c308...

Drat, archive.org didn't snag it. Do you happen to have a copy? https://web.archive.org/web/20230000000000*/https://github.c...

Re: North Korean campaign targeting security researchers

#168

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

> why the media downplays them

Perhaps you meant the media for some specific country, but news media in Japan do seem to take North Korea quite seriously, and missile launches frequently ends up being the first headline on NHK world news.

Re: North Korean campaign targeting security researchers

#169
You won’t really find anything interesting from this repo aside the update functionality that was likely used for downloading the payload. The topic of interest is the payload that TAG obviously can’t disclose because vendors are fixing whatever bug was behind this 0day

Unsuprisingly, TAG is light on details..

Re: North Korean campaign targeting security researchers

#170
post #104

Earlier quoted context omitted.

I’d bet they’re prepared to do a ton of damage to South Korea via cyberarms more than traditional weaponry too. Eg cut power to the country for days on end. They’ve clearly got 0days and aren’t afraid to use them.

If 'cyberarms' are as potent as you think they are, then how come Russian cyberarms haven't done much damage to Ukraine?

[deleted]
Post reply on HN