Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

181–190 of 302 posts

Re: North Korean campaign targeting security researchers

#181
post #24
post #6

Earlier quoted context omitted.

DPRK’s top 1% live what amounts to an upper middle class life, and tend to educate their children abroad. My understanding is that they even have access to an unfiltered Internet supplied by China. The threat of extermination of their families if they step out of line politically seems to keep those people in check.

I would think they are kept in check the same way the upper middle class is kept in check pretty much everywhere in the world. They live a very comfortable life style and have no interest in doing anything that would jeopardize that.

That's a latent function present to varying degrees in every society (who wants to rock the boat if you're having a good ride?), whereas the threat to one's family is more of a manifest function, sociologically speaking.

Re: North Korean campaign targeting security researchers

#182

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

They probably see the crazy shit the western propaganda machine pumps out about them and are reassured. That is not to say NK is absolved of wrongdoing, however.

Maybe we went a tad too far with Ukraine propaganda. Five Eyes, if you hear me, maybe turn that down a notch for a while, you’re getting as credible as Colin Powell’s words at the UN Security Council, and kids will remember.

Re: North Korean campaign targeting security researchers

#183
post #59

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

>ability to recruit smart hard working people including non-nationals?

Of course. There are a lot more capable fish in the pond than the ones with the connections to a Western company, plus the capable fish in a Western pond but nobody talking to them because the onus is on the fish. You probably know people who are better programmers than people you work with who don't earn as much as people more socially savvy or placed, and who might want to also pay off a mortgage after 30 years.

Re: North Korean campaign targeting security researchers

#184

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

You think the North Korean intelligence community is not aware of the content of Western media?

They probably are aware. There are other means of keeping them in line, both carrot (privileges within DPRK) and stick (consequences for them and their loved ones if they step out of line.)

Re: North Korean campaign targeting security researchers

#185

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

What's the point of the warning? Wouldn't Github just removing the offending repo?

Re: North Korean campaign targeting security researchers

#186
post #124

How did they determine the threat is coming from North Korea?

Someone of you may enjoy this[0] podcast on the North Korean Lazarus Group. [0] https://www.bbc.co.uk/programmes/w13xtvg9/episodes/downloads

Are we supposed to download this and run on our computers?

Re: North Korean campaign targeting security researchers

#187
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

That isn't what they said the threat was; they were sent a document that exploited a 0-day in whatever program reads it.

Ah, I misunderstood, thanks.

Re: North Korean campaign targeting security researchers

#188

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

I reported the repository as malware, guess we'll see what happens with it

> Our review of the account named in your report has concluded. We have determined that one or more violations of GitHub’s Terms of Service have occurred and have taken appropriate action in response.

Re: North Korean campaign targeting security researchers

#189

> Upon discovery, all identified websites and domains are added to Safe Browsing to protect users from further exploitation. dbgsymbol.com is NOT showing up with warning in Safe Browsing on my Brave browser. (warning, unknown vector)

Safe browsing is there for Google to spy on you easily, not to detect hacks.

Re: North Korean campaign targeting security researchers

#190
post #174

Earlier quoted context omitted.

Small tool = less code to read through. If you want to use that suspicious tool, you should at least take a glance at the source code.

In an ideal world that would be the case, but people barely read the README or documentation.

That's on their own fault, and on the alternative closed source scenario nobody would be able to read the source without reverse engineering it first
Post reply on HN