Earlier quoted context omitted.
DPRK’s top 1% live what amounts to an upper middle class life, and tend to educate their children abroad. My understanding is that they even have access to an unfiltered Internet supplied by China. The threat of extermination of their families if they step out of line politically seems to keep those people in check.
I would think they are kept in check the same way the upper middle class is kept in check pretty much everywhere in the world. They live a very comfortable life style and have no interest in doing anything that would jeopardize that.
North Korean campaign targeting security researchers
181–190 of 302 posts
Re: North Korean campaign targeting security researchers
#182What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?
They probably see the crazy shit the western propaganda machine pumps out about them and are reassured. That is not to say NK is absolved of wrongdoing, however.
Re: North Korean campaign targeting security researchers
#183Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.
>ability to recruit smart hard working people including non-nationals?
Re: North Korean campaign targeting security researchers
#184What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?
They probably are aware. There are other means of keeping them in line, both carrot (privileges within DPRK) and stick (consequences for them and their loved ones if they step out of line.)
Re: North Korean campaign targeting security researchers
#185I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)
Re: North Korean campaign targeting security researchers
#186Re: North Korean campaign targeting security researchers
#187I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…
That isn't what they said the threat was; they were sent a document that exploited a 0-day in whatever program reads it.
Re: North Korean campaign targeting security researchers
#188I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)
I reported the repository as malware, guess we'll see what happens with it
Re: North Korean campaign targeting security researchers
#189> Upon discovery, all identified websites and domains are added to Safe Browsing to protect users from further exploitation. dbgsymbol.com is NOT showing up with warning in Safe Browsing on my Brave browser. (warning, unknown vector)
Re: North Korean campaign targeting security researchers
#190Earlier quoted context omitted.
Small tool = less code to read through. If you want to use that suspicious tool, you should at least take a glance at the source code.
In an ideal world that would be the case, but people barely read the README or documentation.