I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do Linux/Mac package managers solve this?
North Korean campaign targeting security researchers
21–30 of 302 posts
Re: North Korean campaign targeting security researchers
#22help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?
Just kind of what the NSA does really with the exception of monetizing on ransomware?
Re: North Korean campaign targeting security researchers
#23Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.
Re: North Korean campaign targeting security researchers
#24This is doubly concerning: Not only for researchers, but also for the public. I always imagined the North Koreans to be at a technical level where they would be the ones consuming published exploits more so than imagining their own. This article means that they are advanced enough to focus on suppressing knowledge rather than consuming what is publicly available.
DPRK’s top 1% live what amounts to an upper middle class life, and tend to educate their children abroad. My understanding is that they even have access to an unfiltered Internet supplied by China. The threat of extermination of their families if they step out of line politically seems to keep those people in check.
Re: North Korean campaign targeting security researchers
#25As a security researcher it also presents an interesting situation. If you're careful enough and can pretend to be dumb enough, you might be able to harvest fresh attack vectors/0day etc. "for free" but the downside is if you overestimate yourself you'll get pwned.
Re: North Korean campaign targeting security researchers
#26This is doubly concerning: Not only for researchers, but also for the public. I always imagined the North Koreans to be at a technical level where they would be the ones consuming published exploits more so than imagining their own. This article means that they are advanced enough to focus on suppressing knowledge rather than consuming what is publicly available.
You should certainly update your perception of NK then. They stole more crypto than anyone else in 2022. [1] 1 - https://www.reuters.com/technology/record-breaking-2022-nort...
I never heard of anyone stoling crypto, so you might be right. /s
Re: North Korean campaign targeting security researchers
#27Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.
> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.
Because in the same way as morale can be a force multiplier, an extreme lack of it can be a force divider. Combine that with their (very likely) inability to sustain even a regional war for more than a few weeks, their antiquated equipment, and their largely unsuccessful domestic military developments, and it's not hard to write them off as largely a non-threat, whether or not this is truly the case.
The major downside is that even if they only manage to sustain for a few weeks, that's plenty of time to level Seoul and inflict damage on cities further south should they decide to make a push against the ROK, and this is what shouldn't be downplayed.
Re: North Korean campaign targeting security researchers
#28help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?
Re: North Korean campaign targeting security researchers
#29Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.
Put a gun to someone's head and you'll find that they're capable of just about anything.
Re: North Korean campaign targeting security researchers
#30help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?
I'm thinking they are hoping to find exploits that the security researcher(s) are working on, and may not be known to others (use a 0-day to steal other 0-days). I'd presume that a decent security researcher's laptop would have much more valuable things on it, compared to Bob the Waiter's laptop. Educated guess. Grain of salt, etc...