Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

21–30 of 302 posts

Re: North Korean campaign targeting security researchers

#21
I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit.

I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do Linux/Mac package managers solve this?

[1] https://ffmpeg.org/download.html

Re: North Korean campaign targeting security researchers

#22
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

1. Spy on researchers, harvest 0-days before they're published, monetize them (selling 0-days, spreading ransomware, etc), 2. Sell info/research to publish academic research before the victim does, 3. geopolitical leverage, 4. blackmail researchers to get more of the above, 5. use 0-days found by others for global dragnet surveillance, which translates to money and political power, 6. plant (dormant) code in critical infrastructure internationally for geopolitical leverage / future war. 7. inject any code into any repo that the researchers have access to or that the researchers are known to make use of (tools), 8. economic espionage / accesss to high-tech international IP

Just kind of what the NSA does really with the exception of monetizing on ransomware?

Re: North Korean campaign targeting security researchers

#23

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

Put a gun to someone's head and you'll find that they're capable of just about anything.

Re: North Korean campaign targeting security researchers

#24
post #6

This is doubly concerning: Not only for researchers, but also for the public. I always imagined the North Koreans to be at a technical level where they would be the ones consuming published exploits more so than imagining their own. This article means that they are advanced enough to focus on suppressing knowledge rather than consuming what is publicly available.

DPRK’s top 1% live what amounts to an upper middle class life, and tend to educate their children abroad. My understanding is that they even have access to an unfiltered Internet supplied by China. The threat of extermination of their families if they step out of line politically seems to keep those people in check.

I would think they are kept in check the same way the upper middle class is kept in check pretty much everywhere in the world. They live a very comfortable life style and have no interest in doing anything that would jeopardize that.

Re: North Korean campaign targeting security researchers

#25
Not really shocking or new but kind of interesting. Why would they use 0days on security researchers. My guess is it's a test with upside. On the one hand if it works on a security researcher, you can go "live" because you got a good one and on the other hand you estimate that in the long run you'll get 1+x 0days out of the deal from said researcher.

As a security researcher it also presents an interesting situation. If you're careful enough and can pretend to be dumb enough, you might be able to harvest fresh attack vectors/0day etc. "for free" but the downside is if you overestimate yourself you'll get pwned.

Re: North Korean campaign targeting security researchers

#26

This is doubly concerning: Not only for researchers, but also for the public. I always imagined the North Koreans to be at a technical level where they would be the ones consuming published exploits more so than imagining their own. This article means that they are advanced enough to focus on suppressing knowledge rather than consuming what is publicly available.

You should certainly update your perception of NK then. They stole more crypto than anyone else in 2022. [1] 1 - https://www.reuters.com/technology/record-breaking-2022-nort...

> You should certainly update your perception of NK then. They stole more crypto than anyone else in 2022.

I never heard of anyone stoling crypto, so you might be right. /s

Re: North Korean campaign targeting security researchers

#27

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

>I don't understand why the media downplays them so heavily.

Because in the same way as morale can be a force multiplier, an extreme lack of it can be a force divider. Combine that with their (very likely) inability to sustain even a regional war for more than a few weeks, their antiquated equipment, and their largely unsuccessful domestic military developments, and it's not hard to write them off as largely a non-threat, whether or not this is truly the case.

The major downside is that even if they only manage to sustain for a few weeks, that's plenty of time to level Seoul and inflict damage on cities further south should they decide to make a push against the ROK, and this is what shouldn't be downplayed.

Re: North Korean campaign targeting security researchers

#28
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

Security researchers often have the most access to stuff at big companies.

Re: North Korean campaign targeting security researchers

#29

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

Put a gun to someone's head and you'll find that they're capable of just about anything.

Even better, do it to their children, and literally everybody else who is important in their lives.

Re: North Korean campaign targeting security researchers

#30
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

I'm thinking they are hoping to find exploits that the security researcher(s) are working on, and may not be known to others (use a 0-day to steal other 0-days). I'd presume that a decent security researcher's laptop would have much more valuable things on it, compared to Bob the Waiter's laptop. Educated guess. Grain of salt, etc...

I don't know - I think primary research on these things might be easier than sifting through all the "exhaust" on someone else's laptop to figure out what they've discovered.
Post reply on HN