Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

281–290 of 302 posts

Re: North Korean campaign targeting security researchers

#281

Earlier quoted context omitted.

So, you believe their nuclear weapons don't work?

Probably not, with insufficient confidence to assume that is the case

That's a strange assumption when many countries were able to independently verify nuclear tests between 2009 and 2017. The largest of which had a bast yield 4 to 12 times the nuke dropped on Nagasaki.

Re: North Korean campaign targeting security researchers

#282
post #280

Earlier quoted context omitted.

The 0-day is in a popular software package. The GitHub repo apparently contains a backdoor ability to execute code from the attacker. If I had to guess, this would be the software update functionality here: https://github.com/dbgsymbol/getsymbol/blob/cb4bdedc1a85c308...

That's just malware. There's no 0-day here.

That’s what Google is calling it, so I’m inclined to believe them.

Re: North Korean campaign targeting security researchers

#283

Earlier quoted context omitted.

Probably not, with insufficient confidence to assume that is the case

That's a strange assumption when many countries were able to independently verify nuclear tests between 2009 and 2017. The largest of which had a bast yield 4 to 12 times the nuke dropped on Nagasaki.

These tests happened. Most experts suspect that their success rates were far below claimed outcomes. But the important question is can you put the bomb on a weapon, launch it, and detonate it at the target. I think probably not very successfully. I also suspect they’re not stockpiling these things as claimed.

I also don’t think it matters because they would be pretty dumb to use them. I’m of the mindset that they will most likely simply collapse at some point and the nukes will become unmaintained and useless.

Re: North Korean campaign targeting security researchers

#284

I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…

Even binaries hosted on an official website can be hacked, if they hack the website and change the checksums. It happened to Linux Mint. https://www.trendmicro.com/vinfo/fr/security/news/cybercrime... .

This is why signing binaries is important.

Re: North Korean campaign targeting security researchers

#285
post #280

Earlier quoted context omitted.

That's just malware. There's no 0-day here.

That’s what Google is calling it, so I’m inclined to believe them.

"In addition to targeting researchers with 0-day exploits, the threat actors also developed a standalone Windows tool that has the stated goal of 'download debugging symbols from Microsoft, Google, Mozilla and Citrix symbol servers for reverse engineers.'

The attackers used a 0-day but getsymbol is not one.

Re: North Korean campaign targeting security researchers

#286
post #186
post #124

Earlier quoted context omitted.

Someone of you may enjoy this[0] podcast on the North Korean Lazarus Group. [0] https://www.bbc.co.uk/programmes/w13xtvg9/episodes/downloads

Are we supposed to download this and run on our computers?

The podcast seems to be available on Spotify and similar.

Re: North Korean campaign targeting security researchers

#287

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

> They have money

And much more of it after crypto gained popularity. Darknet Diaries went through investigating some of their hacks. Amounts from one can be more than entire GDP of a small country. Some crypto is washed through Macanese etc banks but most is just used to pay for weapons and stuff directly.

Re: North Korean campaign targeting security researchers

#288

What I wonder is this: these North Koreans clearly have unrestricted internet access (sort of have to to find 0-days) and they also clearly at least understand English. How have they not accidentally stumbled across media that shows them all the things their state media doesn't?

"All of our secret agents are loyal patriots, while all of theirs are brainwashed hostages!" The reality is that like every other country's intelligence services, they would obviously recruit for patriotism. This question is like asking why US intelligence agents who have access to information about the DPRK beyond the propaganda don't defect to the DPRK's superior healthcare coverage, zero school shootings, and bett…

> defect to the DPRK's superior healthcare coverage, zero school shootings, and better litter management.

I can't believe you're glorifying the DPRK without mentioning that they celebrate Tax Abolition Day since eliminating it in 1974.

Re: North Korean campaign targeting security researchers

#289

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

It looks like its no longer on Github. Does anyone have the source code mirror? I would love to get a peek on it.

Re: North Korean campaign targeting security researchers

#290
post #285

Earlier quoted context omitted.

That’s what Google is calling it, so I’m inclined to believe them.

"In addition to targeting researchers with 0-day exploits, the threat actors also developed a standalone Windows tool that has the stated goal of 'download debugging symbols from Microsoft, Google, Mozilla and Citrix symbol servers for reverse engineers.' The attackers used a 0-day but getsymbol is not one.

Yep, that’s what I said.
Post reply on HN