Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

31–40 of 302 posts

Re: North Korean campaign targeting security researchers

#31

Earlier quoted context omitted.

Put a gun to someone's head and you'll find that they're capable of just about anything.

Even better, do it to their children, and literally everybody else who is important in their lives.

Probably more carrot than stick. NK hackers who can bring in millions to the state from crypto hacking, ransom etc likely live more comfortably than manual laborers.

Re: North Korean campaign targeting security researchers

#32
post #28
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

Security researchers often have the most access to stuff at big companies.

I don't know about that. I work in security, as a service to customers, but we have a running gag about "the real security people" who give you a phone call if you accidentally step off the path on your work machine.

Re: North Korean campaign targeting security researchers

#33
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

It states clearly in the article the goal was to acquire debug symbols for Ms, Citrix, and others with the goal of reverse engineering. If you have been following Citrix, their Netscaler product has been the subject of multiple high severity vulnerabilities, and they sit in mission critical networks. From here the most likely move is their most common, ransomware, the proceeds from which they use to fund parts of their military.

Re: North Korean campaign targeting security researchers

#34

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

    > third-world living conditions [...]
I know that the phrase has gained an orthogonal meaning since the cold war, but if we use the original one it's funny to call what's arguably the only remaining second-world country "third-world".

Re: North Korean campaign targeting security researchers

#37
I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it.

If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

Re: North Korean campaign targeting security researchers

#38

Earlier quoted context omitted.

Even better, do it to their children, and literally everybody else who is important in their lives.

Probably more carrot than stick. NK hackers who can bring in millions to the state from crypto hacking, ransom etc likely live more comfortably than manual laborers.

Yeah, just look at what engineers here in the States are willing to do for money they don't really need

Re: North Korean campaign targeting security researchers

#39

I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…

Why trust Github? The GetSymbol tool has 215 stars there. Looks perfectly legit unless you check the issues.

https://github.com/dbgsymbol/getsymbol

Re: North Korean campaign targeting security researchers

#40
post #34

Earlier quoted context omitted.

> People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people. People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military. I don't understand why the media downplays them so heavily.

> third-world living conditions [...] I know that the phrase has gained an orthogonal meaning since the cold war, but if we use the original one it's funny to call what's arguably the only remaining second-world country "third-world".

I mean if we're going by the original definitions, I think Laos, Vietnam, and Cuba are also still second-world though none of them are bizarrely neo-Stalinist the way North Korea is.
Post reply on HN