Earlier quoted context omitted.
Thats a quote from the attacker, not part of the article itself. I don't think they are suggesting the article was AI written.
[flagged]
Anatomy of a Failed (Nation-State?) Attack
31–40 of 40 posts
Re: Anatomy of a Failed (Nation-State?) Attack
#32Re: Anatomy of a Failed (Nation-State?) Attack
#33Crime surged during COVID. But, what type of crime? https://www.tandfonline.com/doi/full/10.1080/2330443X.2022.2... Hint: homicides and car theft. Burglary and larceny actually went down. But, homicides surged prior to the start of the pandemic. If there is no correlation between the economic shutdown and homicides, then the crime surge was basically just car theft. Car theft does not come from random homeless people…
We aren't in a recession while the stock market is up, even though that has nothing do with the state of the economy
For >10 years prior I had a fairly flat salary at two separate employers. Yearly raise of about 2%.
Now salary is up about 50% from almost 10 years ago and home value almost doubled during the same timeframe.
I know I’m not that lucky in life… I don’t live in a HCOL area. I don’t work in an industry that is on fire. Nobody actually gets huge raises for performance.
Sure, the stock market has seen enormous gains over the past 10-15 years. Even the major indices have maintained gains that would traditionally be unimaginable.
That can’t be real growth - it’s the recipe for inflation.
If half the country owned $1000 of NVIDIA 20 years ago, would we be richer? No, inflation would follow and the other half would be poorer…
Re: Anatomy of a Failed (Nation-State?) Attack
#34Earlier quoted context omitted.
We aren't in a recession while the stock market is up, even though that has nothing do with the state of the economy
True, but the past 6-7 years make me seriously question whether it’s real growth or inflation. For >10 years prior I had a fairly flat salary at two separate employers. Yearly raise of about 2%. Now salary is up about 50% from almost 10 years ago and home value almost doubled during the same timeframe. I know I’m not that lucky in life… I don’t live in a HCOL area. I don’t work in an industry that is on fire. Nobody…
Inflation has been focused in assets for... some reason, and assets aren't counted in CPI, giving the government a false signal that it was okay to print more money for a while now.
Have a look at every other stock market, too. They don't usually go up forever like this. They usually stay steady or go up quite slowly.
Re: Anatomy of a Failed (Nation-State?) Attack
#35This all stinks of Lazarus: https://en.wikipedia.org/wiki/Lazarus_Group I've done incident responses for this exact type of attack multiple times. They've gotten much better organized lately and will often contact developers directly (over LinkedIn or WhatsApp) to run this type of attack. (Although, usually pretending to run a test for a job interview -- which is maybe why the author was confused about the code)
Why assume it is Lazarus? This sort of an attack is comically simple to pull off with a 12b obliterated LLM model and some basic scripts and proxies. Security has to evolve, or the world will be cooked by script kiddies running email loops. There's really nothing sophisticated about this these days, and it's only a short matter of time before it becomes commonplace.
Attribution is hard, but if we're talking about defending, there's little cost to assuming Lazarus-style threat actor.
Re: Anatomy of a Failed (Nation-State?) Attack
#36This all stinks of Lazarus: https://en.wikipedia.org/wiki/Lazarus_Group I've done incident responses for this exact type of attack multiple times. They've gotten much better organized lately and will often contact developers directly (over LinkedIn or WhatsApp) to run this type of attack. (Although, usually pretending to run a test for a job interview -- which is maybe why the author was confused about the code)
Why assume it is Lazarus? This sort of an attack is comically simple to pull off with a 12b obliterated LLM model and some basic scripts and proxies. Security has to evolve, or the world will be cooked by script kiddies running email loops. There's really nothing sophisticated about this these days, and it's only a short matter of time before it becomes commonplace.
But people train up and develop skills.
Re: Anatomy of a Failed (Nation-State?) Attack
#37Earlier quoted context omitted.
Why assume it is Lazarus? This sort of an attack is comically simple to pull off with a 12b obliterated LLM model and some basic scripts and proxies. Security has to evolve, or the world will be cooked by script kiddies running email loops. There's really nothing sophisticated about this these days, and it's only a short matter of time before it becomes commonplace.
Fair challenge, you're right that there's nothing sophisticated about this type of activity, but if you look at Lazarus activity this is their ttp. I mentioned TraderTraitor, go look them up (that sounds terse, it's not meant to be). They stole a couple of hundred million dollars in the past 6 months. They're not particularly sophisticated in terms of ttp, but because they're a nation-state actor they it's an entirel…
Very. Frustrating how many "Nation State" attributions boil down entirely because it's some Russian hacker, and they're using some publicly known bit of malware.
No 0days, no magic...
Re: Anatomy of a Failed (Nation-State?) Attack
#38This all stinks of Lazarus: https://en.wikipedia.org/wiki/Lazarus_Group I've done incident responses for this exact type of attack multiple times. They've gotten much better organized lately and will often contact developers directly (over LinkedIn or WhatsApp) to run this type of attack. (Although, usually pretending to run a test for a job interview -- which is maybe why the author was confused about the code)
100%. I can't find it now, but someone last month posted a similar story on HN. The threat actor had stolen someone's GitHub account and altered their otherwise legitimate looking repo. They'll expend a lot of effort in order to masquerade and trick you. TraderTraitor is another good DPRK example. Anyone reading - if you're ever a victim, worth reporting to your national CERT and your org. The CERT can provide advice…
Some 13yo kid with a VPS could do it
Re: Anatomy of a Failed (Nation-State?) Attack
#39Earlier quoted context omitted.
True, but the past 6-7 years make me seriously question whether it’s real growth or inflation. For >10 years prior I had a fairly flat salary at two separate employers. Yearly raise of about 2%. Now salary is up about 50% from almost 10 years ago and home value almost doubled during the same timeframe. I know I’m not that lucky in life… I don’t live in a HCOL area. I don’t work in an industry that is on fire. Nobody…
Oh it's all inflation. Don't pay attention to the inflation numbers from the government - pay attention to how much essentials are up, and assets with similar fundamentals. Inflation has been focused in assets for... some reason, and assets aren't counted in CPI, giving the government a false signal that it was okay to print more money for a while now. Have a look at every other stock market, too. They don't usually…
All inflation numbers are just faked.
Re: Anatomy of a Failed (Nation-State?) Attack
#40Author here - if anyone has any contacts at Cloudflare to get the proxied domains (at least roadpay[.]cc) taken down, that would be great. I wasn't able to get an abuse report to stick. Ditto for the related LinkedIn profile and Twitter accounts. The C2 IP (89.124.107.161) and malware-serving git repo (144.124.244.92) are both hosted on VDSINA in Russia, so not sure if there's anything to do there.
The best route to request a takedown of this domain and luaventures{.}xyz (the other domain mentioned in your blog post) would be at the host and/or the domain registrar. Cloudflare isn't the host or registrar these domains. We have no capacity to take down content hosted by others.