Earlier quoted context omitted.
Even better, do it to their children, and literally everybody else who is important in their lives.
Probably more carrot than stick. NK hackers who can bring in millions to the state from crypto hacking, ransom etc likely live more comfortably than manual laborers.
North Korean campaign targeting security researchers
41–50 of 302 posts
Re: North Korean campaign targeting security researchers
#42I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…
By building their binaries from source and hosting them on their servers?
Re: North Korean campaign targeting security researchers
#43[flagged]
edit: nice edit to the parent. the original was a github link to the .exe file.
Re: North Korean campaign targeting security researchers
#44Evidence for attribution to North Korea?
At minimum the payload.
Re: North Korean campaign targeting security researchers
#45Earlier quoted context omitted.
Security researchers often have the most access to stuff at big companies.
I don't know about that. I work in security, as a service to customers, but we have a running gag about "the real security people" who give you a phone call if you accidentally step off the path on your work machine.
At one of the hosting companies I worked at -- for example -- I was able to download the root password of every linux host and the domain password for every windows host as a proof of concept for a project. Nobody told me to stop but as a courtesy I did end up telling the manager of the internal SOC that it was possible. He was pretty floored. Apparently they setup monitoring for single queries of passwords, but since my queries returned more than one result, it wasn't "caught".
So yeah. Lots of access.
Re: North Korean campaign targeting security researchers
#46help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?
It states clearly in the article the goal was to acquire debug symbols for Ms, Citrix, and others with the goal of reverse engineering. If you have been following Citrix, their Netscaler product has been the subject of multiple high severity vulnerabilities, and they sit in mission critical networks. From here the most likely move is their most common, ransomware, the proceeds from which they use to fund parts of the…
The ultimate purpose of the malware embedded within the GetSymbol software is what is not known.
Re: North Korean campaign targeting security researchers
#47help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?
It states clearly in the article the goal was to acquire debug symbols for Ms, Citrix, and others with the goal of reverse engineering. If you have been following Citrix, their Netscaler product has been the subject of multiple high severity vulnerabilities, and they sit in mission critical networks. From here the most likely move is their most common, ransomware, the proceeds from which they use to fund parts of the…
Re: North Korean campaign targeting security researchers
#48Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.
[flagged]
It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.
Re: North Korean campaign targeting security researchers
#49Evidence for attribution to North Korea?
This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles.
This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.
Re: North Korean campaign targeting security researchers
#50If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!
Speaking of, can someone find the exploit in the linked repository? I'm curious what it does, but can't bother with going through all files. TFA could've linked to it, as well as mention how they determined this project is linked to NK hackers...