Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

41–50 of 302 posts

Re: North Korean campaign targeting security researchers

#41

Earlier quoted context omitted.

Even better, do it to their children, and literally everybody else who is important in their lives.

Probably more carrot than stick. NK hackers who can bring in millions to the state from crypto hacking, ransom etc likely live more comfortably than manual laborers.

Both really. In NK the stick awaits all who stop chasing the carrot.

Re: North Korean campaign targeting security researchers

#42

I wonder how legit are some of the most popular download sites: e.g ffmpeg windows binaries [1] are hosted from some random person’s site. Sure you can check the checksum etc but that still doesn’t guarantee any relationship with a specific git commit. I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do…

"How do Linux/Mac package managers solve this?"

By building their binaries from source and hosting them on their servers?

Re: North Korean campaign targeting security researchers

#45
post #32
post #28

Earlier quoted context omitted.

Security researchers often have the most access to stuff at big companies.

I don't know about that. I work in security, as a service to customers, but we have a running gag about "the real security people" who give you a phone call if you accidentally step off the path on your work machine.

I don't work in security anymore, but when I did, access tended to be... loose. Outside of security, there hasn't been a single job (of quite a few) where I didn't have root access.

At one of the hosting companies I worked at -- for example -- I was able to download the root password of every linux host and the domain password for every windows host as a proof of concept for a project. Nobody told me to stop but as a courtesy I did end up telling the manager of the internal SOC that it was possible. He was pretty floored. Apparently they setup monitoring for single queries of passwords, but since my queries returned more than one result, it wasn't "caught".

So yeah. Lots of access.

Re: North Korean campaign targeting security researchers

#46
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

It states clearly in the article the goal was to acquire debug symbols for Ms, Citrix, and others with the goal of reverse engineering. If you have been following Citrix, their Netscaler product has been the subject of multiple high severity vulnerabilities, and they sit in mission critical networks. From here the most likely move is their most common, ransomware, the proceeds from which they use to fund parts of the…

That was the stated legitimate purpose of the GetSymbol software by its creators. As far as I understand, this data is freely available and the GetSymbol software makes it easier to download rather than having to go to multiple different websites.

The ultimate purpose of the malware embedded within the GetSymbol software is what is not known.

Re: North Korean campaign targeting security researchers

#47
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

It states clearly in the article the goal was to acquire debug symbols for Ms, Citrix, and others with the goal of reverse engineering. If you have been following Citrix, their Netscaler product has been the subject of multiple high severity vulnerabilities, and they sit in mission critical networks. From here the most likely move is their most common, ransomware, the proceeds from which they use to fund parts of the…

That was the decoy behind the secondary infection vector, not the motivation.

Re: North Korean campaign targeting security researchers

#48

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

[flagged]

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men.

It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

Re: North Korean campaign targeting security researchers

#49

Evidence for attribution to North Korea?

"SoUrCe?"

This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles.

This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.

Re: North Korean campaign targeting security researchers

#50
I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point.

If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!

Speaking of, can someone find the exploit in the linked repository? I'm curious what it does, but can't bother with going through all files. TFA could've linked to it, as well as mention how they determined this project is linked to NK hackers...

Post reply on HN