Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

51–60 of 302 posts

Re: North Korean campaign targeting security researchers

#51
post #7

help me think like a blackhat. what is the end game for this? attempting to see what knowledge researchers have to be able to detect, circumvent, etc what the "bad guys" are up to? attempting to dox, smear the research(er)?

1. Spy on researchers, harvest 0-days before they're published, monetize them (selling 0-days, spreading ransomware, etc), 2. Sell info/research to publish academic research before the victim does, 3. geopolitical leverage, 4. blackmail researchers to get more of the above, 5. use 0-days found by others for global dragnet surveillance, which translates to money and political power, 6. plant (dormant) code in critical…

Given the crazy shit the CIA has been documented to get up to, and the fact that the NSA has similar lack of oversight of agents in the field, why do you think that there isn't any monetizing on ransomware going on?

Re: North Korean campaign targeting security researchers

#52
post #35

[flagged]

Why tf would you post an unsanitized link to a malware executable here? edit: nice edit to the parent. the original was a github link to the .exe file.

Most of us don't run Windows, this is HACKER News not PEBKAC News.

Re: North Korean campaign targeting security researchers

#53
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

That isn't what they said the threat was; they were sent a document that exploited a 0-day in whatever program reads it.

Re: North Korean campaign targeting security researchers

#54
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

> the threat actors sent a malicious file that contained at least one 0-day in a popular software package

i.e. not executables

Re: North Korean campaign targeting security researchers

#55

Earlier quoted context omitted.

[flagged]

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

Re: North Korean campaign targeting security researchers

#56
post #49

Evidence for attribution to North Korea?

"SoUrCe?" This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles. This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.

Attributing cybercrime is never a slam dunk unless you have physical evidence: devices, people, etc. /var/log/*/access.conf is not that.

Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal.

WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chinese, Iranian, etc.

It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution.

Re: North Korean campaign targeting security researchers

#57

Earlier quoted context omitted.

[flagged]

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

Re: North Korean campaign targeting security researchers

#58
post #35

[flagged]

Why tf would you post an unsanitized link to a malware executable here? edit: nice edit to the parent. the original was a github link to the .exe file.

Because we assume our fellow users here are not morons and aren't going to download a file from virustotal.com that says "2 security vendors flagged this file as malicious" and run it and get infected.

You'll note that the github.com link was also published upthread, and is even more malicious.

In linking to the binary, I can download it and run it through radare2/ghidra/idapro and do some static analysis on it for myself.

Re: North Korean campaign targeting security researchers

#59

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

>ability to recruit smart hard working people

including non-nationals?

Re: North Korean campaign targeting security researchers

#60
post #57

Earlier quoted context omitted.

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

> maybe the US should end the korean war

Takes two, not just the UN side, to end the war.

Post reply on HN