Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

61–70 of 302 posts

Re: North Korean campaign targeting security researchers

#61
post #30

Earlier quoted context omitted.

I'm thinking they are hoping to find exploits that the security researcher(s) are working on, and may not be known to others (use a 0-day to steal other 0-days). I'd presume that a decent security researcher's laptop would have much more valuable things on it, compared to Bob the Waiter's laptop. Educated guess. Grain of salt, etc...

I don't know - I think primary research on these things might be easier than sifting through all the "exhaust" on someone else's laptop to figure out what they've discovered.

yeah although there might be easy things like correspondence on a bug report embargo

Re: North Korean campaign targeting security researchers

#62
post #57

Earlier quoted context omitted.

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

You can't be serious.

Re: North Korean campaign targeting security researchers

#63
post #49

Evidence for attribution to North Korea?

"SoUrCe?" This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles. This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.

This seems like a disproportionately mocking tone for the original comment made.

Re: North Korean campaign targeting security researchers

#64
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

> the threat actors sent a malicious file that contained at least one 0-day in a popular software package i.e. not executables

It became an executable :)

Re: North Korean campaign targeting security researchers

#65
post #57

Earlier quoted context omitted.

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

"Ending the war" requires handing South Korea over to DPRK based on their conditions and they still claim their government has rightful jurisdiction over it.

I mean the war is effectively over. It's been a cold war since the "cease fire" has been adhered to. It's not like they're going to stop trying if we agreed to take down the DMZ. Their entire culture is based around reunification and defeating the evil Americans.

Re: North Korean campaign targeting security researchers

#66
post #56
post #49

Earlier quoted context omitted.

"SoUrCe?" This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles. This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.

Attributing cybercrime is never a slam dunk unless you have physical evidence: devices, people, etc. /var/log/*/access.conf is not that. Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal. WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chines…

[deleted]

Re: North Korean campaign targeting security researchers

#67
post #57

Earlier quoted context omitted.

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

This is such a strange take it borders on satire.

Could you elaborate on if you genuinely think this would resolve the issues the DPRK experiences?

Re: North Korean campaign targeting security researchers

#68
post #50

I wonder what the chances are that a security researcher would execute a Windows binary they receive over chat from a rando. This isn't even security 101, just common sense at this point. If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!…

> how they determined this project is linked to NK hackers

If they have enough confidence to attribute and not disclose how/why, one can fairly guess they don't want to burn sources or indicators which might still be useful moving forward but likely won't be if disclosed...

Re: North Korean campaign targeting security researchers

#69

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

[flagged]

I can't speak for the general public but my own impression of the country is that its nuclear weapons and isolation make it incredibly dangerous, and the problem is only getting worse as their arsenal increases.

Plus they have pulled off a number of hacks that became mainstream news so I would expect plenty of people to think that North Korea has competent software developers.

Re: North Korean campaign targeting security researchers

#70
post #57

Earlier quoted context omitted.

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

This would cause immediate conflict with China. Imagine China showing up to liberate Mexico from the drug cartels.
Post reply on HN