Live data from Hacker News

North Korean campaign targeting security researchers

blog.google

81–90 of 302 posts

Re: North Korean campaign targeting security researchers

#81

Earlier quoted context omitted.

those things aren't mutually exclusive. North Korea is a malnourished country, evidenced by the pretty stark fact that South Koreans are now so much taller that South Korean women are approaching the height of North Korean men. It's just that if you pump a quarter of your entire GDP into nukes and hackers you can still be decent at it even if your people are starving.

[flagged]

It's not that hard to verify given the people who have risked their life to escape the country and spoken openly about the conditions there.

Re: North Korean campaign targeting security researchers

#82
post #25

Not really shocking or new but kind of interesting. Why would they use 0days on security researchers. My guess is it's a test with upside. On the one hand if it works on a security researcher, you can go "live" because you got a good one and on the other hand you estimate that in the long run you'll get 1+x 0days out of the deal from said researcher. As a security researcher it also presents an interesting situation.…

Security researchers generally have more 0 days.

Re: North Korean campaign targeting security researchers

#83
post #65
post #57

Earlier quoted context omitted.

[flagged]

"Ending the war" requires handing South Korea over to DPRK based on their conditions and they still claim their government has rightful jurisdiction over it. I mean the war is effectively over. It's been a cold war since the "cease fire" has been adhered to. It's not like they're going to stop trying if we agreed to take down the DMZ. Their entire culture is based around reunification and defeating the evil Americans…

You could equally say ending the war means handing NK over to SK because that's what South Korea's constitution says.

Less flippantly, "ending the war" means reaching a mutual agreement that preserves the two Korea's current territories: nobody sane is using the term to mean anything else.

(BTW, South Korea did push for officially ending the war multiple times, IIRC. It's just that North Korea remains uninterested. Same for the US - probably because they don't see the deal happening realistically.)

Re: North Korean campaign targeting security researchers

#84

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

Put a gun to someone's head and you'll find that they're capable of just about anything.

Put a gun to someone's head, and they suddenly become less capable. A small amount of stress is good for productivity, but excessive stress destroys cognitive abilities.

Re: North Korean campaign targeting security researchers

#86

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

I'm really curious where the 0-day is in the code of the project honestly

Re: North Korean campaign targeting security researchers

#87

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

> technical capacities or ability to recruit smart hard working people

Of course, there are different senses of "recruitment". The best recruits don't know they even have been..

The take-away here is that it's 99% social engineering and 1% a script-kiddy payload drop. Their SE play is based on our innate ability to be recruited, because we want to be. Because we spend our school and college days being conditioned to want to be valued, to feel needed, to look for validation and reward, to make beneficial connections and sell ourselves. Self commodification/reification is the beating heart of capitalism.

They're smart to use that against us, by reaching out to security researchers, who (from personal experience) often feel isolated and/or undervalued.

After all it's just "international collaboration" , right?

Without due diligence in checking out new contacts (especially if they contact you to discuss things that they know interest you and then stroke the ego of your specialism) recruitment is easy.

In the end you can't easily know whether that charismatic voice on the phone is really from your government, from Google, from a fellow researcher who wants to "share and collaborate"... and you probably wouldn't know what would constitute a credible proof of identity.

Intelligence agencies could do well to spend a little money on benevolently watching out for commercial, civic, academic or hobbyist researchers who are valuable targets and sending a polite heads-up when the packets start arriving from N Korea.

Re: North Korean campaign targeting security researchers

#88
post #30

Earlier quoted context omitted.

I'm thinking they are hoping to find exploits that the security researcher(s) are working on, and may not be known to others (use a 0-day to steal other 0-days). I'd presume that a decent security researcher's laptop would have much more valuable things on it, compared to Bob the Waiter's laptop. Educated guess. Grain of salt, etc...

I don't know - I think primary research on these things might be easier than sifting through all the "exhaust" on someone else's laptop to figure out what they've discovered.

On difficult targets this is unlikely to be the case.

Re: North Korean campaign targeting security researchers

#89

Lifetimes ago as an intelligence officer I spent years tracking DPRK activities and developments. People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.

[flagged]

A few years ago during the 2016 Democratic primaries, Bernie Sanders was roundly mocked by mainstream media for saying NK was a top threat due to their disengagement from the international processes.

https://www.youtube.com/watch?v=8M4CoEodUTI

Re: North Korean campaign targeting security researchers

#90

I notice that the getsymbol tool on Github has 214 stars, and no banner to indicate that the tool is malicious. There is a recently filed issue with a link to the Google blog post, but that's it. If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)

This also serves as a reminder that code hosted on github might be malicious and we shouldn't blindly trust those just because the author seems to have similar interests.. I've done that multiple times :(
Post reply on HN