Google: North Korean hackers posing as security analysts

Discussion in 'other security issues & news' started by hawki, Jan 27, 2021.

  1. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "Google releases alarming report about North Korean hackers posing as security analysts...

    Google unveiled a new report from its Threat Analysis Group on Monday highlighting the work of a group of cyberattackers associated with the government of North Korea that sought to impersonate cybersecurity researchers in an effort to target those 'working on vulnerability research and development at different companies and organizations.'...

    ...the attackers used a variety of fake blogs, Twitter accounts and LinkedIn profiles to make themselves look legitimate and communicate with researchers and analysts they were hoping to go after.

    '...After establishing initial communications, the actors would ask the targeted researcher if they wanted to collaborate on vulnerability research together, and then provide the researcher with a Visual Studio Project'...

    'Within the Visual Studio Project would be source code for exploiting the vulnerability, as well as an additional DLL that would be executed through Visual Studio Build Events. The DLL is custom malware that would immediately begin communicating with actor-controlled C2 domains.'..."

    https://www.techrepublic.com/articl...-posing-as-security-analysts/#ftag=RSS56d97e7
     
  2. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    That is one hell of a genius idea. Trying to hack the people who find zero day exploits and harvest em by using your own zero day exploit, 300 IQ right here

    Seems like the majority of em failed tho, minus that one guy that got compromised because his browser was non-restricted. I mean as ahome user I have no reason to be afraid, but if ure a high value target its just dumb not to sandbox or restrict ur browser so even in the event of it getting compromised nothing happens
     
    Last edited by a moderator: Jan 27, 2021
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
  4. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "Internet Explorer was to blame for spate of recent cyberattacks

    In a major revelation, security researchers have discovered that a yet-unpatched vulnerability in Microsoft’s venerable Internet Explorer (IE) web browser was responsible for the spate of attacks against security researchers reported last month.
    Google’s Threat Analysis Group (TAG) last month disclosed that a North Korean state-sponsored hacking group employed various means, including creating elaborate fake personas to engage with the researchers, in their bid to break into their workstations.

    Now, according to reports, South Korean security firm ENKI has identified a previously undisclosed zero-day vulnerability in IE, which they claim has been exploited in these recent attacks...

    According to the report, ENKI is in touch with Microsoft who’ve requested further details from the Korean company..."

    https://www.techradar.com/news/internet-explorer-was-to-blame-for-spate-of-recent-cyberattacks
     
  5. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Who of these researches is using IE in 2021...

    They should get their job revoked (if they really used IE)

    Well, maybe they were researching IE...
     
  6. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,174
    Location:
    USA
    We encountered one of our customers using IE last week. A lot of businesses, especially larger ones, are slow to move.

    I'm still wondering where North Korea got hackers. I thought they barely had internet...
     
  7. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "How North Korea's Hackers Became Dangerously Good...

    North Korea is cultivating elite hackers much like other countries train Olympic athletes, according to defectors and South Korean cyber and intelligence experts. Promising students are identified as young as 11 years old and funneled into special schools, where they are taught hacking and how to develop computer viruses.

    'Once you have been selected to get into the cyber unit, you receive a title that makes you a special citizen, and you don’t have to worry about food and the basic necessities,' says a defector familiar with North Korea’s cyber training..."

    [Interesting read]

    https://www.lopinion.fr/edition/wsj/how-north-korea-s-hackers-became-dangerously-good-147906
     
    Last edited: Feb 5, 2021
  8. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    Yeah I read hospitals or military still ran XP lol
     
  9. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    Interesting article. Thanks for sharing :thumb:
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    LOL, fully agree. And if you are foolish enough to use IE, then at least protect it with anti-exploit like HMPA, MBAE or Sandboxie.
     
  11. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,174
    Location:
    USA
    For all of the countless memes with pics Un holding a floppy disk, you have to suspect they don't have a lot of advanced tech, or at least didn't.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice