Update on campaign targeting security researchers
blog.google
blog.google
You got to admit that's a pretty clever strategy: cast a wide net and convert your older already patched exploit into a zero day.
you'd think security researchers would know the importance of keeping their system patched...
I would just write it as: "an entity" is trying to target security researchers. But it has less marketing power.
That feels like a bold claim to make without any references.
"Marble Framework"[1], Wikileaks' Vault 7:
> Marble is used to hamper forensic investigators and anti-virus companies from attributing viruses, trojans and hacking attacks to the CIA. [...] The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion
* * *
The first sentence says they themselves were able to attribute it to a North Korean-sponsored entity. One of the very first and obvious parts of the attribution process is considering and attempting to rule out false flags. False flag assessment could potentially be the majority of such an attribution effort, even.
They're specifically and explicitly staking their credibility on the claim that the attribution is ultimately North Korea and not merely some entity possibly masquerading as North Korea.
They certainly could be wrong, but these sorts of comments remind me of Feynman's remarks about non-physicists frequently suggesting the experts didn't consider [X] when the experts have in fact spent much of the past few decades concertedly considering and trying to understand [X] every day. If something is obvious to you, it's probably very obvious to the people who dedicate their lives to that field; at least if it's a technical field.
I'm intrigued, do you have a source for that? It's a phenomenon I came across daily (say Covid) and because the world is becoming increasingly complex I would argue that so does the appeal of 'simple' explanations, or 'why the experts are wrong'.
I think the counterpoint to it is that it's also somewhat common for specialists to get stuck in local Maxima, as their expertise provide a deep but potentially narrow framework for thinking about the problem, and people with more broad experience may be more able to find more imaginative solutions.
There was a piece that I can probably dig up about the theory that this has quite seriously affected e.g. theoretical / particule physics - for decades we have spent more and more money trying to prove more and more complex versions of superstring theory etc., and what might be needed is more whacky out-of-the-box ideas that could lead to simpler explanations that fit our subatomic observations better.
I would produce a research paper with "my method is the best" and nothing behind to prove it, I hope my peers would be very skeptical.
They can easily report their findings privately to the appropriate authorities without any loss in potential for real punishment or rectification.
Perhaps it could be to gain a bit more trust or respect from researchers (targeted or otherwise) and/or certain customers/users, or perhaps the US government encouraged them due to some geopolitical calculus, or maybe it's part of some plan that only makes sense because of some private knowledge known to few.
It may very well may not be North Korea, but you at least have to grant them some degree of charity in the sense that they're confidently putting their neck out there and saying "we really think the North Korean government is behind this". If they didn't have high confidence in the claim, they wouldn't have clearly attributed it to them like they did.
As you retorted, the default response in these situations would indeed be to say "a sophisticated entity" or "a sophisticated, possibly government-sponsored entity". Often even if you're pretty sure you know who it is.
Laying it all out on the field like they did probably suggests months and hundreds/thousands of man-hours of deep investigation to be sure they really got it right. They have some of the best security people in the world and rely on people taking their company and security teams seriously, so when they make such a claim, they know it carries a lot of weight and liability.
As others have mentioned, publicly presenting APT attribution evidence is often a double-edged sword for these sorts of things. Especially when you're Google and have a dual role of both threat research and directly protecting a lot of systems and customers against the threats you're researching. The more you tip your hand, the harder both jobs become, and you lose some of the mutual benefit you get from having both kinds of insight.
Also, circumstantially, the North Korean government has shown a pattern of things like this for decades. Even if you hypothetically assumed 90% of the North Korean attributions by private industry and intelligence agencies are wrong (very doubtful IMO; but just for the sake of argument), the remaining 10% would still make this newly reported attack unsurprising for them. That of course certainly doesn't mean people should default to blaming them whenever they're accused, but it means the prior probability for these sorts of attacks isn't low, so it wouldn't be shocking if it is true.
And, finally, just on how such attributions are done in the first place: at least as of 2021, it's often not as hard as you might think. The interesting thing about attribution is it flips the infamous "attacker's edge" around.
Attackers have a huge advantage when targeting a system/organization in that defenders have to win every time, but attackers often only have to win once to start infiltrating and pivoting. Conversely, covert attackers trying to evade or misdirect attribution need to successfully cover all of their tracks, but forensic investigators often only need to discover one mistake to start pulling on threads and pivoting. And, and in both cases, the bigger and more complex the surface area, the more likely at least one opening will be found.
Q: Do we think that anyone in North Korea, never mind anyone in power in North Korea, cares whether some group in the West "attributes" another alleged hack to them?
> forensic investigators often only need to discover one mistake to start pulling on threads and pivoting
Would that be the forensic investigators who can't actually disclose their evidence of the "mistake" because it might help the adversary?
Possibly. It's true that they may just not care at all. But it's difficult to know how they work and think internally.
>Would that be the forensic investigators who can't actually disclose their evidence of the "mistake" because it might help the adversary?
It would be the investigation/research team and whoever's leading them who would be making that decision. But, basically, yes.
That's a weak argument.
We live in a post-credibility world. Every major corporation, government and media giant has been caught lying on similar subjects and suffered no consequence.
The status quo is, Google can absolutely afford to lie to the public and expect it not to affect is bottom line even if it gets caught (or at least, affect its bottom line less than pissing off the US by pointing the finger at an allied country would).
(On the other hand, if it did cover up US allies that way, I'd expect whistleblowers to reveal it, and so far I don't think they have; so I dunno)
Surely no security researcher would open a link in IE as their "burner browser"?
Edge is the Microsoft browser whose newer versions are based on Chromium.
More on IE in South Korea: https://www.nationthailand.com/Startup_and_IT/30321025
I submitted the article here, hopefully we get an on-the-ground update. https://news.ycombinator.com/item?id=26656052
I guess I had assumed that the standard was compatible with newer versions of Windows or MS browsers. Really sad if it isn’t.
Unsure on whether major sites have gotten around to removing it though, perhaps a Korean HN reader could comment.
Also worth pointing out that security researchers targeting specific platforms/applications (say a specific version of older Windows where one particular organization has applications which require a specific version of IE) might be a valuable stack for the researcher to spend time on.
That said, those stacks/environments should be treated like a meth lab: you want to be very careful what you do with it and it shouldn’t be commingled with where you live and play.
There are US private citizens who are monitored/tracked due to the known national security risk if they are captured to work for other nations. Cybersecurity is huge.
Last name sounds like he is affiliated with Lazarus?
I equate security devs to arms dealers. It sounds like a cool job, but it seems like it's not.
I think it's totally fair to critique the arms dealers (and that's indeed undeniably exactly what they are), but only a small percentage fall into that bucket.