Countering threats from North Korea
blog.google
blog.google
* Only serving the iframe at specific times, presumably when they knew an intended target would be visiting the site.
* In some email campaigns the targets received links with unique IDs. This was potentially used to enforcea one-time-click policy for each link and allow the exploit kit to only be served once.
* The exploit kit would AES encrypt each stage, including the clients’ responses with a session-specific key.
* Additional stages were not served if the previous stage failed.
Is this a normal level of sophistication for a CVE?They are hard to come buy and building tooling is a long and expensive process on top of everything else.
Most of what we got was recycled RAT malware with various packers though, it didn't trend towards being particularly interesting because you usually don't need to be to catch people, at least that's my impression. Maybe it's bad toupee fallacy.
Mobile numbers are non-geographic everywhere else that I know of.
Landlines used to be geographic but this isn't relevant any more again new to number portability.
Just saying that some countries are small enough that it's essentially the same.
https://stackoverflow.com/questions/18523417/can-i-retrieve-...
(Twilio is awesome by the way)
https://stackoverflow.com/questions/18523417/can-i-retrieve-...
(Twilio is awesome by the way)
Back in the 90s and early 2000s the worst that could happen was, say, texting a commercial number to get a polyphone ringtone, and that actually being a subscription. But obviously that is something you have to initiate first, not something passive.
My number was leaked in a particular data breach that actually had nothing to do with me, but a different family member who had all of their contacts vacuumed up before the breach. So from my perspective it was passive.
you can be sure to be bombarded with calls and sms if a students applies for a notify thing or gives their number somewhere outside exam halls or on student help websites.
same for shops asking for mobile numbers.
then there are marketers who randomly call each number, send sms to see what sticks.
the situation is pretty bad i would say because for every careful person who sees through the ruse, there are hundreds who fall for million dollar prizes and kyc scams and all.
people call you and say "we are form bank. main branch. you need to verify your debit card or your account will close". no name of bank, no place of branch, just "from bank. main branch".
At the moment it's pretty bad with lots of calls from overseas. (People with hilariously un-local accents trying to tell you they are calling from the Ministry of Health of Ministry of Manpower...)
Those overseas callers are faking caller id to look like local numbers.
Typically used via poorly named idn homograph attacks https://en.m.wikipedia.org/wiki/IDN_homograph_attack
Homographs look exactly the same.
(And of course "homograph" ["same writing" or "same picture"] is a better name than "homoglyph" ["same carving"].)
> a homoglyph is one of two or more graphemes, characters, or glyphs with shapes that appear identical or very similar.
"Very similar" and "two or more" being the key words.
As for homograph I found homoglyph by reading the wiki and it saying homoglyph is more appropriate.
(Insert obligatory "wiki it's not always accurate etc etc"). Overall I'd take either one and personally don't care. Just trying to match what you're saying with what I'm reading and make sense of where the truth is.
Diving in (even if the parent doesn't care :) ):
The last sentence is the real challenge: Meanings depend 100% on writer and reader understandings. If two agree that 'homograph' means 'chicken poop', as long as they're the only ones communicating then 'chicken poop' it is; but if someone else reads it, our language subsystem fails.
Some dictionaries influence meaning by being prescriptive (e.g., American Heritage, IIRC); others report what has been understood by being descriptive (e.g., Oxford). The problem is, Wikipedia is neither: It represents the understandings of a few editors of unknown knowledge; it is neither descriptive nor prescriptive and we quickly get into chicken poop scenarios.
* Homograph, report Merriam-Webster and Oxford, means words with the same spelling but different meanings (or origin or pronunciation), e.g., the bow of a ship and a bow and arrow.
* Homoglyph doesn't appear in Oxford, Merriam-Webster, American Heritage, or any others (per Wordnik and OneLook), except Wiktionary. Wiktionary descriptively traces the word back to 1938 (though maybe with a different meaning in that case) and says it means a glyph with the same or similar appearance but different meaning. That still doesn't define a term for the entire string "ycornbinator.com", only the "rn", but close enough!
To be clear: reporting what has been understood still influences meaning. Choice of inclusion moderates spread; definitions are inherently lossy and cannot capture the whole range of nuance; the compiler's understanding can be inaccurate. Lexicography is not a neutral art, no matter your choice of biases. And OED no less "represents the understandings of a few editors of unknown knowledge" than Wikipedia does. With different goals, and to different standards, to be sure, but Gell-Mann amnesia goes hard until you get into the weeds.
I agree and actually had a sentence in the GP that said it, but removed it because it was getting too long. An important point. Also, the Oxford English Dictionary intends to be descriptive and says so, but many readers won't understand that and take it as prescriptive.
> OED no less "represents the understandings of a few editors of unknown knowledge" than Wikipedia does.
The knowledge of OED editors is not unknown but well known and exceptional - the world's leading lexicographers, with the best training and decades of experience. The resources are exceptional: top-notch professional lexicographers, domain experts, databases, teams of volunteers reading and contributing, etc. The definitions are not based on the contemporary understanding of a few people but on over a century of accumulated research, back to the beginning of English, and the understandings of those people, plus it depends on the input of domain experts, editors, etc.
I'm not knocking Wikipedia, which has its value, and the OED is, like every human institution, limited. But beyond that general statement, the quoted sentence doesn't describe the OED at all.
What is unusual is that NK used a sophisticated attack chain to successfully pwn a hardened industry (notably, fintech).
At this point I think it’s safe to say that NK is a significant competitor to FVEY in terms of cyber warfare capabilities.
https://microsoftedge.github.io/edgevr/posts/Super-Duper-Sec...
https://microsoftedge.github.io/edgevr/posts/Introducing-Enh...
What they've found is that JIT can be disabled in most sites with no user-visible impact.
This, combined with WebAssembly, is a game-changer in waiting for browser security.
[1] https://chromium.googlesource.com/chromium/src/+/ddc017f9569...
(Disclaimer: I am head of TAG)
The thing with trying to hide yourself is you have to do everything right to guarantee some false flag operation will work but if you make enough mistakes in this process there will be reasonably high-confidence links between some action and some person.
An example that I _have_ seen in some write up: some snippet of malware code showing up in a stack overflow question (with the shape and user variables being the same).
At one point it's like... probably that person. Of course maybe there are other indicators to the contrary but that's data for you. Gotta use your noggin a bit.
I ask because it’s broadly accepted that there are extremely powerful and wealthy entities in the West who benefit from an aggressive US foreign policy and heightened geopolitical tensions.
Hack something shoddy together, go to war/regime change/etc, and worst case if it does come to light that the "intel" was wrong, a well-placed "whoopsie-daisy" is enough to wash hands of all responsibility or scrutiny.
Following those links yield these two documents, which both have "Attribution" sections. Presumably some of these tell-tale signs were identified in the ongoing exploitation.
https://www.clearskysec.com/wp-content/uploads/2020/08/Dream...
https://securelist.com/operation-applejeus/87553/#attributio...
> One of the top identifiers of Lazarus is their dual attack mission – money theft and espionage. This modus operandi is unique to North Korea, as other state actors usually focus on espionage only. North Korean money theft operations are carried out in service of the government, as a way of funding the nuclear program
Like, seriously? "You not only do espionage but also steal money, therefore you're NK"?
This is about WannaCry, but it shows how multi-source attribution is done.
Lol
In the real world you can't possibly fake every single code comment left in Russian as long as these comments make sense and there's enough of them. It takes a lot of effort to actually truly fake something, at certain point it becomes the same as completely doing the job itself in order to properly fake it.
A vulnerability is a vulnerability. Why bring politics in, right in the title? It would feel much more OK if simply said in the text, that a NK hacker group is currently known for exploiting it.
Imagine it was a vulnerability being exploited by a TLA of the US of A. What would Google say? Or would they have received a gag order to not talk about it at all? But then what happens if some third-party researcher discovers the vulnerability independently and reports it? What would Google say?
It means more random user-agent/referrer data for them and I'm guessing more domain authority or whatever that crap is.
It's marketing. The article concludes with how the Google Chrome safe browsing list was updated bla bla bla.
It's all just marketing. That's how Google operates. Everything is a shop window. Everything you say, do and make. Google is the market research company.
Except they've repeatedly created products that no one wanted and killed them.
But that's a form of market research when you have a lot of money.
I feel like Google collects so much information it probably doesn't get much sense out of it. Who knows
Interesting seeing Japanese here but might just be a language thing.
> LinkedIn profile Protection – we believe that LinkedIn has yet to develop sufficient security mechanisms and protect its users against impostor accounts. We find it alarming that a fictitious profile, copycat an existing account, can be open and use without alerting to source profile from which the information was stolen, as well as profiles contacted by the new imposter profile.
Sounds like some low hanging fruit
Honeypots are harder than they look, basically.
As regarding effectiveness of firejail, then it relies on Linux container protection which is quite good given that many providers use that to run untrusted code.
However, the problem with firejail or similar tools is that that try to integrate with GUI and that makes the attack surface vastly bigger. To protect against highly sophisticated attacks something like Qubes OS should be used with explicit whitelisting of domains to connect.
What do you conclude? We shouldn't care or do anything? The Internet, the medium, seems to greatly increase the volume of scams and from everyone, not just countries.
https://bgpview.io/asn/131279#peers-v4
http://cooks.org.kp/en/ is hosted on that network.
they are truly on survival mode, and given Russia's recent performance in Ukraine, its really eye opening to see just how much of a paper tiger their military is, relying again on asymmetric weapons of indiscriminate destruction of all things human.
Ok thats clever, and a nod to Zeus exploit kit, I love hacker group names lol
assuming it has capabilities to support "modern" web
Edit: from another comment in a sibling thread, you indicate thinking that WASM has a "security model / sandbox". That would have been (part of) the answer to the grandparent comment I suppose.
"WebAssembly describes a memory-safe, sandboxed execution environment that may even be implemented inside existing JavaScript virtual machines. When embedded in the web, WebAssembly will enforce the same-origin and permissions security policies of the browser."
Basically I felt like it was designed with security in mind and I do wonder whether it'd prevent attacks like this
The question is,
is WASM's security model / sandbox "safer" / "easier to actually execute" than JS'?
Of course JS ain't gonna go anywhere now, but if popular JS frameworks started emitting WebAssembly behind the scenes, so devs could still write their JS(and C++/C#/etc) code, but it'd use WASM under the hood then that'd start process of the deprecation of JS.
Which would mean that after all popular JS frameworks managed to migrate and popular sites adopted to this, then in ideal world you'd be able to turn off javascript and still use those sites/apps via WASM, not by default for everyone, but at least users that care would have an option to do so while still being able to use the web.
You gotta start somewhere
I'm wrong somewhere? or out of the touch with reality?
https://developer.mozilla.org/en-US/docs/WebAssembly
As for vulnerabilities, here are nccgroup's slides about WASM explots:
https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-...
Here's an example vulnerability in WASM parsing leading to RCE:
https://labs.f-secure.com/assets/BlogFiles/apple-safari-wasm...
What could happen is that browsers will support wasm natively and they'll translate JS into wasm. I'm not qualified enough to judge whether it would be possible to achieve current levels of JS performance with that approach, but theoretically it could be possible. In this case only wasm security will matter.
But I did not hear about any kinds of those plans, those are just my wild speculations. So deprecating of JS is not going to happen anytime soon. Wasm will accompany JS and that's about it for the foreseeable future.
Your question is non-sensical as is. I think you need to expand it to have people be less confused as to what you’re asking.
The second one is bigger.
And WebAssembly has been used by Mozilla for sandboxing: https://hacks.mozilla.org/2021/12/webassembly-and-back-again...
So it may help. But wasm is never going to be eg a substitute for JS, so it's not going to "save us" the way you imply.
They're soon to test a nuclear weapon and already play fun games testing missiles and having them land just off the coast of Japan. Not going to be fun once those things are nuclear missiles and en route to Tokyo.
The people are severely repressed, it's hard to imagine how much North Koreans suffer, look up Yeonmi Park's story.
What we seem to do is ignore these maniacs, until it's too late or it's absolutely critical, then they hold us hostage, like Putin.
(edit: another old article that points out inconsistencies in Yeonmi Park statements: https://thediplomat.com/2014/12/the-strange-tale-of-yeonmi-p... ... The JRE interview wasn't a fluke)
I don't think that you can reasonably treat Yeonmi Park as a reliable witness.
North Korea's train network is 4700km long, though it is not perfect... If you want to travel from Pyongyang to Chongjin for example, you're better off flying there
Sanctions against Russia aren't uniquely effective in a way that sanctions against NK aren't. It's just that the threat of having your economy look like North Korea's is pretty dire.