I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni....
To some extent, the PDF viewer/OS doesn't matter. A dedicated and well resourced attacker like the Lazarus Group will find holes in all of them. The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets.
I dispute this: the web browser is one of the most defended pieces of software of all time, especially relative to its complexity. I would find it much safer to open a potentially malicious PDF in my browser's JS-based reader than using a desktop reader.
> The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets.
It also probably would have been helpful if one employee didn't have access to almost half of the validators, especially on a system they're accessing email with.
I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.
This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.
I don't install anything personal on my work computer, but I wouldn't hesitate to open an email or pdf from a seemingly trusted source. I don't really blame the dev here.
What you propose is a reasonable solution, but I feel like it slams in the face of actual human behavior. Most people act the way I describe, even most tech professionals.
This might just result in employees finding ways to remote access their work computer from their personal computer from wherever they are, but at least that's an additional wall for would-be attackers to hurdle.
Figure out a company uses <some-saas> register a phishing domain (e.g. gith.ub) send them an email with important info about their account, and a PDF attachment with more details.
If it's that easy to compromise a system all you have to do is get a few employees to open the PDF right?
I think the clear move here should be to avoid pdf, just like the move is to avoid doc
What usually happens is that layers 1 and 2 of 3 are constantly compromised, no one cares to follow up, and one day layer 3 gets compromised, shock of shocks.
It says it was an offer letter, so my guess is that opening it in the browser came up with an error like "to be able to digitally sign this offer letter, please open it in a desktop PDF reader with full scripting support enabled :)"
[0] https://helpx.adobe.com/reader/using/protected-mode-windows....
But you never know.