North Korean campaign targeting security researchers
blog.google
blog.google
If anyone from Github is reading this -- I strongly suggest adding a banner or modal dialogue to warn users about the backdoor in this tool, and any other software with a known backdoor (e.g. forks of the project)
The attackers used a 0-day but getsymbol is not one.
> The 0-day is in a popular software package.
(I have no idea what this is.)
> The GitHub repo apparently contains a backdoor ability to execute code from the attacker.
(This is what Google says and I think it’s the autoupdater.)
Is this different than what you feel?
"But the tool also has the ability to download and execute arbitrary code from an attacker-controlled domain."
Sounds like most software nowadays to be honest. The blog author does not really point out why this code would be more malicious than "normal" or how the code author is known to be Korean.
0: https://github.com/dbgsymbol/getsymbol/blob/cb4bdedc1a85c308...
if (updateDlg.DoModal() == IDOK) { … }
then doesn’t that mean it only runs that code if the user clicks “OK” on the update dialog?(Edit: I think I understand now. It’s not the code, it’s the update URL that’s the problem, because it’s controlled by NK. So if you run this and blindly click “OK”, then it will download an executable that will infect your PC.)
(Edit 2: Or the issue is not in the source at all, but is in the prebuilt binary.)
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Or a story from today:
https://news.ycombinator.com/item?id=37425007
So perhaps the similarity between iMessage and GutHub actions is there are a lot of things that could go wrong. In iMessage it’s a pile of memory unsafe code that was not originally designed to withstand attack. In GutHub actions there is a lot of trust in their parties that could potentially be exploited.
https://source.android.com/docs/security/bulletin/2023-09-01
For certain parts of integration and testing jobs that are operating on untrusted code, it'd therefore be desired to not allow incoming PRs to change certain parts of the CI configuration (not only including .github/workflows, which can be protected using branch protection rules, but the testing framework).
It's possible to achieve this by splitting up your workflows and using workflow_run but it's non-obvious and finicky enough that I very rarely see it done.
GitHub could make this easier and propose better patterns than they do in their attempt to address the problem[0], which I think could use a 2023 follow-up.
[0]: https://securitylab.github.com/research/github-actions-preve...
---
In this context, an iMessage message <> a GitHub PR, I guess.
https://arstechnica.com/gadgets/2023/09/apple-patches-clickl...
iMessage itself is a dumpster fire that time and again has been proven to be an attack vector.
It would be very easy to add a backdoor to one of those build steps.
The comparison with iMessage is that it’s unsafe by design, at the architecture level, because you’re relying on live code made by anonymous people. One day, attack vectors will be found every second day.
I almost laughed when GitHub suggested me an Action for Makefile based projects. The entire build process in my case consists of "make package"...
No it isn't.
It's become normalized but it isn't fine. Whoever thought it was a good idea to download massive amounts of unaudited code at build time to then run it behind your defensive lines should have thought about that a bit longer. CI/CD is great. GitHub/GitLab are great. But combining the two has substantial risks. More so for languages that have broken package management and namespace issues.
If you trust Google or Apple with your phone then I'm fine with that, it's your phone, your life. But I've found that trusting companies to have their incentives aligned with your own or with what's good for the world in general is a structural mistake that will find you disappointed each and every time given a long enough engagement. You can't trust that which you don't own and can't verify.
- IntelliJ plugins,
- Maven,
- NPM,
- GitHub Actions.
Jetbrains says it carefully reviews the source code of all versions of all plugins, and Maven has a somewhat decent dependency tree that you can restrict to major actors (Spring-Apache-Google).
Maybe the key to trust would be to have larger pieces of code (such as Spring) with quite a lot of process to check-in code, rather than a thousand NPM packages. The parcellization of OSS didn’t do good for trust.
At best they can be used for coin mining (running up a huge bill), at worst for stealing private customer data (and then selling/ransomwaring it).
There is some irony in there.
I just had a look at it like 30 minutes ago and it was still there then.
Here are archives of what it looked like
http://web.archive.org/web/20230907185609/https://github.com...
http://web.archive.org/web/20230907193333/https://github.com...
http://web.archive.org/web/20230907193402/https://github.com...
It's much more likely that the binary releases and/or autoupdate binaries are backdoored. If someone compiles their own version, and then clicks to accept the autoupdate, they could be infected. The binary is 15+MB in size, which is far more than enough to hide a small backdoor.
https://github.com/dbgsymbol/getsymbol/blob/cb4bdedc1a85c308...
https://github.com/bb33bb/getsymbol
https://github.com/clayne/win-getsymbol
here is the same link as in the comment above from one of the forks:
https://github.com/bb33bb/getsymbol/blob/main/GetSymbol/CMai...
the code fetches from `UPDATE_CHECK_URL`, which is hardcoded as:
which as of the time of this posting, returns:
"GetSymbol 2.0.3|https://dbgsymbol.com/downloads/2.0.3/GetSymbol.exe"
the GetSymbol.exe file (which is downloadable right now) being presumably the infected file being discussed..!
you can still see cached bits of the code via github search -> https://github.com/search?q=path%3AGetSymbol%2FCMainDlg.cpp+...
and a tiny bit of the repo's main page in google's cache: http://webcache.googleusercontent.com/search?q=cache%3Ahttps...
and the user's github profile, again from google's cache: https://webcache.googleusercontent.com/search?q=cache:JXXyoV...
the dbgsymbol.com links above still work, obviously.
...which while admirable from one perspective, also effectively destroys the evidence.
I prefer the warning instead.
Analysis of which accounts starred it prior to publicity is probably a worthwhile endeavor. If there's any commonality with other obscure projects, that may be an indicator those accounts could be puppets.
I hope an analysis like you proposed could yield some insights to patterns or maybe even enough data to do some machine learning on.
I'd also strongly suggest they add a way to flag projects in a way that is appropriate.
I would just assume that non-gh or official hosted downloads (where reproducible/attested builds are available) are just state actors by default. Am I paranoid? How do Linux/Mac package managers solve this?
You trust Github to have reasonably good security, and to not maliciously meddle with user content, so that if you see a repository under github.com/neovim, and you additionally trust the user called neovim, then you can reasonably trust that any repositories under github.com/neovim don't contain malware.
By building their binaries from source and hosting them on their servers?
Which is one of the reasons why a lot of people promote that openness.
If you want to use that suspicious tool, you should at least take a glance at the source code.
You're right, (not just) online AV multiscanners are also FUD machines that will happily accept malicious programs but reject anything well crafted and optimized because it doesn't like exactly like the shit MSVC craps out with default settings.
> Wouldn't help if the source code already has the backdoor in there though
I'm not sure if you're aware but random tools don't just spawn in official package repositories overnight.
There's a vetting process, for both new packages and new maintainers. Also in established distros, packages don't get accepted to official repositories unless it's a critical and highly demanded one.
So yeah, any software can have vulnerabilities, regardless of OS. But stray tools and dubious actors, are pretty much a solved problem in linux distros. The situation on Windows is laughable in comparsion. No need to spread FUD.
Pretty much, packaging is not a brainless process. One of the effort that specifically target this is the Reproducible builds project [0], along with many other security measures set by each distro.
There are also usually multiple testing and updates rolling stages.
The best evidence of how effective these measures is its actual reputation and record on the ground.
You also have the option of building from source yourself. Some package managers and distros (Gentoo, NixOS, Guix) do this for you.
This is BTW the main reason I wouldn't use derivate distros for anything serious.
Debian's generally trusted in the community - their slow pace come from risk-aversiveness.
The question asked by parent comment was:
"How do Linux/Mac package managers solve this?"
The concern is that FFmpeg does not provide Windows binaries for themselves, they link to someone else who does.
You could argue that those providers are fine since they're implicitly being endorsed by FFmpeg, but it's not super clear whether they're trustworthy people involved in FFmpeg or randos that opened a GitHub issue saying "Hey I'm providing Windows binaries for people if they want them!"
https://www.trendmicro.com/vinfo/fr/security/news/cybercrime....
The same thing happens with mpv: https://mpv.io/installation/
The Windows download is provided by "shinchiro" on SourceForge.
The MacOS download is provided by "stolendata", on stolendata.net
As a security researcher it also presents an interesting situation. If you're careful enough and can pretend to be dumb enough, you might be able to harvest fresh attack vectors/0day etc. "for free" but the downside is if you overestimate yourself you'll get pwned.
Or just be after the accesses the targets have...
There are different mindsets in this game. You want one type of person to find the holes in your system, and a different type of person to protect it.
Also known as "automatic updates". Thank you, Big Tech, for indoctrinating the mainstream population into accepting this subservience (or forcing this non-choice on them) --- and now that that subservient and trusting attitude includes security researchers too, it's ironic to see it coming back to bite you.
Some of us knew all along what that attitude was going to lead to, and probably not all of us are security researchers either --- we've just seen all the other negative effects of letting you push stuff to our machines and run it, and put two and two together.
> Impact: Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
https://support.apple.com/en-us/HT213906
Not a betting man, but I'd guess that's the vulnerability being discussed.
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zer...
How have they not accidentally stumbled across media that shows them all the things their state media doesn't?
The simplest explanation here is also the most cruel:
https://news.ycombinator.com/item?id=37425542
- They can't get to X freer country as that's just difficult for all North Koreans
- They likely can't just stop hacking for carrot and/or stick reasons. They are likely closely monitored.
- Maybe some people drink the kool-aid. I'm sure these people are very well compensated.
Imagine getting a week of solitary confinement for trying to read a Korea Times article.
They're closely monitored where they work and often have threats against their family.
They probably are aware. There are other means of keeping them in line, both carrot (privileges within DPRK) and stick (consequences for them and their loved ones if they step out of line.)
The reality is that like every other country's intelligence services, they would obviously recruit for patriotism. This question is like asking why US intelligence agents who have access to information about the DPRK beyond the propaganda don't defect to the DPRK's superior healthcare coverage, zero school shootings, and better litter management. They don't value those aspects of DPRK society which seem better, and probably don't necessarily trust that they actually are better in X specific circumstance (pretty valid!). I don't see why it would be any different for DPRK intelligence.
The USA is also great if you earn 200k/y as a software developer.
If you're a teacher, not so much.
I can't believe you're glorifying the DPRK without mentioning that they celebrate Tax Abolition Day since eliminating it in 1974.
https://www.cnn.com/2023/03/03/asia/north-korea-hunger-famin...
If this were the case then it would not be necessary for them to shoot people trying to leave.
People in the late USSR were in a similar situation. Even without necessarily knowing all the details, the average person, and certainly the intelligentsia and people working in the intelligence services, had a growing awareness of the absurdity of it all, how different the rest of the non-Communist world was, and so on. Something similar is true in China, today. A person in China who wishes to inform themselves about China's history or recent offences against human rights, can at this point, do so, and fairly easily.
But... then what? Can't talk about it. With whom would it be safe? Can't tell others what you've learned. Can't discuss your perspective.
In my view it was not the truth that destroyed e.g. the USSR. It was allowing people to organize independently of state control. That, plus truth, was fatal. Both the Chinese and North Korean ruling parties have learned that lesson. It doesn't actually matter if a significant proportion of the public knows the truth. They can know the truth, alone, in isolation, unable to act on it.
All authoritarian states will end up having a caste sysem hierarchy. The upper caste have it just as good a people in the West and in modern times they will have unfiltered access to the Internet. They have zero reason to revolt because they have everything then need.
how much of what we think we know about our own governments is verifiably true?
If anything, I'm sure it gave researchers a chance to play around with the binary in a secure environment. They wouldn't even need to reverse engineer it, since the source code was made public by the attackers. Good guy black hats!
Speaking of, can someone find the exploit in the linked repository? I'm curious what it does, but can't bother with going through all files. TFA could've linked to it, as well as mention how they determined this project is linked to NK hackers...
i.e. not executables
If they have enough confidence to attribute and not disclose how/why, one can fairly guess they don't want to burn sources or indicators which might still be useful moving forward but likely won't be if disclosed...
Young infosec practitioners are encouraged to get certifications, OSCP, eJPT, etc. A lot of these cert mills require that you pwn known boxes. This gives rise to discord servers where you can "help eachother". Some of this help is in the form of binaries or obfuscated source code.
They run it on their pentest job laptop, you know, the one with the SSH keys to their report writing box. They get pwnd, and now DPRK has access to a bunch of US civilian corporate data and weaknesses.
I may have actually witnessed this.
If the security researcher's environment isn't well designed (which absolutely happens, whether it's via budget or inattentiveness,) then the attacker can get to a delicious creamy filling very fast.
Look at this article for example. The first two words are the attributed actor. Yet there is absolutely no way to prove it. Attribution on the Internet is really, really, really difficult. We don't know how difficult it is because we have no independent method to determine when we're right or wrong. And we would be foolish to think that attribution is never politically motivated.
Based on this, I generally assume that their attribution is accurate. However, if you take a step back and view it objectively, it appears quite hypocritical, given the privacy-invasive origins of this intelligence.
dbgsymbol.com is NOT showing up with warning in Safe Browsing on my Brave browser. (warning, unknown vector)
1 - The first 4 bytes of all url hashes in the blocklist are cached in the browser.
2 - When there is a match, you request of Google the actual urls on the blocklist.
3 - Client side your browser blocks loading the url.
Google only knows that the site had a hash collision with the first 4 bytes of something in the blocklist.
I, personally, think that's a fair price for otherwise free malware protection. It's also built into Firefox and on by default. [2]
[1] https://developers.google.com/safe-browsing/v4#update-api-v4
Does anyone have any links for that, or do we just autoaccept that FBI/CIA/GCHQ/Mossad do it and it's fine, because they are in our group?
[0] https://www.bbc.co.uk/programmes/w13xtvg9/episodes/downloads
[1] https://blog.cyberproof.com/blog/which-countries-are-most-da...
[2] https://blog.cloudflare.com/ddos-attack-trends-for-2021-q4/
"Look, see? NK. We even copied some Korean words into the comments."
People shouldn’t underestimate their technical capacities or ability to recruit smart hard working people.
People hear about third-world living conditions and deprivation and say "aww, cute" as though it's sticks and rocks they're launching into the sea of Japan. They have money...it's all poured into the military.
I don't understand why the media downplays them so heavily.
And I don't understand why the media upplays them so heavily, as some kind of peer threat capable of meaningful force projection.
(Well, I do understand it, someone needs to keep pounding the drum to keep this country on a forever-war footing.)
When someone gets mugged on your street, you can consider taking precautions. If your response is to roll out half a mile of barbed wire, electric fencing, and landmines all through the perimeter of your property, I would say that is absolutely 'upplaying' the actual level of threat.
Most Americans' understanding of the actual threat posed to the US by NK is ludicrously upplayed. NK is a credible offensive threat to SK, but that's a very limited problem for anyone living in Nashville, Tennessee.
Perhaps TN is just a radically different world, I'd frankly believe it, but I haven't seen anything too significant at all. The last time people were really concerned about NK for like... 3 days, I think it was ~2012 or so.
I wasn't criticizing the blog post, I was responding to a comment in this thread that claimed that for some strange reason the danger of NK is systemically underplayed by the media.
I argue that no, the media more typically overplays it, much like it overplays the threat from other non-peer nations. I'm assuming you don't feel like the news is telling you that Iran is a threat either... Which would put you in an informed minority.
Because in the same way as morale can be a force multiplier, an extreme lack of it can be a force divider. Combine that with their (very likely) inability to sustain even a regional war for more than a few weeks, their antiquated equipment, and their largely unsuccessful domestic military developments, and it's not hard to write them off as largely a non-threat, whether or not this is truly the case.
The major downside is that even if they only manage to sustain for a few weeks, that's plenty of time to level Seoul and inflict damage on cities further south should they decide to make a push against the ROK, and this is what shouldn't be downplayed.
Also, during a kinetic conflict where you're invading, it's often more strategically valuable to lie dormant in their networks than it is to scorch them, a la America sitting inside of Iraq's phone networks and just listening.
There's a lot of work being done now to change it [1], but I've heard from multiple cybersecurity grunts in critical infrastructure that they just assume foreign APTs are in their networks. Strategically, why in the world wouldn't they be? There's basically no downside other than burning TTPs. We should damn well expect the NSA to have their fingers in every foreign pot they can reach.
[1] To be fair, there was a lot of work before too. But now people are more scared.
I also don’t think it matters because they would be pretty dumb to use them. I’m of the mindset that they will most likely simply collapse at some point and the nukes will become unmaintained and useless.
> third-world living conditions [...]
I know that the phrase has gained an orthogonal meaning since the cold war, but if we use the original one it's funny to call what's arguably the only remaining second-world country "third-world".There are a few reasons that interlock.
- The DPRK government is a mob family with sovereign status and nukes. Most folks in western countries don't have a strong sense of what that means - looking through the lens of mostly free nations, it is hard to imagine the realities on the ground, and they fill in the blanks with what they know about bureaucratic states.
- Lots of western folks, but USians in particular, are extremely ignorant and incurious about Asia and asian cultures. This amplifies the above problems and tends to lead to ridiculous ideas being believable.
- DPRK's propaganda encourages some of this. Their interests are served when people in the west are thinking about their nukes and ignoring the hacking that pays for them. A side order of "we're so mean and crazy we starve our people" helps stoke the mad-man authoritarian archetype.
Perhaps you meant the media for some specific country, but news media in Japan do seem to take North Korea quite seriously, and missile launches frequently ends up being the first headline on NHK world news.
And much more of it after crypto gained popularity. Darknet Diaries went through investigating some of their hacks. Amounts from one can be more than entire GDP of a small country. Some crypto is washed through Macanese etc banks but most is just used to pay for weapons and stuff directly.
including non-nationals?
Of course, there are different senses of "recruitment". The best recruits don't know they even have been..
The take-away here is that it's 99% social engineering and 1% a script-kiddy payload drop. Their SE play is based on our innate ability to be recruited, because we want to be. Because we spend our school and college days being conditioned to want to be valued, to feel needed, to look for validation and reward, to make beneficial connections and sell ourselves. Self commodification/reification is the beating heart of capitalism.
They're smart to use that against us, by reaching out to security researchers, who (from personal experience) often feel isolated and/or undervalued.
After all it's just "international collaboration" , right?
Without due diligence in checking out new contacts (especially if they contact you to discuss things that they know interest you and then stroke the ego of your specialism) recruitment is easy.
In the end you can't easily know whether that charismatic voice on the phone is really from your government, from Google, from a fellow researcher who wants to "share and collaborate"... and you probably wouldn't know what would constitute a credible proof of identity.
Intelligence agencies could do well to spend a little money on benevolently watching out for commercial, civic, academic or hobbyist researchers who are valuable targets and sending a polite heads-up when the packets start arriving from N Korea.
Unsuprisingly, TAG is light on details..
At minimum the payload.
2. Script kid acquires said code, makes slight modifications
3. Script kid deploys the malware
4. Cybersec person @ Google is promoted for uncovering major APT operation, big news story
How do you prove that this is sufficiently implausible?
- Attackers don't want to get identified, so they won't help
- Defenders, or their bosses, don't want to admit they got owned by a "skid"
- Researchers want to pad their resumes with Serious work, not random skid nonsense
- Media wants sensational stories
This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles.
This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.
Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal.
WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chinese, Iranian, etc.
It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution.
I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to (I guess that's how the OP got to see those NK-related IP blocks) Western government agencies that handle this sort of stuff.
1) Derail the conversation 2) Find out ways to further cloak their footprint
IMO if you've worked in the field, you know it's a dumb question meant to invoke something.
"Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!"
Sadly, I am a nobody who happened to see DPRK not tunnel to a VPN.
Really? What does it take to sprinkle North Korea over my code? Is having the North Korean equivalent of JIS in strings enough? I mean, how could there possibly there be any footprint of anything. Does gcc leak info into the binary that my Debian system does not have in the first place? You need to get these guys when they are bragging to their friends. You can't look on the trails they leave behind ...
A lot of cyber security smells like bullet forensics.
Back to the subject at hand, and taking a more general view, trusting a big Pentagon-contractor [1] (and not only) such as Alphabet on the subject of other countries' cyber-attacks against the US (and its Western allies) is just futile.
[1] https://www.reuters.com/technology/pentagon-awards-9-bln-clo...
It's particularly ironic because in this case social media was used to gain access to the researcher's computer:
In one case, they carried on a months-long conversation [on X], attempting to collaborate with a security researcher on topics of mutual interest
HN is another perfect place for that to happen. How do we know that pphysch (or me jryle70) isn't a NK's agent trying to get more information about the technique employed in this case?
So anything to slow down the researchers are my guess. Keep the drain open, so to say. Just my two cents.
https://www.cbsnews.com/amp/news/cryptocurrency-hackers-stol...
> North Korean threat actors used social media sites like X (formerly Twitter) to build rapport with their targets. In one case, they carried on a months-long conversation, attempting to collaborate with a security researcher on topics of mutual interest. After initial contact via X, they moved to an encrypted messaging app such as Signal, WhatsApp or Wire. Once a relationship was developed with a targeted researcher, the threat actors sent a malicious file that contained at least one 0-day in a popular software package.
In the past, actors would release something, watch it spread, and see what reports back. Sometimes detonation would be limited to certain IP ranges or institution types, but broad deployment would quickly put itself on the radar of security researchers and someone would sound the alarm.
I'm thinking this targeted approach works like doctor-shopping: you find the most paranoid people you can and see if you're able to exploit them. If you pull one over on them, then the unsuspecting won't stand a chance. If they do catch on, you run away, iterate on your approach, and try it against another researcher who doesn't know you're making the rounds doing this.
I'd presume that a decent security researcher's laptop would have much more valuable things on it, compared to Bob the Waiter's laptop.
Educated guess. Grain of salt, etc...
Just kind of what the NSA does really with the exception of monetizing on ransomware?
At one of the hosting companies I worked at -- for example -- I was able to download the root password of every linux host and the domain password for every windows host as a proof of concept for a project. Nobody told me to stop but as a courtesy I did end up telling the manager of the internal SOC that it was possible. He was pretty floored. Apparently they setup monitoring for single queries of passwords, but since my queries returned more than one result, it wasn't "caught".
So yeah. Lots of access.
The ultimate purpose of the malware embedded within the GetSymbol software is what is not known.
> 23.106.215[.]105
I always imagined the North Koreans to be at a technical level where they would be the ones consuming published exploits more so than imagining their own. This article means that they are advanced enough to focus on suppressing knowledge rather than consuming what is publicly available.
My understanding is that they even have access to an unfiltered Internet supplied by China. The threat of extermination of their families if they step out of line politically seems to keep those people in check.
1 - https://www.reuters.com/technology/record-breaking-2022-nort...
I never heard of anyone stoling crypto, so you might be right. /s
Gave a lot of insight and background into North Korean hackers, how they operate, how they live and so on. I was familiar with their operations from before, like the SWIFT hack from being in the infosec field. But I still learned a lot.