Just kind of what the NSA does really with the exception of monetizing on ransomware?
I'd presume that a decent security researcher's laptop would have much more valuable things on it, compared to Bob the Waiter's laptop.
Educated guess. Grain of salt, etc...
> North Korean threat actors used social media sites like X (formerly Twitter) to build rapport with their targets. In one case, they carried on a months-long conversation, attempting to collaborate with a security researcher on topics of mutual interest. After initial contact via X, they moved to an encrypted messaging app such as Signal, WhatsApp or Wire. Once a relationship was developed with a targeted researcher, the threat actors sent a malicious file that contained at least one 0-day in a popular software package.
In the past, actors would release something, watch it spread, and see what reports back. Sometimes detonation would be limited to certain IP ranges or institution types, but broad deployment would quickly put itself on the radar of security researchers and someone would sound the alarm.
I'm thinking this targeted approach works like doctor-shopping: you find the most paranoid people you can and see if you're able to exploit them. If you pull one over on them, then the unsuspecting won't stand a chance. If they do catch on, you run away, iterate on your approach, and try it against another researcher who doesn't know you're making the rounds doing this.
So anything to slow down the researchers are my guess. Keep the drain open, so to say. Just my two cents.
https://www.cbsnews.com/amp/news/cryptocurrency-hackers-stol...
The ultimate purpose of the malware embedded within the GetSymbol software is what is not known.
At one of the hosting companies I worked at -- for example -- I was able to download the root password of every linux host and the domain password for every windows host as a proof of concept for a project. Nobody told me to stop but as a courtesy I did end up telling the manager of the internal SOC that it was possible. He was pretty floored. Apparently they setup monitoring for single queries of passwords, but since my queries returned more than one result, it wasn't "caught".
So yeah. Lots of access.