At minimum the payload.
2. Script kid acquires said code, makes slight modifications
3. Script kid deploys the malware
4. Cybersec person @ Google is promoted for uncovering major APT operation, big news story
How do you prove that this is sufficiently implausible?
- Attackers don't want to get identified, so they won't help
- Defenders, or their bosses, don't want to admit they got owned by a "skid"
- Researchers want to pad their resumes with Serious work, not random skid nonsense
- Media wants sensational stories
This is clearly comment bait. If you've done any type of opsec before you know the legal hurdles.
This is coming from someone (me) who personally saw North Korean IP blocks visit malware research articles via combing the server IP logs and verifying the block.
Virtually everything on the wire can be spoofed. Someone in Kansas could own an elaborate network that includes DPRK IPs. And that would be a desirable red herring for any independent criminal.
WikiLeaks taught us that the CIA has tools for spoofing their payloads as Russian, Chinese, Iranian, etc.
It very well could be a DPRK actor, but let's please not kill perfectly valid discussion around attribution.
I'm starting to believe that "killing perfectly valid discussion around attribution" is part of the game itself, after all we have at least two persons in this HN comments thread (the OP, and some other guy above who explicitly said that he worked for intelligence) who have worked directly for or adjacent to (I guess that's how the OP got to see those NK-related IP blocks) Western government agencies that handle this sort of stuff.
1) Derail the conversation 2) Find out ways to further cloak their footprint
IMO if you've worked in the field, you know it's a dumb question meant to invoke something.
"Look! We've succeeded! We've dragged out 'w0z_' and have identified him as a possible (x)!"
Sadly, I am a nobody who happened to see DPRK not tunnel to a VPN.
Really? What does it take to sprinkle North Korea over my code? Is having the North Korean equivalent of JIS in strings enough? I mean, how could there possibly there be any footprint of anything. Does gcc leak info into the binary that my Debian system does not have in the first place? You need to get these guys when they are bragging to their friends. You can't look on the trails they leave behind ...
A lot of cyber security smells like bullet forensics.
Back to the subject at hand, and taking a more general view, trusting a big Pentagon-contractor [1] (and not only) such as Alphabet on the subject of other countries' cyber-attacks against the US (and its Western allies) is just futile.
[1] https://www.reuters.com/technology/pentagon-awards-9-bln-clo...
It's particularly ironic because in this case social media was used to gain access to the researcher's computer:
In one case, they carried on a months-long conversation [on X], attempting to collaborate with a security researcher on topics of mutual interest
HN is another perfect place for that to happen. How do we know that pphysch (or me jryle70) isn't a NK's agent trying to get more information about the technique employed in this case?