> The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits.
At minimum the payload.
At minimum the payload.
2. Script kid acquires said code, makes slight modifications
3. Script kid deploys the malware
4. Cybersec person @ Google is promoted for uncovering major APT operation, big news story
How do you prove that this is sufficiently implausible?
- Attackers don't want to get identified, so they won't help
- Defenders, or their bosses, don't want to admit they got owned by a "skid"
- Researchers want to pad their resumes with Serious work, not random skid nonsense
- Media wants sensational stories