Fake recruiter lured aerospace employee with trojanized coding challenge
welivesecurity.com
welivesecurity.com
That’s damn clever.
I program Apple software, and Xcode projects can dig deep. Apple gives you a warning about opening a downloaded project, but you’re almost certain to ignore that, if you think it’s a take-home.
I assume that taking online ones would ask for hairy access, as well.
Also, the people going for these would probably have pretty damn good access to the corporate Crown Jewels.
Of course, no one would use corporate resources for job-hunting, right? I know that folks here, get all huffy, when I suggest that happens rather frequently.
I’ve maintained a strict “don’t do anything personal on a corporate computer” policy for a long time, but I’ve not found that to be a common approach.
There was a story a few years back making the rounds on HN where an Apple employee had to turn in her corporate device due to some lawsuit against the company. This happens all the time in big companies. She was outraged at this because she had personal nudes on her corporate device. WTF how could anyone think this was a good idea?
https://www.theverge.com/22648265/apple-employee-privacy-icl...
When I worked at Apple I needed a personal iCloud account to set up my corp MacBook. I simply created a new dummy personal account just for that. Nobody's auditing your iCloud account to make sure it's your "real" personal account or anything.
I don't use a personal icloud account on my work computer... it's not even allowed lol.
Just as I was leaving they were in the process of replacing everyone's computer with new ones that were much more locked down.
Meta requires you to link your personal meta account with your work identity.
To take nudes?
Smarter decision is for the corp to just buy your device for you. Then it's a personal device, and at least in some cases I'm aware of, not a government record at least.
Very doable for a phone where your "work" is limited to messages, webmail and calls.
Being greeted with a Department of Defense splash screen before login reminding me that everything I did on that computer was subject to monitoring formed that habit early, and I still can’t shake it, no matter how long I work in Germany, for a German firm with a rather assertive works council.
Where I work we have a take home exercise we have candidates do and then when we have the interview with that person we review their code with them and ask them to make incremental changes to see how they handle the asks with their communication skills and their technical ability. I interviewed one individual who couldn’t even get the REPL started for their project and as they were struggling trying to get it to work I heard them mumble to themself “I should have just use my work computer”. The fact they couldn’t get the most basic aspect of the project to work on their personal meant that they did their coding assignment on their work computerMe, I don't recall using company hardware for anything even remotely personal in many years. It's stupid because they are loaded with all kinds of spyware.
Some people only know how to code within the environment managed by their corporation. This is increasingly the case with folks that have only worked at Kubernetes shops.
Some particular quirk of autocompletion could become almost pure muscle memory, and if it's suddenly missing, you notice.
However, it seems that it does not cover all of my needs: https://github.com/twpayne/chezmoi/discussions/1510#discussi...
Maybe I should use Ansible for system-wide configuration and chezmoi for dotfiles in $HOME.
I am skeptical that nix or home manager would solve these problems. So I just have a specific setup at work, that is typically more advanced and automated than my home system. My leet code interviews suffer because of this. Just makes me realize that coding interviews using an environment that does not mimic the workplace is just excluding senior developers (read: old people) who don’t have the time or patience to jump through these hoops for 15minutes of placating a recently hired college grad
They already have working software development environments. It's a process that can be time-consuming and is done once in a blue moon (basically when you need to reimage the machine). In the meantime, all changes to your software dev environment are gradual, and your work-provided computer ends up being configured like a software development pet instead of cattle.
Moreso if your company adopted/enforces internal development tools.
Ask yourself this: how many times have you went through a complete OS reinstall and subsequently had to setup a working software dev environment? Is this something you have automated? Most people do not.
I guess this is because in college and my first few dev jobs used Macs. A nice side effect is my wife hasn’t had any tech support complaints since we switched, it has been great.
I’d still never use company hardware for personal stuff. I don’t even login to Spotify on the company laptop.
She doesn’t seem to have issues with macOS at all though, aside from the one time I had her using a VPN and it expired which is totally on me and disabling it was nonobvious.
When you get a personal computer you do not need to set up all the things you need to do your work immediately, so you will do the setup of things as you need them.
thus if you get a new personal computer it might not be fully setup yet.
If you are of the age that you have kids you may not have time to do any sorts of personal projects, if so and you have an old personal computer it may not be up to date with what is needed for the coding project because you have not been doing a lot of stuff.
If you have kids or other problems your personal computer may end up broken or unusable and you might not have the money at the moment or the reason to buy a new one.
I expect there is a similar, but worse, problem growing with CoPilot and friends.
I've been a candidate who "couldn't even get the most basic aspect of the project to work".
I had been working for years at a company that most developers in the world would sacrifice their firstborn to have a shot at being hired, and I've been using their work laptop for years on end. I considered switching gigs, I answered a recruiter's call, and I found myself in a technical interview using one of my own laptops. Only during the interview did it dawned upon me that my personal laptop had no development tools installed. Why? Because I never used it for work. Worse, I was used to my employer's automated process to setup software development environments, so I had no assurance that I could setup a fully working dev environments in 5 or 10 minutes, let alone the meeting's full hour. If you want to run Python as a REPL on Windows, good luck.
Thankfully my meeting ended up using a webapp to do the pair programming/coding challenge, but if I had to run code on my personal computer I would have to spend far more time setting it up than testing stuff, reschedule the meeting, or simply bail out.
Some companies allocate more than a day to get new candidates to set up a working dev environment and building a project, while assigning an experienced dev to guide them. I know that because I've onboarded half a dozen people and that's what it usually takes.
I'm reading your comment and I'm surprised you didn't noticed how your account does more to document how oblivious you and your team were to critical failures in your hiring process than in assessing the competence of a candidate. How many times per day do you need to setup a software dev environment? Is this how your company gets paid? Is that where you needed additional people to work on? No? Then why on earth are you evaluating them in a completely irrelevant domain? Don't you have people in your team who can spare some minutes documenting and automating that process?
By the way, following that interciew I was extended an offer for a senior position. If the recruiter was like you and I would have been evaluated on my ability to setup a working software dev environment in the allotted time, I'm sure I would have spent over half the meeting googling for where to download the interpreter and how to set it up.
From my experience, onboarding at companies is a painful process due to internal software, specific setups for complex build processes and (frequently) permissions / annoying processes required for downloading and installing things. Those points are not applicable if you are using publicly available and well documented tools on your own machine.
That takes place only after you search for the python installer, download it, install it, check the environment flags, and restart your terminal of choice.
The web is jam-packed with examples of how problematic it is to setup and deploy Python on Windows, and we're not even touching the problem of how some fundamental packages, such as anything involving the file system, is either riddled with platform-specific gotchas or does not work at all.
Setting up a REPL is a far more involved process than it's being casually described in this thread.
It’s surprising how often this is ignored.
First, this is a coding challenge that the candidate is given before the technical interview that is well defined in the expectations and is small in scope. They are not expected to spend more than an hour or two on it and they send the recruiter (who is an internal recruiter) a link to their github repo with their completed project before the technical interview is even scheduled. Candidates would have several days and potentially even a week between when they finished the project and when we have the technical interview. The candidates are also told that their project will be gone over in the technical part of the interview. I understand that there are circumstances that would prevent the individual from getting an environment set up on a personal computer but if that is case then just stick with using the work computer.
Second, I never even indicated if the individual was hired or not but you made the assumption that we passed on the candidate. The fact that the candidate couldn't get the repl started was just a tidbit that stuck out to me and I made the comment to my coworker as it is odd to me that a candidate would use their work computer for a job search. We just went with the fact we couldn't use a repl and had the candidate just talk out loud with what he would change when we added different scenarios/requirements.
For what it's worth, the candidate was using a Mac for their personal laptop and so all they would have had to do is run the following in their terminal and it would have gotten them pretty close to being able to run the repl
brew install clojure/tools/clojure
Morally grey(pale blue?) aside, I've been given entire days at work to look for new jobs as part of a redundancy agreement, it was widely supported by management.
The solution might be to do real work in VMs while the laptop is a dumb terminal then lock it the fuck down (no downloads!)
There are so many potential consequences. An eager beaver manager once talked a future employer out of employing me through a personal connection, and that was just because they found out. Even if it was unethical or illegal, these things happen, and even in large tech companies. Imagine willingly sharing all details of your job hunts with your employer… maybe it’s just me, but the thought feels wrong.
Work and personal matters should be church and state, right?
Maybe people like the rush…
The most I mix it is using my smaller, lighter, Bluetooth-supporting work laptop for watching innocuous YouTube videos while doing dishes. And I used to use it to print stuff at the office, on occasion.
Not necessarily. On the one level, you don't know their salaries (as they might have negotiated badly or simply be underpaid), and then additionally they might pay a lot for housing, child support, debt, medicine, or other invisible expenses. Living in a place like San Francisco it can quickly add up.
My back can't afford it.
A MacBook Pro is already heavy enough that you can feel if it's in a large suitcase. 2 would be ridiculous.
I do have a separate partition for personal. Maybe I should upgrade that to an external drive, but that sounds inconvenient.
If Apple is listening, please make a carbon fiber MBP.
I completely agree with you, it has a high risk associated with it, and you really shouldn't do it, but i can see how it happens when people don't think things through or don't remain vigilant.
Give me an .exe and ask me to run it, and I'll open it in a hex editor for inspection instead. If what you claim is a "hello world" or Fibonacci generator is much bigger than I'd expect (a few KBs) and contains encrypted-looking data or other attempts at obfuscation, I'm not running it.
But what would be even more wicked, and effective would be pointing them to a GitHub repo with the “challenge” project to complete, and referencing a compromised package that does their bidding as the victim tests their solution.
Unless you're crafting some revolutionary problem for each candidate, changing details won't matter much.
I’m talking about a take home code challenge. It’s unreasonable to have someone to record a video that could last an hour or more. And I’m not gonna sit and watch that.
The stupid thing is that that it's remarkably easy to sandbox and application these days. Sandboxie is free, though not guaranteed to work (but it may very well have done, or at least would have made the strange behaviour obvious) and Windows Pro has had a right-click menu option to run an executable in a sandbox for a while.
When I read the title, I initially thought it was about infection through IDE ("do you trust the authors of this project" is there for a very good reason and in the case of VS Code attackers can get code execution before the prompt through Git config trickery).
I'd be wary of executing a program, but I bet I would click the "sure enable code execution" button if a recruiter sent me a coding challenge in the form of an incomplete project with a Git repo. Especially if they could set up a remote interview process where they want to go through code live "to see how I approach problems".
Right nowt he attack is super basic, but it's not hard to make the initial infection harder to detect in time.
I didn't have access to anything useful to spies, but some of the keywords might look to someone like I did. Like how some recruiters seem to spam all keyword search hits on LinkedIn.
I knew I'd have to report any kind of security incident, and I thought that might interrupt my contracts and income, while a cautious bureaucracy processes the incident. So, no resume online. Also, measures to try to prevent a random burglar from inadvertently stealing the work laptop.
(Now that I'm away from that work, I get to enjoy LinkedIn recruiter spams for Junior Python Leetcode Hazing Engineer roles, like everyone else.)
As a meatspace equivalent I’m sure there are not many CIA operatives walking around foreign countries and giving out CIA-stamped business cards.
Disclaimer: layman's opinion, I only know what internet knows.
It's definitely much slower than the private sector, but if the agencies decide they have a use case, they'll throw money at it until it works in house.
I have also asked the head of HR to make absolutely sure that my name is not on their public "our team" page. As a side effect, I always giggle during the mandatory corporate security training that tells how to deal with targeted attacks and demonstrates example phishing emails - so far, I received zero, if we don't count tests by a pentest agency.
When I was an intern in college and was much poorer, I also was guilty of the same…
Unless you watch free movies on YT or torrent stuff, of course
Grand assertion. Where's your supporting cite? To be clear before goalposts are moved, the context is external optical media drives---a peripheral commonly issued along side laptops without one---not USB mass storage devices.
Wait, _is_ it? In this future year of 2023? I haven’t seen this as common practice for at least a decade.
(The sort of higher-security-stance companies who disable USB drive support will also generally disable support for external optical drives, because why take the risk?)
Of course I aim to respect the security rules of my company. I trust my company. I wouldn’t enjoy working for a company that I wouldn’t trust with my browser cookies.
The laws are also on my side in my jurisdiction. I cannot be fired simply because I did something my company didn’t enjoy on the company laptop. They need a really good reason.
Getting fired is not the risk you are running, getting all your personal data exposed by any civil suit the company gets hit with is the risk.
Exposure is the risk, not firing.
Okay, lets talk about something more likely: your communications are not private - when you connect to an https URL you expect that your password is never in the clear.
With most organisations I have worked with/for, they almost always perform MitM on all TLS connections, and it works seamlessly (i.e. without you knowing) because their certificate is on the machine.
Only the very small and/or very poorly-run organisations aren't doing this, because unless they do the MitM, the network tools they use to detect malicious activity on their network cannot do Deep Packet Inspection (tools such as Darktrace).
It's exceedingly unlikely that the password you used to log into your bank account from your work computer is indecipherable to your network operators. It may as well be in the clear within the network.
One would think that being unable to access modern security research, open source projects, programming resources, or "wild" malware would not exactly raise a nation of brilliant hackers. Perhaps some who subvert the great firewall are vanned and offered a job in the unit?
how do you know they are unable to obtain such things?
also, how do you think hackers are trained? by teaching them how to create a ToDo app with the nightly build of React?
they probably know by heart the ethernet and TCP/IP stack better than the guys who created them and could recite it backwards, and that's already enough to hack plenty of things
I don't know, but I thought they started as "script kiddies" at about age 12 before growing into full size hackers.
Which requires that tech be available widely enough that 12 year old kids can get unsupervised access to it.
Have a listen to the Lazarus Heist podcast for more information.
There is also the fake-hire scam: where staff are lured away with lucrative compensation packages, data-mined by the competitor, and finally jettisoned before the evaluation period expires (typically 6 to 10 months).
A few infected PDFs from various bad actors are also floating around out there with exaggerated promises.
Keep safe, and note 86box supports read-only backing images and sessions Like Bochs/kvm:
https://github.com/86Box/86Box/releases
(works on Apple M1 laptops, but is slow)
elaborate?
So… Interviewer specifically asked me to bring my computer, after the initial intro they asked me to show some code I’d written. I said I’d just connect to my mobile hotspot. They looked shocked and said “I didn’t think you’d have a phone here” (it was an overseas fly out for the day), I said it’s fine, I always have a phone. And they insisted I instead connect to their office wifi.
It was the only wifi i used the whole time i was there.
Back in other country I saw my mail had another logged in session, and a private repo post install script had pulled a resource from my server, from an IP back in the country, and another random country.
Only way to access to private repo was SSH key (or GitHub credentials) Only way to access to Mail was MITM cloning session or access to device (more likely - I thought i would have noticed any MITM cert issues).
Incidentally, from the same country, this time another company, I had another fly out interview request a week later and this company also specifically asked me to bring my computer — when I asked if it would be ok if I wasn’t gonna bring my computer because I needed to get it fixed, they got back the next day and said oh, we have to cancel the interview because we it won’t be possible for us to proceed.
To proceed… with hacking?
Hahaha, who knows? I’m not expert enough to know what this all means. Maybe it’s nothing. It’s probably nothing.
I don't want to be responsible for misrepresenting a country, and I think it's prudent to keep the protection of privacy there until it's definitively proven with evidence.
That's my M.O.
I take it a bit further. I won't go into pissing matches. If folks wanna fight, I'm not the guy to do it.
My general stance is, if it's complimentary/good, I don't worry too much about getting specific. If not, I keep it vague (which sometimes pisses people off, but life is not fair).
I generally don't name my former employers, just to keep their name out of venues where someone else with a grudge could throw poo (see "Apple" -not a former employer of mine).
I’m not sure if it’s connected but in the general sphere of things, maybe one downside I’ve noticed in my life is i can be a bit slow to notice when someone or something isn’t good for me. Even if it’s obvious, to others, i always wanna see the good, sometimes i think I’m in denial willingly! Haha… So I have learned to become aware of such people and their behavior, pattern recognition.
It's a long story, but I have spent my entire adult life, dealing with some of the most dangerous, doesn't-play-well-with-others people on earth. I'm proud to call some of them friends, and have learned to politely avoid getting too entangled with the drama of others.
I've learned that I'm responsible for enforcing my own boundaries, and that I don't need to use nukes. Often a simple "No, I'm not going to do that, but I will do this..." is sufficient.
> How do you think they were able to access your private SSH key by simply having your laptop join their wifi?
I don't know. I assume it's possible, I thought you could get hacked over open wifi? Anyway, but how would it be done do you think?
If it's only MITM then perhaps SSH keys were not compromised. But I didn't take that chance. I just changed everything.
That's what I'm trying to figure. Open wifi or not, your private ssh key shouldn't leave your pc when you're using it. Ditto for whatever sites you visit over HTTPS, the whole point of TLS is to avoid MITMing connections and extracting their contents.
There's things like cellular modem exploits that bypass all the higher layers of the stack and get access to your cell phone at the base layer. I'm guessing similar stuff exists for wifi. Heck it could have even been a power cable I maybe mistakenly plugged in trusting it! I'm not an expert on any of this tho.
With the MITM I think you're right, I would have expected to see some cert issues. But I know I have seen GitHub MITM'ing before with a state issued MITM certificate (won't say where right now), tho I did notice that because there were connection issues and then I paid attention to the address bar.
It could have been that there were cert issues, I just wasn't paying attention to them, as it was an interview. That sounds plausible.
I guess the issue is there's all kinds of exploits and zero days that most regular people don't really know. Of course they could have combined it with a PDF exploit from something they emailed me. I don't know!
Did you find anything on this in the meantime, on theories on the different ways it could be possible? How would you rate your cybersecurity redteam/blueteam knowledge in this domain on a scale of 1 to 10 (10 being best)?
Although you're certificate point did give me pause. Don't you have the private ssh key stored somewhere accessible from github? Like some kind of action or whatnot.
Also, is that key not password-protected? Did you ignore some SSH connection warnings and forwarded your agent?
I don't work in cybersecurity, so let's just say that my readteam knowledge is 1. I just try to understand how things work and protect my stuff as best I can. I'm just very surprised since your situation seems, on the surface at least, to fly in the face of what is commonly expected.
Yep, two different companies flying you out just to hack your shit. It's probably nothing. It makes me curious what you work with. Do you maintain commonly used open source software?
This was at the point in time where I was developing BrowserBox and doing demos but had not released the code publicly.
On the other hand if they invited GP to their HQ, they'd have a lot to lose unless the companies were entirely fake.
And that your mail client saw a new IP and treated it as a new session? I think assuming you were hacked based on this is paranoid.
> To proceed… with hacking?
Or maybe, they didn't have a laptop for you to use (which is stupid, don't get me wrong) so they couldn't do the next stage unless you had a device. Given you had to use it for the first step, it doesn't seem unlikely.
If they wanted to "hack" you, they didn't need to fly you out, they just needed you to clone the repo and run the script.
Let me try again: then didn't ask me to clone any repos of theirs. They only asked me to show them my private repo on GitHub so they could see some significant work I had done. I just picked some random nothing file and they were satisfied. Then I saw that this private repo had been cloned after that trip. Normally you can't see clone IPs on GitHub but for my install process the npm "postinstall" script pulled something off my web server. Basically I had a line buried in one of the scripts referenced in the postinstall script:
wget --header="Authorization: Bearer $MY_ACCESS_TOKEN" https://api.myserver.com/data
The only thing that ever pulled off that URL was that private repo postinstall script. After seeing my mail session at a random IP in that country, I thought oh that's probably me, but then I was already back home and I wondered why there was still a session there, so I then checked the logs of my server saw another IP from that country pulling that URL, from the day after I was there, when I hadn't made any servers there or run that script when there.What you say about the laptop was what I originally thought: Why do they want me to bring a laptop? Do they seriously believe I don't have a computer? Hahaha
> If they wanted to "hack" you, they didn't need to fly you out, they just needed you to clone the repo and run the script.
I agree it sounds implausible, right? It's probs nothing. Likely I'm just misreading it.
I don't want to jump the gun and I think it's prudent to keep an open mind, I certainly don't want to spread a bs rumour, nor misrepresent a country with something had not been definitively proven with facts. That would totally lack integrity, be irresponsible, and would be undermining due process and ethics. It would also just be disgusting awful betrayal of everything good, so I don't want to jump the gun or name and shame.
I was invited and travelled to many countries for these types of interviews back in the day, all over the world: Europe, USA, Asia, even one in Africa. Definitely had some weird vibes at different places, but never had the same feeling of "hacked" as above.
But just wanted to clarify the facts. Does what I said make sense? Sorry it's late here.
Also i didn’t think the original article was referring to Amazon but i could be wrong about that, sorry.
That should have been the first tip off something was wrong, Meta would start with a LeetCode medium or hard.
> hacks and leaks earnings report and insider trades but only right after it leaks <
“North Korea did it wdym”
> investigators find planted reference to an APAC timezone or font within the exploit <
case closed
The attackers were using already known Lazarus malware. The researchers aren't simply basing the Lazarus attribution solely on an insider trading strategy or time zones.
Can it be bypassed? Yes.
Are the researchers whose entire company hinges on the correctness of their analysis doing their absolute best to attribute the attack to a threat actor? Yes.
So to your point, somebody could indeed reuse malware or attempt to replicate it. However, the researchers are likely analyzing the disassembly and bytecode, and replicating complex malware to perfectly imitate a known family of malware is exceptionally difficult and statistically very unlikely. This is how threat intel is able to make any sort of claim of attribution.
Employees don't belong to their employer. There is nothing wrong with trying to acquire a potentially better job. The only real problem is they were using company resources to do so. Also, they were completely incompetent by running random executables.