Google warns security researchers of North Korean campaign

Google’s Threat Analysis Group (TAG) has revealed details of an extensive campaign by North Korean threat actors who have been exploiting zero-day vulnerabilities to target security researchers.

This ongoing campaign was first identified in January 2021, and the latest zero-day exploit used by these threat actors was discovered in recent weeks. Google TAG has reported this vulnerability to the unnamed software vendor, and a patch is currently in development.

The attackers employed a patient and strategic approach, initiating conversations with security researchers on social media platforms to establish trust before suggesting a transition to encrypted messaging apps. This shift was presented as a collaboration opportunity on topics of shared interest. In some instances, attackers spent months building rapport with their targets.

The subsequent phase of the attack involved sending the targeted security researcher a malicious file containing at least one zero-day vulnerability in a popular software package. Additionally, another tool was introduced as a Windows application capable of downloading debugging symbols from major symbol servers such as Microsoft, Google, Mozilla, and Citrix. Although these symbols are typically useful for debugging and vulnerability research, this specific package had the capability to download and execute arbitrary code from an attacker-controlled domain, according to TAG.

TAG’s recommendation for those who have used this software is to perform a clean installation of their operating system, given the potential compromise associated with the tool.

Akshara Krishnan
Akshara Krishnan
Akshara Krishnan is passionate content and copywriter, who is highly interested and competent in the fields of digital marketing and supply chain management. She is an avid reader who enjoys books on self-help and psychology, and actively partakes in classical singing.

Similar Articles

Comments

Most Popular