Hacker News new | ask | show | jobs
by sneakerblack 33 days ago
This all stinks of Lazarus:

https://en.wikipedia.org/wiki/Lazarus_Group

I've done incident responses for this exact type of attack multiple times. They've gotten much better organized lately and will often contact developers directly (over LinkedIn or WhatsApp) to run this type of attack. (Although, usually pretending to run a test for a job interview -- which is maybe why the author was confused about the code)

2 comments

Why assume it is Lazarus?

This sort of an attack is comically simple to pull off with a 12b obliterated LLM model and some basic scripts and proxies.

Security has to evolve, or the world will be cooked by script kiddies running email loops.

There's really nothing sophisticated about this these days, and it's only a short matter of time before it becomes commonplace.

Fair challenge, you're right that there's nothing sophisticated about this type of activity, but if you look at Lazarus activity this is their ttp. I mentioned TraderTraitor, go look them up (that sounds terse, it's not meant to be). They stole a couple of hundred million dollars in the past 6 months. They're not particularly sophisticated in terms of ttp, but because they're a nation-state actor they it's an entirely different threat model than script kiddie.

Attribution is hard, but if we're talking about defending, there's little cost to assuming Lazarus-style threat actor.

>Attribution is hard

Very. Frustrating how many "Nation State" attributions boil down entirely because it's some Russian hacker, and they're using some publicly known bit of malware.

No 0days, no magic...

Yeah, the only "sophistication" is the social engineering aspect. Which back in the day a lot of hackers weren't very good at.

But people train up and develop skills.

100%. I can't find it now, but someone last month posted a similar story on HN. The threat actor had stolen someone's GitHub account and altered their otherwise legitimate looking repo. They'll expend a lot of effort in order to masquerade and trick you. TraderTraitor is another good DPRK example.

Anyone reading - if you're ever a victim, worth reporting to your national CERT and your org. The CERT can provide advice, it's useful for their threat intel, and your org can check their systems. You might not be the end target.

Again, you don't need to be a "Nation State" to think this up, and then implement with a few scripts and a bit of LLM.

Some 13yo kid with a VPS could do it