News: 1664517190

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft warns of North Korean crew posing as LinkedIn recruiters

(2022/09/30)


Microsoft has claimed a North Korean crew poses as LinkedIn recruiters to distribute poisoned versions of open source software packages.

The state-sponsored group has been around since 2009 and was allegedly behind the [1]2014 attack on Sony Pictures in retaliation for the controversial Seth Rogen comedy The Interview.

[2]Dubbed "ZINC", the threat actors have previously run long-term phishing schemes targeting media, [3]defence and aerospace, and IT services organizations in the US, UK, India, and Russia.

[4]

Starting in June of this year, ZINC relied on social engineering tactics: contacting targets on LinkedIn and claiming to be a recruiter, establishing trust with targets, and switching communications to WhatsApp where they delivered shellcode from the ZetaNile malware family.

[5]

[6]

The payloads were either packed with commercial software implants like Themida and VMProtect or encrypted with custom algorithms, which is decrypted using a custom key in the DLL.

“By encoding the victim information in the parameters for common keywords like gametype or bbs in the HTTP POSTs, these C2 communications can blend in with legitimate traffic,” sad Microsoft.

[7]Norks: FBI's Sony Pictures' hacking allegations are 'groundless slander'

[8]From the crew behind the Sony Pictures hack comes Operation Interception: An aerospace cyber-attack thriller

[9]Operation Blockbuster security biz: We'll get you, Sony hackers

[10]Mandiant 'highly confident' foreign cyberspies will target US midterm elections

The open-source software included PuTTY, KiTTY, TightVNC, Sumatra PDF Reader, and muPDF/Subliminal Recording software installer. Once in, the threat actors use custom remote access tools like FoggyBrass and PhantomStar.

Microsoft said the purpose of the attacks appear to be run-of-the-mill cyberespionage and attempts to steal money or data, or just corporate network sabotage.

[11]

If the group has been around since 2009, why bring it up now?

“Due to the wide use of the platforms and software that ZINC utilizes in this campaign, ZINC could pose a significant threat to individuals and organizations across multiple sectors and regions,” said Microsoft.

LinkedIn's Threat Prevention and Defense outfit detected ZINC making fake profiles and targeting engineers and tech support professionals in the past, and when they do, they shut them down. However, educating end users can go a long way in protecting personal and business information.

[12]

Microsoft has advised scanning for indicators of compromise (IOC) and traffic from certain IP addresses. Reviewing authentication requirements for remote access, and ensuring use of multifactor authentication, is also recommended. ®

Get our [13]Tech Resources



[1] https://www.theregister.com/2014/12/20/north_korea_says_sony_pictures_hack_allegations_are_groundless_slander/

[2] https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/

[3] https://www.theregister.com/2020/06/17/eset_lazarus_group_euro_aerospace_targets/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yza@P4L172SvP86p179BcAAAAIY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yza@P4L172SvP86p179BcAAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yza@P4L172SvP86p179BcAAAAIY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2014/12/20/north_korea_says_sony_pictures_hack_allegations_are_groundless_slander/

[8] https://www.theregister.com/2020/06/17/eset_lazarus_group_euro_aerospace_targets/

[9] https://www.theregister.com/2016/02/24/avengers_assemble_against_sony_hackers/

[10] https://www.theregister.com/2022/09/08/mandiant_cyberspies_us_elections/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yza@P4L172SvP86p179BcAAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yza@P4L172SvP86p179BcAAAAIY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



In high school in Brooklyn
I was the baseball manager,
proud as I could be
I chased baseballs,
gathered thrown bats
handed out the towels Eventually, I bought my own
It was very important work but it was dark blue while
for a small spastic kid, the official ones were green
but I was a team member Nobody ever said anything
When the team got to me about my blue jacket;
their warm-up jackets the guys were my friends
I didn't get one Yet it hurt me all year
Only the regular team to wear that blue jacket
got these jackets, and among all those green ones
surely not a manager Even now, forty years after,
I still recall that jacket
and the memory goes on hurting.
-- Bart Lanier Safford III, "An Obscured Radiance"