Security News > 2023 > September > North Korean hackers target security researchers with zero-day exploit
North Korean threat actors are once again attempting to compromise security researchers' machines by employing a zero-day exploit.
The warning comes from Google's own security researchers Clement Lecigne and Maddie Stone, who detailed the latest campaign mounted by government-backed attackers.
The attackers initially contacted the researchers through social media on the pretense of collaborating on security research.
The attackers also tried another trick: they pointed the researchers towards a Windows tool that downloads debugging symbols from Microsoft, Google, Mozilla and Citrix symbol servers for reverse engineers, but is also capable of downloading and executing arbitrary code from an attacker-controlled domain.
"If you have downloaded or run this tool, [Google] TAG recommends taking precautions to ensure your system is in a known clean state, likely requiring a reinstall of the operating system," the researchers advised.
A similar campaign was revealed in January 2021, when threat actors, believed to be backed by the North Korean government, created accounts on Twitter, LinkedIn, Keybase, and Telegram to directly contact security researchers.
News URL
https://www.helpnetsecurity.com/2023/09/08/security-researchers-zero-day-compromise/
Related news
- North Korean ScarCruft Exploits Windows Zero-Day to Spread RokRAT Malware (source)
- Hackers exploit 52 zero-days on the first day of Pwn2Own Ireland (source)
- Lazarus hackers used fake DeFi game to exploit Google Chrome zero-day (source)
- North Korean hackers create Flutter apps to bypass macOS security (source)
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials (source)
- North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks (source)
- Google Adds New Pixel Security Features to Block 2G Exploits and Baseband Attacks (source)
- Researchers Uncover Major Security Vulnerabilities in Industrial MMS Protocol Libraries (source)
- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools (source)
- Iranian hackers now exploit Windows flaw to elevate privileges (source)