Security News > 2023 > September > North Korean hackers target security researchers with zero-day exploit

North Korean hackers target security researchers with zero-day exploit
2023-09-08 09:22

North Korean threat actors are once again attempting to compromise security researchers' machines by employing a zero-day exploit.

The warning comes from Google's own security researchers Clement Lecigne and Maddie Stone, who detailed the latest campaign mounted by government-backed attackers.

The attackers initially contacted the researchers through social media on the pretense of collaborating on security research.

The attackers also tried another trick: they pointed the researchers towards a Windows tool that downloads debugging symbols from Microsoft, Google, Mozilla and Citrix symbol servers for reverse engineers, but is also capable of downloading and executing arbitrary code from an attacker-controlled domain.

"If you have downloaded or run this tool, [Google] TAG recommends taking precautions to ensure your system is in a known clean state, likely requiring a reinstall of the operating system," the researchers advised.

A similar campaign was revealed in January 2021, when threat actors, believed to be backed by the North Korean government, created accounts on Twitter, LinkedIn, Keybase, and Telegram to directly contact security researchers.


News URL

https://www.helpnetsecurity.com/2023/09/08/security-researchers-zero-day-compromise/