Security News > 2023 > September > North Korean hackers target security researchers with zero-day exploit
North Korean threat actors are once again attempting to compromise security researchers' machines by employing a zero-day exploit.
The warning comes from Google's own security researchers Clement Lecigne and Maddie Stone, who detailed the latest campaign mounted by government-backed attackers.
The attackers initially contacted the researchers through social media on the pretense of collaborating on security research.
The attackers also tried another trick: they pointed the researchers towards a Windows tool that downloads debugging symbols from Microsoft, Google, Mozilla and Citrix symbol servers for reverse engineers, but is also capable of downloading and executing arbitrary code from an attacker-controlled domain.
"If you have downloaded or run this tool, [Google] TAG recommends taking precautions to ensure your system is in a known clean state, likely requiring a reinstall of the operating system," the researchers advised.
A similar campaign was revealed in January 2021, when threat actors, believed to be backed by the North Korean government, created accounts on Twitter, LinkedIn, Keybase, and Telegram to directly contact security researchers.
News URL
https://www.helpnetsecurity.com/2023/09/08/security-researchers-zero-day-compromise/
Related news
- North Korean hackers create Flutter apps to bypass macOS security (source)
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials (source)
- Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection (source)
- North Korean govt hackers linked to Play ransomware attack (source)
- North Korean hackers pave the way for Play ransomware (source)
- Hackers target critical zero-day vulnerability in PTZ cameras (source)
- Germany drafts law to protect researchers who find security flaws (source)
- North Korean hackers employ new tactics to compromise crypto-related businesses (source)
- North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS (source)
- North Korean hackers use new macOS malware against crypto firms (source)