3 ms·
> The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits. At minimum the payload.
by operator-name 3y ago
> The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits.
At minimum the payload.
- pphysch 3y ago1. DPRK does an actual cybercrime, shellcode/payload eventually gets discovered and disseminated among researchers 2. Script kid acquires said code, makes slight modifications 3. Script kid deploys the malware 4. Cybersec person @ Google is promoted for uncovering major APT operation, big news story How do you prove that this is sufficiently implausible?
- philosopher1234 3y agoi dont think proof is on the table here. you just have to speculate, and make an educated guess.
- pphysch 3y agoI agree, but all the incentives are aligned with making sensational attributions: - Attackers don't want to get identified, so they won't help - Defenders, or their bosses, don't want to admit they got owned by a "skid" - Researchers want to pad their resumes with Serious work, not random skid nonsense - Media wants sensational stories
- willcipriano 3y agoAs shown in the Snowden leaks, The United States was in development of exactly this capacity and its essentially impossible to attribute attacks to nations like this. Anyone who claims to be able to is either ignorant or lying.
- postsantum 3y agoMarble Framework, if anyone is interested