3 ms·
I agree in part — a lot of the attribution is extremely weak and based entirely on some correlation of previously weakly attributed tactics, techniques, and pro
by clwg 2y ago
I agree in part — a lot of the attribution is extremely weak and based entirely on some correlation of previously weakly attributed tactics, techniques, and procedures (TTP in security parlance). Also, I think the effort in describing all these threats in this way is misplaced, but that's an entirely different rant.
The counter is North Korea in actually capable of pulling off these attacks because of just how bad things are on the internet and how little skill is actually required to pull off a devastating attack. Even in situations where there isn't active exploit development programs in-country, exploits and exploitation frameworks are available on GitHub or for purchase. We have no idea what sort of controls are in place to prevent someone like North Korea from getting access to Pegasus, Core Impact, or Canvas VulnDisco exploits, plus the support and tooling they receive from friendly countries like China.