ZeroHour
Ars Technica · Securitypublished ()ingested

North Korea-backed hackers target security researchers with 0

criticalExploit / PoCimportance 60
Full article326 words · extracted from arstechnica.com · click to collapse

North Korea-backed hackers are once again targeting security researchers with a zero-day exploit and related malware in an attempt to infiltrate computers used to perform sensitive investigations involving cybersecurity.

The presently unfixed zero-day—meaning a vulnerability that’s known to attackers before the hardware or software vendor has a security patch available—resides in a popular software package used by the targeted researchers, Google researchers said Thursday. They declined to identify the software or provide details about the vulnerability until the vendor, which they privately notified, releases a patch. The vulnerability was exploited using a malicious file the hackers sent the researchers after first spending weeks establishing a working relationship.

Malware used in the campaign closely matches code used in a previous campaign that was definitively tied to hackers backed by the North Korean government, Clement Lecigne and Maddie Stone, both researchers in Google’s Threat Analysis Group, said. That campaign first came to public awareness in January 2021 in posts from the same Google research group and, a few days later, Microsoft.

Two months later, Google was back to report that the same threat actor, instead of lying low after being outed, had returned, this time targeting researchers with a zero-day exploiting a vulnerability in Internet Explorer. Microsoft, which tracks the hacking group as Zinc, patched the vulnerability the same month.

In March, researchers from security firm Mandiant said that they, too, had detected North Korea-backed hackers, tracked as UNC2970, targeting researchers. Mandiant researchers said they first observed the UNC2970 campaign in June 2022.

The playbook in 2021 is the same as the one Google has observed in recent weeks. The hackers pose as security researchers and post security-related content on blogs or social media. They patiently develop relationships with real researchers and later take their discussions to private forums. Eventually, the fake researchers share Trojanized exploits or analysis tools with the researchers in an attempt to have them run it on their personal machines.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/09/north-korea-backed-hackers-target-security-researchers-with-0-day/