jerry,
@jerry@infosec.exchange avatar

It’s perhaps a bit disappointing that Google decided not to reach out to me/the mod team as they posted this: https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/

The account is suspended now.

JezCaudle,
@JezCaudle@infosec.exchange avatar

@jerry Can I put it on CV (Latin for resumé) that I have been targeted by the NK Lazarus group?

I think I should be allowed to put it on LinkedIn with my 50 meters swimming certificate.

Make T-shirts @jerry and sell them to pay for the servers. “I’m an NK target! Infosec.exchange etc

davep,
@davep@infosec.exchange avatar

@jerry Didn't they contact you before publishing?

jerry,
@jerry@infosec.exchange avatar

@davep no

davep,
@davep@infosec.exchange avatar

@jerry That's a bit shabby, in my opinion.

davep,
@davep@infosec.exchange avatar

@jerry I had a look earlier. How very odd.

tahomasoft,
@tahomasoft@infosec.exchange avatar

@jerry thanks for taking action Jerry! I agree, that is disappointing about Google not giving you a heads up first.

jerry,
@jerry@infosec.exchange avatar

@tahomasoft I am sure they had a reason. I will give the benefit of the doubt.

Lee_Holmes,
@Lee_Holmes@infosec.exchange avatar

@jerry Sadly, this seems to be often the case. In Azure, we had folks super upset about abuse of the platform (bad storage accounts, etc.) but had never used any of the abuse reporting mechanisms.

This is like when the whole security industry blogs and complains about some malicious threat actor steamrolling the world. But then @briankrebs just goes and reports it to their registrar / hoster and gets them nuked.

jerry,
@jerry@infosec.exchange avatar

@Lee_Holmes @briankrebs Google may have a perfectly rational reason for not contacting me, and so I am not going to assume, but just saying that it’s disappointing.

erickolb,
@erickolb@infosec.exchange avatar

@jerry @Lee_Holmes @briankrebs If nothing else, this is an opportunity to build a new bridge. Perhaps they're so accustomed to Twitter/X being faceless and non-responsive that they simply did not consider it might be otherwise here.

jerry,
@jerry@infosec.exchange avatar

Also, if you downloaded the tools referenced in https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/ it’s time to do all the things.

erickolb,
@erickolb@infosec.exchange avatar

@jerry Well, Maddie - one of the co-authors - appears to also have a profile on this server too, if you wanted to tag her and have a chat about it.

jerry,
@jerry@infosec.exchange avatar

@erickolb thank you. I will do that.

jerry,
@jerry@infosec.exchange avatar

The account had 16 followers on the fediverse. Nearly all of those were here on ISE. I intend to look closely into each one.

mathaetaes,
@mathaetaes@infosec.exchange avatar

@jerry When you're big enough that N. Korea starts using your server for nation state operations, I think that means you made it.

Congratulations!

jerry,
@jerry@infosec.exchange avatar

@mathaetaes that is a somewhat alarming revelation 😅

geekgrrl,
@geekgrrl@infosec.exchange avatar
catsalad,
@catsalad@infosec.exchange avatar
dnsprincess,
@dnsprincess@infosec.exchange avatar

@jerry how hard is it to find the report button?

jerry,
@jerry@infosec.exchange avatar

@dnsprincess based on the >2400 reports we’ve processed to date, I’m going with “not very”

JessTheUnstill,
@JessTheUnstill@infosec.exchange avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines