← back

Same loader, new front doors: Tracking DPRK Through The Supply Chain

Slides from my BSides talk, 42 slides.

Download PDF (12 MB)
  1. Slide 1: Tracking DPRK Through The Supply Chain Same loader, new front doors Oscar Sanchez Jr · osj · inf0stache
  2. Slide 2: Who is this guy? Oscar Sanchez Jr for long, osj for short, inf0stache online. I'm an engineer, a researcher, a seeker of hobbies
  3. Slide 3: What am I going to yap about Who North Korea (DPRK) What Malware When On install Where Your computer Why ?
  4. Slide 4: Why do they do this? Crypto stolen by DPRK hackers, per year 2022 ~$1.7B 2023 $660M 2024 $1.34B 2025 $2.02B $6.75B all time Source: Chainalysis (2023 revised from ~$1B to $660M)
  5. Slide 5: What does the full picture actually look like
  6. Slide 6: How it starts Recruiter message
  7. Slide 7: GetChainVerse
  8. Slide 8: Screenshots of the GetChainVerse X profile and its Blockchain Developer job post on hirist.tech
  9. Slide 9: The coding test "react-check-error" ?
  10. Slide 10: react-check-error What's inside https://jsonkeeper.com/b/JOCBY
  11. Slide 11: jsonkeeper.com/b/JOCBY What's at the link Malware.
  12. Slide 12: okay okay, maybe it was a mistake. let's look at their gist
  13. Slide 13: you'll never believe what those gist decode to...
  14. Slide 14: getchainverse gist Decoded
  15. Slide 15: Meme: believe it or not... malware
  16. Slide 16: Lots of campaigns, lots of names each one does things a little differently Contagious Interview Lazarus Group Famous Chollima ↓ fake job ↓ big heists ↓ IT workers Today we're mostly looking at Contagious Interview...
  17. Slide 17: Why devs specifically? Their machines have the good stuff passwords to various things bank accounts crypto maybe some good photos documents crypto currency laying around
  18. Slide 18: The way it works is quite simple.
  19. Slide 19: A recruiter reaches out to you,
  20. Slide 20: you likely do a great job and advance, congrats!
  21. Slide 21: So you get the take home assignment
  22. Slide 22: Follow the setup instructions run npm install
  23. Slide 23: that's really all. DPRK thanks you
  24. Slide 24: So what did you install?
  25. Slide 25: A loader that quietly grabs the next stage and runs it
  26. Slide 26: THAT SUCKS
  27. Slide 27: What I want you to take from this Spot the malware. or at least be a little more cautious
  28. Slide 28: One of the first iterations Just an obfuscated mess. Deobfuscated, it looks like this. Malware.
  29. Slide 29: Right in index.js. No attempt to hide. the first file runs on preinstall package.json "scripts": { "preinstall": "node index.js" }
  30. Slide 30: Another iteration looks more innocent Malware.
  31. Slide 31: I've seen them hide it in an svg? An svg is just XML afterall Malware.
  32. Slide 32: One of my favorite methods I've seen from them Malware.
  33. Slide 33: A simple hash
  34. Slide 34: Malware.
  35. Slide 35: I reported it. Then waited. Github followed up with me two months later and the repos are now down.
  36. Slide 36: What else has DPRK been doing in the supply chain?
  37. Slide 37: So what is PolinRider? No interview needed. Just open the wrong repo.
  38. Slide 38: Recently: PolinRider It's just a font file, right?
  39. Slide 39: Run by a VS Code task
  40. Slide 40: PolinRider: inside the font file The next stage comes from the blockchain a technique called EtherHiding, that's a whole other talk Malware.
  41. Slide 41: So as you can see, DPRK are a creative bunch and very generous with their malware.
  42. Slide 42: that's all i got, thank you for coming to my talk. you can find me on linkedin or twitter, bluesky or whatever.  X / Bluesky inf0stache  LinkedIn heyosj Website heyosj.com feedback, slides and more