/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google says North Korea-backed hackers are again targeting security researchers via a zero-day exploit; this still unfixed flaw is in a popular software package

Google researchers say currently unfixed vulnerability affects a popular software package.  —  North Korea-backed hackers …

Ars Technica Dan Goodin

Context & Ripple Effects

This report extends a documented pattern: Google had previously described a suspected North Korean campaign that used fake researcher identities, blogs, and backdoor software to pursue infosec specialists, as covered in the earlier campaign against security researchers.

The significance is the combination of a targeted social-engineering audience and an exploit that remains unpatched: researchers who investigate vulnerabilities can themselves become an entry point for intelligence collection or further compromise.

First-order effects

  • Security researchers and organizations using the affected software package face immediate exposure until a fix or effective mitigation is available.
  • Google’s disclosure gives defenders and the research community a concrete warning that the same North Korea-linked targeting pattern is active again, now paired with a zero-day.

Second-order effects

  • Security teams and software maintainers will need to prioritize detection, containment, and patch development over routine update cycles, while researchers may tighten verification of contacts and collaboration materials.
  • The campaign reinforces that vulnerability researchers are a high-value target set: compromising their devices can expose unpublished findings, tools, and trusted professional networks.

Third-order effects

  • If repeated targeting persists, zero-day defense will increasingly require protecting the research ecosystem—not only patching products—through stronger operational security around discovery and disclosure workflows.
  • The case fits a broader shift toward state-linked actors combining tailored targeting with unpatched flaws, raising the value of faster vendor response and cross-industry threat sharing.

The trend: State-linked hacking campaigns are increasingly pairing identity-based targeting of specialists with zero-day exploitation to reach high-value technical networks.

Discussion

  • @digivector Adam on x
    Check if you've communicated with Paul091_! Outside of the 0-day, they also pushed their github project, GetSymbol - meant to help researchers download symbols. But it contains an update channel that could allow them to run arbitrary exes on machines of interest! [image]
  • @billyleonard Billy Leonard on x
    🚨 DPRK 🇰🇵 campaign against security researchers - new from @Google TAGs @maddiestone @_clem1 @digivector on new 0day ITW and potential infection through a tool aimed at helping the research community. as wu said protect ya neck kids 🦇 https://blog.google/...
  • @ryanaraine Ryan Naraine on x
    @wdormann agree. the decision to withhold the name of the software package is so odd.
  • @_xpn_ @_xpn_ on x
    Not saying we need validating by being targeted by NK.. but y'all know this shit is going on your LinkedIn if [@]Paul091_ slid into your DM's
  • @wdormann Will Dormann on x
    I suppose I'd like to know at least what class of app was targeted with this 0day. Is that too much to share? [image]
  • @wdormann Will Dormann on x
    But we'll find out exactly what the vulnerability is, and what was being targeted in 7 days. If Google follows their own policy, that is. [image]
  • @johnhultquist John Hultquist🌻 on x
    Coupled with the news yesterday of targeting of MSFT's debugging system, obvious trend of advanced threat actors seeking to infiltrate the vulnerability process.
  • @ianwboyle Ian Boyle on x
    🚨 Dose Of Reality 1) APTs use socials, forums, repos, etc. 2) If you're poking around, gaining privs or access, making noise, etc. you're bound to be tracked by nation states. 3) Spies / state actors are everywhere. You likely have no idea where / who they are. Vigilance
  • @maddiestone Maddie Stone on x
    Our contact email is at the bottom of this blog post: https://blog.google/...
  • @shanehuntley Shane Huntley on x
    North Korea 🇰🇵 thinks it's easier to steal 0day from researchers than to find it themselves. If you are doing security research or have privileged access you have to assume you could be targeted at some point by a nation state.
  • @kseproso @kseproso on x
    #Lazarus Additional file: GetSymbol - v2.0.2.exe MD5: 49b8fbe174867c9933a496b94b9a93d5 SHA-1: 1493d924a65a99b1ea46aa9ad96d3b971c41544 0 SHA-256: 2bd5e0428a32c852b318abc44d51f65caabc2d0 e83bf3e5a47ee70cde2231984 https://blog.google/... [image]
  • @jgamblin Jerry Gamblin on x
    Wait, so am I not getting a free trip to Pyongyang? https://blog.google/...
  • @evacide Eva on x
    Security researchers love it when state actors send the malware to them directly. We are very lazy. Here's Google's TAG writing up a North Korean campaign targeting security researchers. Please enjoy. https://blog.google/...
  • @lukolejnik Lukasz Olejnik on x
    Attention, another wave of threat actors targeting security researchers. N Korea. 0days in use. They build rapport using social media (X, Mastodon), then deliver the infected files. https://blog.google/... [image]
  • @vxunderground @vxunderground on x
    Today Google TAG (Threat Analysis Group) reported they have identified North Korean State-Sponsored Threat Actors targeting security researchers (again). They identified accounts on both Twitter and Mastodon. 😋 https://blog.google/...
  • @felixaime Félix Aimé on x
    These domains can be related as well. If someone has data on these ones 🫶 : > rapisigns[.]com > ecordillos[.]com > bitsvertise[.]com > ismartrium[.]com https://blog.google/...
  • @maddiestone Maddie Stone on x
    North Korean actors 🇰🇵 are targeting security researchers again including use of at least one 0-day. IOCs in the blog ⬇️ If you've been in contact, please reach out https://blog.google/... [image]