当前位置:首页 > 报告详情

追查朝鲜国家支持的“传染性访谈”行动:通过软件供应链攻击开发者.pdf

上传人: S** 编号:1241078 2026-05-16 52页 6.70MB

1、Hunting North Koreas State-Sponsored“Contagious Interview”Operation:Attacks on Developers via the Software Supply ChainAdversarial tradecraft:How threat actors weaponize open source.Social engineering:Recruiter lures targeting developers and job seekers.Malware zoo:First,second,and third-stage paylo

2、ads.Threat hunting:Detection and triage.Defense guidance:Identify and mitigate risk.Memes:Just a few.From North Korea(DPRK)to the U.S.and BackInterview?Yes,its fake recruiter outreach and an interview-like scenario.Contagious?The“assignment”gets targets to run code thats actually malware.How long ha

3、s it been around?First malicious infrastructure detected in 2022.Really North Korea?High-confidence by USG,and leading security companies.Scale of intrusions?Thousands of victims and infected systems.Scale of theft?North Koreas overall crypto theft$2.02B in 2025 but no vetted total just for Contagio

4、us Interview operation.Contagious Interview What,Why,WhowhoamiKirill Boychenko Senior Threat Intelligence Analyst at Socket(software supply chain security company).Now:Hunt threats,reverse malware,and track adversarial activity across a dozen ecosystems.Previously:CTI and malware analysis at Recorde

5、d Futures Insikt Group(ARMOR:Advanced Reversing,Malware,Operations,and Reconnaissance).SANS Technology Institute alumInfiltrating Official Package RegistriesInfiltrating Official Package RegistriesModern Software Is Composed,Not Written From ScratchOpen Source Dependencies Create a Software Supply C

6、hainModern application has 70 90%open source components(direct and transitive dependencies).GitHub hosts 400M+code repositories and 100M+developers.Open source ecosystems like npm for Node.js(JavaScript/TypeScript)and PyPI for Python have millions of packages with billions of downloads.Open Source S

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
客服
商务合作
小程序
服务号
折叠