# One hacker vs. the Hermit Kingdom

By [Blake Thompson Heuer](https://readme.synack.com/author/blake-thompson-heuer)

Published:

Feb. 06, 2022

_Welcome to Changelog for 2/6/22, brought to you by_ [_Synack_](/content/site-root.html) _! Blake here, reporting from Washington. It’s been another jam-packed week for cybersecurity news, with a massive crypto heist, a first-of-its-kind NSA interview and some_ [_gloomy numbers_](https://readme.security/thousands-of-pentagon-contractors-could-buckle-under-cybersecurity-push-a034ff75d314) _for a Pentagon supply chain security program. Let’s dive in:_

## The payload

Can one person hack a whole nation?

It sounds like a promo for a bad movie, but it’s a real question: _Wired_ [reported](https://www.wired.com/story/north-korea-hacker-internet-outage/) Wednesday that one anonymous American hacktivist has been single-handedly responsible for recent outages plaguing North Korean-hosted websites and email services.

A better question might be: _Should_ any one person hack a whole nation?

I don’t think so. Hacking a nation-state in your pajamas is the cybersecurity equivalent of [free-soloing](https://youtu.be/QpqDpZoQCAs?t=43) sheer granite in Yosemite — one wrong move, and you’ve doomed yourself while leaving a mess for someone else to clean up. The hacker _Wired_ identified as “P4x” doesn’t seem too concerned: Stung by a Pyongyang-backed hacking campaign last year that targeted Western security researchers, P4x set out on a revenge mission. He wants to teach the Hermit Kingdom a lesson, coordinating a series of DoS attacks against government targets there.

Cyberattacks launched from the comfort of a home office carry a veneer of safety. What’s the worst that could happen? How would notoriously isolated North Korea possibly retaliate against a lone U.S. hacker? And how much damage could P4x really do, given that the vast majority of North Korean citizens have no internet access? As he emphasized to _Wired’s_ Andy Greenberg, his goal is to “keep NK from hacking the western world completely unchecked,” but not to harm civilians. “My conscience is clear,” he added.

It’s all fun and games until somebody triggers an international crisis. Why would Kim Jong-un have any reason to believe P4x is who he says he is, and not a U.S. version of “lone-hacker”-cum-Russian-intel-officer [Guccifer 2.0](https://www.thedailybeast.com/exclusive-lone-dnc-hacker-guccifer-20-slipped-up-and-revealed-he-was-a-russian-intelligence-officer)?

We have enough to worry about without kicking more beehives in cyberspace. To P4x, I’d say: So what if you were targeted by North Korean hackers last year? Let it go.

## The week, compiled

A top NSA official offered his first public comments on cybersecurity R&D priorities in an interview with [_MIT Technology Review_](https://www.technologyreview.com/2022/02/01/1044561/meet-the-nsa-spies-shaping-the-future/) _._ Gil Herrera, head of NSA’s Research Directorate, was circumspect when it came to specifics about what the high-tech directorate — _Technology Review’s_ Patrick Howell O’Neill likened it to a “small elite technical college” — is pouring money into. Quantum computing breakthroughs, with their potential to break many conventional encryption protocols, are high on the NSA’s list. But so are new mathematical approaches to wrangling Big Data into actionable intelligence.

“Everyone thinks their data is the messiest in the world, and mine maybe is because it’s taken from people who don’t want us to have it, frankly,” Herrera told O’Neill. (Evidently he’s never seen my notebooks.)

Here’s what else we’re reading:

[_Reuters_](https://www.reuters.com/technology/exclusive-iphone-flaw-exploited-by-second-israeli-spy-firm-sources-2022-02-03/) _:_ The infamous “zero-click” iPhone exploit abused by Israel-based spyware developer NSO Group was replicated by a second, lower-profile Israeli company called QuaDream. The ForcedEntry software exploit allowed attackers — AKA, QuaDream and NSO Group customers — to break into a victim’s iPhone without requiring so much as a clicked link or opened text message. Buyers of QuaDream’s multimillion-dollar “REIGN” spyware included governments known to wield malware against political dissidents, sources told Reuters.

[_The Wall Street Journal_](https://www.wsj.com/articles/cyberattack-on-news-corp-believed-linked-to-china-targeted-emails-of-journalists-others-11643979328) _:_ A sweeping hack of journalists at WSJ, the _New York Post,_ and other News Corp. holdings is suspected to have been led by hackers working to benefit China’s interests, investigators say. The attackers were able to steal reporters’ notes in Google Docs, see story drafts before publication and access emails dating back to at least February 2020, according to preliminary findings. The case offers another chilling reminder of how journalists face heightened hacking risks due to the nature of our work.

[_Motherboard_](https://www.vice.com/en/article/xgd483/dollar320-million-crypto-heist-rocks-decentralized-finance-world) _:_ Cryptocurrency heists are a dime a dozen, but the latest cyberattack on decentralized finance “blockchain bridge” Wormhole turned heads in the cybersecurity community for its eye-popping $320 million price tag. What’s a blockchain bridge, you ask? Think of it as the roadway used to convert one type of cryptocurrency, like Solana, to another like Ethereum. And last week’s 9-figure heist is a major bridge collapse.

“Patriot” missile defense systems are staged during a Nov. 4, 2016 U.S.-led military exercise in Romania. Tech. Sgt. Brian Kimball/Dod News photo/ [Flickr](https://flickr.com/photos/dodnewsfeatures/30783103856/)

[_README_](https://readme.security/thousands-of-pentagon-contractors-could-buckle-under-cybersecurity-push-a034ff75d314) _:_ Only one in four U.S. defense contractors are on track to meet baseline cybersecurity standards set to take effect over the next two years at the Department of Defense. The revelation marks the latest hurdle for the Cybersecurity Maturity Model Certification program, a Trump-era effort to ensure tens of thousands of suppliers to the Pentagon are defended against hackers. Biden pledged a do-over of the program — now dubbed CMMC 2.0 — but the looming compliance process is still fraught with risks for contractors large and small, as Shaun Waterman reports.

[_The Wall Street Journal_](https://www.wsj.com/articles/biden-administration-forms-cybersecurity-review-board-to-probe-failures-11643898601) _:_ The Biden administration is convening a 15-person “Cyber Safety Review Board” with an all-star list of cybersecurity leaders including NSA cybersecurity director Rob Joyce, Luta Security CEO Katie Moussouris and Kemba Walden, assistant general counsel for Microsoft Corp.’s Digital Crimes Unit. The board’s first order of business is to probe the U.S. response to the [bombshell Log4j vulnerability](https://readme.security/why-log4j-wont-go-away-5-key-questions-on-the-bombshell-vulnerability-2810ac3f91f6). The panel is loosely modeled after the National Transportation Safety Board, best known for leading independent investigations of U.S. plane accidents — though one cybersecurity CEO [noted](https://twitter.com/RobertMLee/status/1489349480600285187) that the CSRB panel doesn’t feature anyone with deep operational technology or industrial control system expertise, arguably the cybersecurity arena that’s linked closest to safety.

[_Mandiant_](https://www.mandiant.com/resources/ransomware-extortion-ot-docs) _:_ Speaking of ICS security, ransomware extortion sites routinely house sensitive operational data stolen from industrial organizations like power utilities and oil companies. That’s a big problem, because dated [OT](https://en.wikipedia.org/wiki/Operational_technology) information can still be useful for attackers. “Even if the exposed OT data is relatively old, the typical life span of cyber physical systems ranges from twenty to thirty years,” Mandiant researchers pointed out in research unveiled last Monday.

## Flash memory

The Winter Olympics kicked off Friday in Beijing, bringing plenty of fanfare but [very little natural snow](https://www.washingtonpost.com/sports/olympics/2022/02/01/fake-snow-winter-olympics/). The cyberthreat forecast is similarly clear, according to [some experts](https://www.recordedfuture.com/threats-2022-olympics-games/), but some past Olympic events have been stormier. Hackers backed by Russia’s GRU spy agency struck the 2018 Winter Olympics in Pyeongchang, South Korea with such guile that [_Wired_ later labeled](https://www.wired.com/story/untold-story-2018-olympics-destroyer-cyberattack/) the cyberattack “the most deceptive hack in history.” Olympic Destroyer, as the attack came to be known, ricocheted through key South Korean IT systems ahead of opening ceremonies, leaving behind a trail of false flags to point the finger at North Korea. The worm spread via a potent Windows networking vulnerability, causing collateral damage and even disabling the ski lift at a nearby South Korean resort, as [Kaspersky researchers](https://securelist.com/olympicdestroyer-is-here-to-trick-the-industry/84295/) observed. Being from Florida, that’s basically my worst nightmare: I’ll hope for the Beijing athletes’ sake that they can avoid [a similar fate](https://youtu.be/wo1gJDtgOMU?t=40).

## Local files

[_BBC News_](https://www.bbc.com/news/technology-60250956) _:_ European oil facilities faced a barrage of cyberattacks last week, disrupting IT systems in Germany, the Netherlands and Belgium. At least some oil deliveries were affected, and German news outlet _Handelsblat_ [reported](https://www.handelsblatt.com/unternehmen/energie/benzinversorgung-black-cat-erpressersoftware-staatsanwaltschaft-ermittelt-nach-angriff-auf-tankstellen-zulieferer/28029264.html) that the BlackCat ransomware variant was implicated in the attacks there.

[_CyberScoop_](https://www.cyberscoop.com/palestinian-targeted-arid-viper-hamas/) _:_ Cisco Talos researchers disclosed a renewed hacking campaign targeting Palestinian organizations, noting that the “Arid Viper” Arabic-speaking threat group is recycling 5-year old tactics with little regard for their conspicuousness.

[_CultureMap_](https://sanantonio.culturemap.com/news/city-life/02-01-22-san-antonio-5-million-dollar-hub-cybersecurity/) _:_ A $5 million cybersecurity training center is taking shape in San Antonio, a hub of U.S. hacking talent.

## Off-script

Lightning bolt!

The National Oceanic and Atmospheric Administration recorded the world’s longest-ever lightning flash, a 477-mile arc that spanned from Texas to Mississippi on April 29, 2020. The so-called [megaflash](https://public.wmo.int/en/media/press-release/wmo-certifies-two-megaflash-lightning-records) resembles a supercharged sidewinder as it snakes across the southern U.S:

A record-setting lightning flash. Credit: NOAA/via YouTube.
_That’s it for this week — feedback, tips and hacking tricks are welcome at bsobczak@synack.com. Thanks for reading!_
