Google has released a report revealing that North Korean hackers are targeting security researchers participating in vulnerability. The attacks were detected by the Google Threat Analysis Group (TAG), a Google security team that specializes in hunting down APT hacking groups.

Google said North Korean hackers used profiles on various popular social media platforms — including Twitter, LinkedIn, Telegram, Discord , and Keybase — to communicate with security researchers using fake personas. In some cases, the hackers even attempted to reach security researchers via email.

Adam Weidemann, a security researcher at Google TAG, noted that after the hackers established initial communications, they asked the target researcher if they wanted to collaborate on researching the vulnerabilities, and then provided the researcher with a Visual Studio Project.
The Visual Studio Project contained malicious code that installed malware on the targeted researcher's operating system. The malware acted as a backdoor, communicating with a remote C&C server and waiting for commands.
Wiedemann explained that the attackers didn't always distribute malicious files to their targets. In some cases, they asked security researchers to visit a blog they had hosted at blog [.]Br0vvnn[.]io. According to Google, the blog hosted malicious code that "infected" the security researcher's computer after he accessed the site. Specifically, Weidemann noted that it installed a malicious service on the researcher's system and a backdoor in memory that began transferring data to a C&C server controlled by the hackers.

Google TAG also added that many victims accessing the site were running "fully up-to-date versions of Windows 10 and the Chrome browser," yet were still "infected."
Details about the browser-based attacks are scarce so far, but some security researchers believe that North Korean hackers likely used a combination of Chrome and Windows 10 vulnerabilities to develop the malicious code.

So, the Google TAG team is asking the cybersecurity community to share more information about these attacks if any security researchers believe they have been infected.
The Google TAG report includes a list of links to fake social media profiles that North Korean hackers have used to reach security researchers.
Additionally, security researchers are advised to review their browsing history and see if they interacted with any of these profiles or accessed the malicious domain blog.br0vvnn.io. If they did, they are most likely infected and should take some steps to investigate their systems.

As ZDNet reports, North Korean hackers are targeting security researchers with the ambition of stealing exploits for vulnerabilities discovered by the infected researchers, vulnerabilities with which malicious actors could deploy their attacks with little or no development cost.
Meanwhile, several security researchers have already revealed on social media that they received messages from the attackers' accounts, although none have admitted that any systems have been compromised.
