BLOG
Ransomeware arrests, crypto heist, Mac and Baileys malware, DPRK's A/B testing
By cb482791-4ef1-4762-96ad-b0ca4bdd538e · The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.
This week we talked about:
ShinyHunters and KillSec arrests: Dutch police arrested Pepijn van der Stap, a long-time ShinyHunters member known as Umbreon, on September 16, less than a year after he finished a prison sentence for earlier hacking. His arrest followed a power struggle with the group’s 16-year-old leader over who controls its infrastructure. Separately, police arrested three suspected members of the KillSec ransomware group. The group is linked to roughly 1,000 attacks and used AI to build its infrastructure and identify victims.
Bitget crypto heist: Suspected North Korean hackers stole $351.6 million from the hot and warm wallets of crypto exchange Bitget. Customer accounts still showed full balances after the funds were drained. Incident response firm SlowMist attributes the initial access to a zero-day in an unnamed security product.
Signed Mac malware posing as Claude Desktop: A lookalike Claude Desktop site is serving a signed macOS installer hosted on GitHub. It appears to be the real app with a padded payload added. Because it’s signed, macOS installs it without warning, and the file is about four times the size of the real installer.
Baileys campaign update: The number of malicious npm packages abusing the Baileys WhatsApp library now tops 100. Most only inflate follower counts for WhatsApp channels, so the direct risk is low. Some have also served as a base for other attacks, including WhatsApp-based C2.
PolinRider A/B testing: DPRK’s PolinRider campaign is changing its fake font trick to slip past detections that rely on a single file name. The fa-solid-400.woff2 payload has been renamed to 500, 900, and 300 and moved deep into legitimate folders. Most recently it was given a .llf extension that has nothing to do with fonts.
We’re hiring: OpenSourceMalware is looking for a part-time malware researcher with software supply chain experience.
Resources #
ShinyHunters and KillSec arrests #
[00:00:00] Jenn Gile: Hello. It is Thursday, October 1st. Um, after last week talking about the ShinyHunters hack of the FBI, uh, Paul and I, I think we’re both, um, a little jazzed that some arrests were announced both, uh, with two groups, both ShinyHunters and KillSec, right?
[00:00:21] Paul McCarty: Indeed, indeed. The, uh, the forewarned arrests are starting to happen, so happy days
[00:00:30] Jenn Gile: Happy days. [00:00:31] Jenn Gile: So to be clear, these are ransomware groups. We haven’t seen these groups active in the software supply chain space, but, um, definitely shared tactics, similar technologies. So I think there’s a lot to learn by looking at this. Um, the first thing to know is the ShinyHunters arrest is of somebody who, uh, is kind of purported to be the leader.
[00:00:56] Jenn Gile: Um, it’s a little unclear if they really are or not, but they’re, uh, Dutch. They were arrested in the Netherlands. Uh, they were actually recently released from prison after serving three years. Uh, you know, uh, they’re an allegedly reformed hacker, clearly not. Um, they were recently working at a security company.
[00:01:18] Jenn Gile: Um, so they have been charged. Um, Paul, I see you have in the notes also for inciting two murders. I did not hear that. What, what’s that?
[00:01:28] Paul McCarty: Yeah. All right. So this guy’s name, I’m gonna mur- I’m gonna, forgive the pun, I’m gonna murder his name, but it’s, um, Pepijn. It’s a Dutch name, obviously, P-E-P-I-J-N. Um, uh, it’s Pepijn van der Stap.
[00:01:41] Paul McCarty: Um, yeah, he’s, he’s 24, I think, and he was arrested on the 15th of September. Um, he’s got a long history. So he’s, he’s a known hacker, um, and he’s been involved with ShinyHunters, uh, and other groups, you know, before. He was arrested in 2023. He was sent to prison for parts of three years, just got out. One of the press releases I saw said that he got out in December of 2025.
[00:02:06] Paul McCarty: The other one said January of 2026. So this is very recent. Um, and he was on, they call it probation, but in America we’d, we’d call that parole, um, which are two different things. But anyhow, maybe in the Netherlands it’s different. But yeah, he is, um… All right. So my, I wouldn’t call it inside baseball, Jenn. I would say that in my research and, and talking to some people that know more, he was effectively the leader of the ShinyHunters group or, or whatever was the precursor for that for a while, and he owned all of the infrastructure for the group, and then he got arrested in 2023, went to prison.
[00:02:47] Paul McCarty: And anyhow, more recently, there’s this kid, um, this Jordanian kid, Rey, who’s kind of came over from, from the Lapsus$, that ridiculous Lapsus$ ShinyHunters-
[00:02:59] Jenn Gile: SLSH group … me- Yeah … [00:03:01] Paul McCarty: right. Amalgam. Yeah. And Rey is, you know, 16, so I’m not gonna say his name. Krebs is fully doxxed him, um- And, um, lives in Jordan and has taken over kind of…
[00:03:13] Paul McCarty: And, and he and, mm, Umbreon. So, um, the Pepijn’s handle was Umbreon. He’s been using it for years. Um, and, um, Rey and Umbreon were… There was some sort of power struggle inside of ShinyHunters basically over who, who kind of called the shots and who owned the infrastructure. And this is always a thing with these groups, whether it’s ransomware, whether it’s software supply chain, it’s like whoever owns the C2 infrastructure basically owns the ability to make money off of it, like the revenue generation side of it.
[00:03:43] Paul McCarty: So, um, that’s super important. Yeah, so I guess these two were beefing, Rey and Jordan, and Pepijn, Umbreon in, um, in, uh, the Netherlands. Mm-hmm. And, and Rey basically kind of outed or doxxed, um, Umbreon by using his, uh, logo. His… So Umbreon is a Pokemon character and there’s this
[00:04:06] Jenn Gile: whole- Yeah. I mean, from what I saw, you know, order of timeline here, uh, Umbreon was arrested, like you said, September 16th.
[00:04:16] Jenn Gile: The FBI hack happened after that presumably by Rey, but he’s trying to shift blame onto Umbreon. Lots of drama here.
[00:04:26] Paul McCarty: Lots of drama. And they, somebody asked Rey, you know, “Is, is Umbreon part of your group?” And he said, no. And he said, “Well, if you look back at your history, it’s clear he’s part of your group.”
[00:04:35] Paul McCarty: But anyway, it was just, you know, 16 year olds being 16 year olds. Um, so, uh, Umbreon, Pepijn formerly worked for Hadrian, um, and then worked more recently for Neo, um, in the Netherlands, um, is an offensive security researcher. I mean, not surprising. And I think we’re gonna see more of this unfortunately. We were teased this in Europe that, um…
[00:04:59] Paul McCarty: And other people have been kind of teasing this on, on Twitter and other places, that there’s a number of arrests coming, uh, you know, around people that are actively in the, the, um, uh, security research space, one of whom, you know, up until recently worked at, um, Huntress. Um-
[00:05:18] **Jenn Gile:** Mm-hmm. So
[00:05:19] **Paul McCarty:** Yeah. Potently.
[00:05:19] **Jenn Gile:** You know, we’ve got- Yeah
[00:05:20] Jenn Gile: an overlap here of young Criminals and experienced researchers getting involved with them. So looking at KillSec, uh, they’re a ransomware group as well. Um, you know, similar MO, “We’ll leak your data if you don’t pay us.” Uh, they’re suspected of about 1,000 attacks, uh, allegedly maybe 500 of those were successful.
[00:05:46] Jenn Gile: They’re kind of vague in the article, but are basically like, yeah, they’ve been financially, um, very successful attacks. Uh, the article talks about, uh, how this particular group is, um, known to use AI to build and operate their infrastructure and identify potential victims. And if you look at the ages of the people arrested, that’s not a huge surprise.
[00:06:08] Jenn Gile: Um, so three arrests. One is a 16-year-old from Spain. The other two are in their 20s, uh, from the UK and Romania. There’s a fourth person who was not arrested. Uh, sounds like probably the reason is he was a minor. Well, I assume he… They were a minor at the time the crimes were done, in the country where they live, they may be safe from prosecution because of that.
[00:06:32] Jenn Gile: Not totally clear. But, um, yeah, similar story here, right? [00:06:40] Paul McCarty: Yeah. And the same thing is going on with the remnants of the TeamPCP crew too as well, right? And, um, with, with Box Turtle exploiters, um, you know, some still on Twitter and talking. I wonder, I wonder why that could be. Could it be that they’re under 18 and in their country- Uh, I won’t say it
[00:07:00] **Jenn Gile:** Basically safe Anyhow.
[00:07:02] **Jenn Gile:** Yeah. Could be
[00:07:02] **Paul McCarty:** Yeah But
[00:07:03] **Jenn Gile:** yeah, you- It’s not, it’s
[00:07:04] **Paul McCarty:** not foolproof …
[00:07:05] Jenn Gile: you bring up a point that we’re in a place in cyber crime where a lot of the threat actors are minors, they live places where they’re safe from prosecution or safe to an extent. Um, you and I met someone recently who is a reformed threat actor who shared that they actually intentionally got caught while they were still a minor because they knew the, uh, repercussions would be light, and they were.
[00:07:39] Jenn Gile: And then- Yeah … that person went on to commit more crimes as an adult and ultimately, you know, did pay the price for it.
[00:07:48] Paul McCarty: Yeah, 10-4. I, and I brought this up in our show notes because I’m seeing a pattern. Like, and we’ve talked about it before here, and I’ve talked about it on stage and other places, we both have, that, you know, AI agent, agentic tools allow people to write stuff that they weren’t able to write before, right?
[00:08:05] Paul McCarty: It brings us all a, kind of a skill set that we didn’t necessarily have before. Um, or even those of us that are software engineers like myself, you know, like just, anyhow, we all understand this, like, technological advance that we’re all going through. What we have here is we have these very capable agentic tools and people under the age of 18 who don’t really understand the consequences of their action, and there is no other place that this is better been, you know, advertised and seen than in TeamPCP’s Twitter post, their constant Twitter posting, right?
[00:08:41] Paul McCarty: Like, they said, “Oh, we know the end is coming,” and, but they didn’t know the end is… I mean, they, in their head, they thought they knew that the end was coming, but you don’t know what prison’s like until you’ve been arrested and stripped down and sent… Like, they, they have no idea what’s coming to them, so they’re operating in this kind of pretend worldview where, you know, there are no consequences.
[00:09:01] Paul McCarty: And, and unfortunately in some of these countries, including Australia, if you’re under the age of 18, you cannot be arrested for some of these crimes, which is unfortunate. Now, I’m not saying that I want 16-year-olds to go to prison. Don’t say that at all. But we have a problem here where these tools are allowing people that are under the age of 18 to do real crimes.
[00:09:19] Paul McCarty: Let’s be very clear. This malware that I’m seeing, just in the last week I found two net new malware strains, and I’ve been a- because of the terrible OPSEC of the author, I’ve been able to track it all the way back to somebody who’s under 18, which is why I’m not gonna emphasize his name and any of the details.
[00:09:34] Paul McCarty: But, like, and, and, and the reason they have terrible OPSEC is because, you know, they feel like they’re untouchable.
[00:09:41] Jenn Gile: Yeah. Well, I think it is that invincible, uh, attitude that a lot of kids get. You know, you and I have spent our fair share around, uh, kids as parents and, you know, they don’t often understand the consequences Okay, let’s talk- I know I, I
[00:09:59] **Paul McCarty:** know I didn’t at 16.
[00:10:00] **Paul McCarty:** Sorry.
[00:10:01] **Jenn Gile:** No, of course not. I know
[00:10:02] **Paul McCarty:** I didn’t.
North Korea steals $351.6M from Bitget #
[00:10:03] Jenn Gile: Uh, let’s talk about a group that absolutely does know the consequences. Um, so also tangentially related to, um, malicious open source, uh, Bitget was hit in the last week. Um, so this is a crypto… Are they an exchange group? I’m actually not totally clear. Yeah, they’re a, a crypto exchange.
[00:10:25] Jenn Gile: And, um, so the hackers are presumed to be North Korean. They stole $351.6 million of crypto after a backend compromise. Uh, we’ve seen this before, right? This is not the first crypto exchange hit by North Korean hackers. It’s certainly not the first, um, theft of crypto by North Korean hackers. Uh- I don’t know.
[00:10:53] Jenn Gile: What do you wanna, what do you wanna say about this? [00:10:56] Paul McCarty: Well, I mean, you know, like you said, this is one in a long line of, of large crypto heists. Um, I actually came across a really cool website. I forgot to send you the link last night, but it’s called, um, Crypto Heist Calendar, and basically what it does, it shows you month, month, like it has a calendar and on each day it’ll show, like, Bitget, 351 million, and then a few days before that’ll be another one.
[00:11:18] Paul McCarty: Um, so I’ll make sure that I get that to you so we can put that in the show notes. But, um, I think what’s interesting about this one is that, um, DPRK threat actors are getting a lot better at, I mean, just more technologically advanced and being able to do stuff to blockchain and to these ecosystems and, and it’s just yet more evidence that DPRK is much more advanced than people, you know, in the enterprise give them credit to.
[00:11:42] Paul McCarty: Just because they don’t do ransomware, enterprise security architect, doesn’t mean they’re not a threat, right? Because they’re using this money. What do you think they’re gonna use this 341 mil- sorry, $351 million, Jenn, for? They’re gonna use it to build nukes. It’s that simple.
[00:11:58] Jenn Gile: And probably put it back into their cyber crime programs, right? [00:12:05] Jenn Gile: Um- 100%. Yep … there’s a lot of assumptions about this country culture not having the capability to do this crime. I mean, we just see evidence after evidence that they certainly have the funding, and when you have the funding to do it, you can make it happen. Uh- Yeah. 100% … rewinding for a second 'cause we had a delayed comment come through.
[00:12:27] Jenn Gile: Uh, Matt Fields- Mm-hmm … over in our LinkedIn stream says, “Evolution of script kiddies.” And yeah, for sure, back on the, the ransomware s- thing, that’s definitely what we’re seeing. You know, it’s, uh, interesting 'cause I get asked a lot when I’m talking about, um, North Korean campaigns, you know, how much we’re seeing in terms of indicators of AI usage.
[00:12:46] Jenn Gile: I just got it, you know, asked again a couple days ago and we just… I mean, certainly they’re using AI. Any serious developer, I don’t know if anyone’s gonna take a- offense to that, but honestly, everyone’s using AI in their development now. Uh, so of course they’re using it, but it’s the difference between, uh, enabling faster iteration and, um, infrastructure automation versus what we see with the ransomware groups is giving them the ability to do something that they would not have been able to do otherwise.
[00:13:20] Paul McCarty: Yeah. And bringing patterns, development patterns to, you know, neophyte, um, threat actors. Um, a, a really good example is, is the fact that we’ve just seen this increase in binary based open source malware whose… Oh, my dad’s calling me. Um-
[00:13:38] Jenn Gile: Well, I guess I would say like we’ve seen a history of, um, China, for example, being very good at finding vulnerabilities in legacy products and then exploiting them.
[00:13:52] Jenn Gile: I think what we’re seeing with the North Korean hackers is, you know, in many cases they are finding vulnerabilities to get into these larger, uh, institutions, but I think a fair assumption is they’re probably able to find vulnerabilities easier by using LLMs. I’m sure, you know, as we see the whole- 100%, yeah
[00:14:15] Jenn Gile: you know, CVE explosion, uh- Yeah … would this Bitget compromise have been effective otherwise. Um, we don’t have a lot of details on exactly what was compromised, though from what you said, the, the internet verse is saying it might have been a security tool that was compromised.
[00:14:34] Paul McCarty: Well, it’s more than that. [00:14:35] Paul McCarty: It’s, it’s official. Um, because basically Bitget hired a well-known, um, crypto, uh, incident response team called SlowMist. I think they’re South Korean. Um- Mm. And there’s this whole ecosystem that a lot of people don’t realize, like this whole like incident responder stuff, is a lot of it is based in Southeastern Asia.
[00:14:54] Paul McCarty: But you’ve got Seal Alliance and you’ve got SlowMist and a bunch of others. But anyhow, SlowMist, uh, has already re- uh, uh, updated their first report, which is not long. It’s only a few pages. But, um, basically what it says is that DPRK used a zero-day in an, a yet un- uh, they haven’t released the name of it, but it’s in a security product.
[00:15:16] Paul McCarty: Um, now I’m gonna say I have a little bit of inside baseball here and I can… You know, it’s not official yet, so I don’t wanna like get myself sued, but, but I, I think what we’re looking at here is I think we’re looking at an exploit in one of these, um, kind of zero trust VPN tools. I’m, I’m not gonna say any names.
[00:15:37] Paul McCarty: But, um, I, that’s my understanding. Um, and we’ll see when, when eventually that, that comes out. But basically they found a zero-day and then they used that to exploit it. Um, and they, they stole, um, crypto. It w- it was, uh, in an unusual way in the sense that inside of the Bitget platform, when customers logged in, they still saw all of their assets in their account.
[00:15:59] Paul McCarty: But those assets- Right … had been drained. And so there was obviously, you know, some Uh, disconnect between what the customer was seeing and what was actually happening on, on the, uh… And it was only their it was their hot and warm wallets, not cold wallets. So I’m like, “Okay, so those are the most important wallets.”
[00:16:19] Paul McCarty: But anyhow, um, uh, more details to come, uh, but I suspect it was in one of these zero tier kind of VPN replacement tools.
Signed Mac malware posing as Claude Desktop #
[00:16:28] Jenn Gile: Okay. Well, let’s move on to, uh, a more close to home topic. You’re seeing a really successful Mac campaign dropping. Um, we don’t see- Yeah … a ton of, uh, OS targeting malware in our space often.
[00:16:46] Jenn Gile: Not, I won’t say not a ton, but like often the threat actors make an effort to make it multi OS, so it’s a little unique that it’s Mac only. But as you and I have seen, uh, most software developers are using Macs, so not a huge surprise that they might decide to invest specifically in Mac, Mac attack, Mac malware.
[00:17:06] Jenn Gile: So what are you seeing? [00:17:07] Paul McCarty: Mac attack. Um, good intro. Yeah, so, um, we’ve seen this kind of increase in Mac related ClickFix and our friends at Jamf are all over this. They’re doing so much great research in this space, and in fact, I got, um, I got heads up on this latest evolution from them. Um, I asked if it was okay to talk about it too as well.
[00:17:28] Paul McCarty: But um, basically, uh, there’s a bunch of Mac or, uh, OS specific ClickFix stuff, and then a new website came out, um, claude-desktop.com, and it’s still up, still serving out a DMG. The DMG is about, I think it’s 210 megs. It’s big.
[00:17:44] Jenn Gile: Um- Oh, that’s interesting. After we talked about it a couple weeks ago, I looked at it and it was down, so.
[00:17:49] Paul McCarty: Yeah, it’s back, homie. It’s back. Mm. It’s back. Um, and they’ve changed the backend a little bit, but, um, one of the reasons that we are particularly interested in, in this stuff, um, because it’s not typically soft supply chain and malware related, is that on the back end now most of the time it’s being hosted on GitHub.
[00:18:06] Paul McCarty: Um, hey GitHub, you’re becoming the world’s biggest hosting provider for malware. Good job. Um, but yeah, um, but- And that’s exactly what we saw. And the interesting thing now is we’ve seen overlap now behind… So basically, once you get behind the first stage, oftentimes now there’ll be some overlap between some of the infrastructure and these ClickFix or, um, or this new evolution, which I’ll talk, talk about here in a second, and software supply chain st- stuff, like the second and third stage will start to overlap.
[00:18:37] Paul McCarty: Now, now here’s what’s interesting about this latest one, claude-desktop.com. It’s serving out a DMG that is signed. This is an installer. It’s not ClickFix. This is an installer. It looks, and it, and I think it actually is, if I’m not correct, it actually is the Claude installer, but with some extra things, a big padded, uh, extra bit that delivers the payload.
[00:18:57] Paul McCarty: Um, we’ll have a write-up about it. Um, Jamf has done some, some great work in this space, but, um, I think that’s an important thing. This is signed, so when you install it, your macOS is like, “Oh, yeah, sure. No worries. Go ahead and install it,” right? Now, I think since then Apple has killed this particular, um, uh, partner.
[00:19:17] Paul McCarty: Um, so I think now if you try to install it, you will get an error. I haven’t actually tried that today, but, um, this is evidence of, you know, the, the evolution, the constant evolution of this. The website is sexy. The DMG, the DMG looks great. If you don’t know, the actual size of a real Claude DMG is about 50 megs.
[00:19:35] Paul McCarty: This one’s four times the size. Um, we will have file hashes and all the information up on, um, OSM promptly.
Baileys campaign tops 100 packages #
[00:19:43] Jenn Gile: Nice. Okay. Uh, a campaign I’ve been keeping an eye on this week that we talked about in brief last week is one that’s hitting the Baileys ecosystem. Uh, this is really different from what we usually see.
[00:19:59] Jenn Gile: So it’s not… It doesn’t include a RAT or, um, info stealer or any of the, like, really concerning pieces of malware. What it does instead, there’s hundreds of these packages out there, um, we’re classifying them as malicious, but the actual risk to the user is low because what these packages are doing is they’re being used to artificially inflate follower count for WhatsApp channels.
[00:20:30] Jenn Gile: So, uh, if I have a WhatsApp channel and I wanna increase my followership, basically I can pay these threat actors. Unclear if the people paying for this know that it’s being done in a sketchy way. Um, but then the threat actors are spewing out all these, um, copies of a, like an acceptable well-known Baileys package and packages that have this little component in them
[00:21:02] Paul McCarty: Yeah. [00:21:03] Paul McCarty: Yeah, and the vast majority of it, like you say, um, you know, is just about inflating your follower count. But when you ingest those, um, what are they called? They’re called newsletters. When you ingest those newlet- newsletters, it does lead to, you know, to other attacks too as well. So we’ve seen, you know, C2, WhatsApp-based C2, and o- other kind of attacks built on top of this.
[00:21:26] Paul McCarty: So we can’t… While it, at its heart, most of it, like you say, is, you know, malicious but not super impactful, um, you know, if you are using… If, if you’re in this ecosystem, if you’re, if you need to talk to the WhatsApp API and you’re using, um, the WhiskeySockets and Baileys libraries, you know, just be aware 'cause there’s just a bazillion of these.
[00:21:47] Paul McCarty: Uh, there is a bazillion of them. And the problem now too is that all the malicious detection tools are all, like, spun out, like, “Oh, we need to find all these Bailey things.” So now I’m seeing legitimate Baileys libraries that people just-
[00:22:00] Jenn Gile: Mm … [00:22:00] Paul McCarty: forking their own and adding it are now getting labeled as malicious when, in fact, they’re not.
[00:22:04] Paul McCarty: Um, so, you know, the vast majority, just to be clear, are malicious, so I’m not saying this is a huge problem. But, um, uh, yeah, and OX came out with a really good article, um, talking about- Yeah, they did a nice
[00:22:18] **Jenn Gile:** job … how many
[00:22:19] **Paul McCarty:** they found. They found, like, 100, I think.
[00:22:20] **Jenn Gile:** I think so, yeah.
[00:22:22] **Paul McCarty:** Yeah, Moshe and his, his team do a great job over at OX.
[00:22:25] Paul McCarty: Um, I wish they would reboot the, um, the OSC&R, um, Matrix, but anyhow, um, uh, those guys do a great job.
PolinRider A/B tests its way past detections #
[00:22:33] Jenn Gile: Yeah. Okay, last topic, unless we get any questions coming in, is some, uh, DPRK research I did last week into this week. So I started noticing maybe two weeks ago, um, that the fake font trick they’ve been using for all of this year, back into last year, uh, that they had started changing the file name.
[00:22:58] Jenn Gile: So for the longest time, it’s been fa-solid-400.woff2. Um, pretty much every example of this that we saw was pointing at that particular file. So this is the task’s, uh, auto-run attack vector, where it auto-runs that file. That file is not actually a font. It contains obfuscated JavaScript that delivers some lovely malware to your machine.
[00:23:27] Jenn Gile: So what I’ve been, uh, noticing is they changed it from 400 to either 500, or more recently I started seeing 900. And I was like, “Well, that’s an interesting choice.” Clearly they know that people are looking for it by file name and- Right … decided if we change it by a digit, they won’t catch it anymore, which is true Gotta hand it to them.
[00:23:51] Jenn Gile: Which is- That’s a, a stupid but smart way to get around, uh, a common detection that we’re, you know, seeing people use.
[00:23:59] Paul McCarty: Well, in, in general, I see this all the time because we’re gonna GitHub and we do these searches and basically, you know, initially all we saw was just, like, the malicious versions, and then really quickly we saw all these people writing detections, like clear detection engineering.
[00:24:10] Paul McCarty: But here’s a shout-out to y’all that are making your detection engineering. If you use very specific static search mechanisms, right? Like, um, solid dash, uh, fa-solid-400.woff2, if you only look for that file and DPRK or the threat actor changes that, you’re gonna miss it. That’s what Jennifer was saying here, right?
[00:24:30] Paul McCarty: Um, and that’s exactly what they’ve done because you can see when you go to the public GitHub, you
[00:24:36] **Jenn Gile:** see lots of- Well, it’s not just that. So there’s more, right?
[00:24:38] **Paul McCarty:** Yeah, yeah.
[00:24:39] Jenn Gile: There is, yes. Um, they’re changing the name of the file. The second variation that I found, or you found, I think, late last week was, um, they’re changing the location of the file.
[00:24:49] Jenn Gile: So it used to be, and probably still to some extent, the malware when it was, you know, force pushing into these repos, uh, you know, the tasks file in VS Code gets pushed up, and then the second thing is a top level folder that’s public/fonts, and that’s where all the fake fonts live. So very, very easy to, like…
[00:25:10] Jenn Gile: The second you look at your top levels in GitHub, you’re like, “Oh, where did that come from?” So what have they done? They, uh, have figured out how to plant that folder deep within a legit folder. So I’ve seen lots of different examples of this. Um, they’re not creating a folder from scratch, they’re taking something that’s already in the repo.
[00:25:30] Jenn Gile: So if you’re, again, looking- Uh, you know, visually at the top level or I would assume, you know, running some kind of a top level does this have public fonts at the top, uh, this also is meant to bust detections, right?
[00:25:46] Paul McCarty: That’s exactly right. Yeah, 10-4. Um, yeah, they also are… And by the way, you know, I originally wrote the first blog post about this back in like November of last year when I, when I hit the TasksJacker, um, campaign, so this is even before PolinRider.
[00:26:03] Paul McCarty: Um, and some of those original things, so between November and like March there was like, I don’t know, four or five different sub variants of those. Some of those sub variants haven’t, have been totally, you know, not used over the last four or five months. Well, they’re coming back. Mm. A really good example is for a while there they were using fake dictionary files, .dic files.
[00:26:24] **Jenn Gile:** I’ve seen a couple of those. Yeah.
[00:26:25] **Paul McCarty:** Yeah. And
[00:26:27] Jenn Gile: I’m looking at one- So the other one that I found just on Monday, I was like typing up my social post to share this research and my agent was like, “Hey, do you wanna include this thing where there’s like now a .llf file variation?” And I was like, “Wait, what?” Wait, what?
[00:26:44] Jenn Gile: “Do what? Tell me more.” 'Cause it was keeping an eye on a repo that I was researching, and sure enough in the time between when I had published a blog on Friday night to, uh, Monday morning, you know, writing the social, uh, the repo had been force pushed overwritten again so that they, um, changed the file type.
[00:27:04] Jenn Gile: And so what you should know is a .llf is not a font file, it’s this super obscure file type. Uh, you know, some extent might be used in gaming. There’s a couple other use cases, but literally has nothing to do with fonts. So, uh, again, they’re keeping the front of the file name basically the same. So fa-solid-fill in a number.
[00:27:27] Jenn Gile: The one that I saw was 300, but instead of .woff2 it’s a .llf Um, really smart way to evade detection. Uh, when we looked for it on Monday, I think you said there were over 100 versions already on GitHub, right?
[00:27:47] Paul McCarty: Yeah. It’s, it’s… Um, I just found 120. Now, GitHub’s search API, as, as many of you might know, is terrible at giving you actual numbers.
[00:27:56] Paul McCarty: So I’m seeing 127 of these using the LLF file format and suffix. I would suspect the number is much higher than that, so.
[00:28:04] Jenn Gile: Yeah. And especially, like, keep in mind, that’s just searching public repos. That’s not searching- Correct … private. So we can make an assumption on all these numbers, but you said you did some updates to our detections, found another 8,000 or so compromised repositories.
[00:28:22] Jenn Gile: We have over 10,000 in the database right now, which puts us pushing 20,000, which is crazy.
[00:28:31] **Paul McCarty:** Yeah. Well, there’s gonna be some- Like, mind-boggling to
[00:28:33] **Jenn Gile:** us …
[00:28:34] Paul McCarty: sorry, there should, I should have been more explicit. There… Th- those 8,000 new ones, there’s gonna be significant overlap between those and-
[00:28:40] Jenn Gile: Ah, you’re right [00:28:41] Jenn Gile: what we already had 'Cause they would be potential reinfection or continuing. Which is just- Regardless,
[00:28:45] **Paul McCarty:** it’s
[00:28:45] **Jenn Gile:** a lot …
[00:28:46] Paul McCarty: just is often just the same file. So- Yeah … like, literally it’s just the same repo. So we’ve already found it. But part of that, because we’re getting so many of these now, and because the API is so slow and rate limits you so quickly, basically it makes the whole hunt really…
[00:29:00] Paul McCarty: By like- After, after I become a millionaire from, a multimillionaire from OSM, the first thing I’m gonna do is I’m gonna go and build a, a replacement for GitHub that has a proper search API. I, like, I… If I… I, I would die happy, Jenn, knowing that people can search their SCM provider and be able to find all the examples of, of things, right?
BSides Canberra recap #
[00:29:21] Paul McCarty: But anyhow, um, hey, this is a good segue to talk about Canberra BSides. I’m going off script here, but I don’t care.
[00:29:27] Jenn Gile: Um- No, go for it. We’ve got time. [00:29:30] Paul McCarty: Cool. If you took my class on Saturday, which was all day, by the way, this was a, a long training, um, it was all, like, detection engineering stuff in GitHub. We specifically talked about, you know, these static, uh, detection signatures, things like that path that Jenn was talking about, public/fonts, and then looking for those files.
[00:29:49] Paul McCarty: But then also ways to l- use wild carding and some of the things that the search API does give you in GitHub, but also other techniques to find these things in a more, in a broader kind of way, which means that you have to, like, slice by file name and because there’s, like, a 1,000 character limit, or sorry, 1,000 search limit, and then there’s a 4,000 search limit depending on what you’re doing, all this other stupid stuff.
[00:30:09] Paul McCarty: But anyhow, we talked about that in my ch- at length in my training, and I’m wearing… I honestly think this is one of the dopest shirts. Like, this is one of the best. Kylie and, and Silvio did a great job with this year’s… I mean, the whole conference was great, but, like, the swag this year was just, um, next level.
[00:30:27] Paul McCarty: We’re, we’re big Tron fans here in, in my family, and, um, and the mini-mes got some swag this year, so they’re, they’re happy.
[00:30:35] **Jenn Gile:** Yeah. You got some great swag from them. And, oh, and Matt.
[00:30:38] **Paul McCarty:** Yeah, and Matt w- who just came in, and Matt was in my class and so, so shout out to Matt.
OpenSourceMalware is hiring #
[00:30:44] Jenn Gile: Yeah. Well, um, I think the thing to end on is a heads-up to the community. [00:30:49] Jenn Gile: We are hiring. We’re really excited about this. Uh, we’re looking to bring on a part-time malware researcher. So if you are, uh, looking for some part-time work at this point or if you know someone who’s got software supply chain malware experience who might wanna do a little work in this space, um, head on over to our LinkedIn.
[00:31:09] Jenn Gile: We’ve posted about it. Don’t contact us directly, please. We get lots of crazy DMs. Uh, no recruiters also, please. Um, but we would love to hire someone from the OSM community. That would be exciting.
[00:31:21] Paul McCarty: Yeah, I would love to… Yeah. What you said. I would love to see- Yeah … would love to see that. Um, we got, we got the best swag in the biz.
[00:31:31] **Jenn Gile:** All right. On that note, let’s wrap.
[00:31:34] **Paul McCarty:** Thanks, everyone for listening. Really appreciate it. See ya.