Live data from Hacker News

How the “Kim” dump exposed North Korea's credential theft playbook

dti.domaintools.com

11–20 of 196 posts

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#12
post #3

> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

What alternative do you suggest?

[flagged]

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#13
So this is interesting from a technical perspective. Some of this infrastructure is used by pen testers and the likes, which just goes to show that there is no such thing as a defensive weapon. I'll let you ponder why that might be pertinent.

Unfortunately, it quickly turns into a discussion of how bad NK and China are and how China shouldn't support NK (because, again, they're bad).

I'll offer two words to expose the hypocrisy of this: Stuxnet, Pegasus.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#15
post #12

Earlier quoted context omitted.

What alternative do you suggest?

[flagged]

In the US you’re allowed to have pretty much whatever code you want on your computer, obviously excepting binary representations of illegal photo/video content.

How do they even enforce it? Or is it just an extra law to throw at someone already convicted of something?

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#16

Earlier quoted context omitted.

Why is this comment downvoted? You have the right to see China, USSR and NK as immoral regimes but there's nothing non-factual here.

The topic is cybercrime and espionage, not nuclear brinksmanship or colonialism. Whatever parallels can be drawn don't seem to be very relevant, so the comment comes off as an attempt to deflect criticism.

Maybe it wasn’t clear, but I think the comment is explaining the importance for superpowers of keeping their immediate surroundings politically aligned - china wants NK on their side for the same reason neither the US or the URSS wanted nukes on their doorstep.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#17
post #4
post #3

> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

They are heavily used in penetrationtests and red teaming engagements. Banning such tools from the public just mystifies attackers ways to defenders, while not in any way hindering serious malicious actors. We had that discussion back in the 90s and early 2000s.

Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#19
post #12

Earlier quoted context omitted.

What alternative do you suggest?

[flagged]

>Not sure about US law, but in Germany, creating or possessing a hacking tool (including things like nmap) is a criminal offence.

Surely that must be wrong, are security certs not a thing in Germany?

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#20
post #12

Earlier quoted context omitted.

[flagged]

Wait, installing nmap on your laptop from a Linux distribution's repositories is a crime in Germany?

Not really, so long as you don't use it for anything 'bad'. i.e. if you're just running against your local network, who's gonna report it?
Post reply on HN