How the “Kim” dump exposed North Korea's credential theft playbook
11–20 of 196 posts
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#12> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?
What alternative do you suggest?
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#13Unfortunately, it quickly turns into a discussion of how bad NK and China are and how China shouldn't support NK (because, again, they're bad).
I'll offer two words to expose the hypocrisy of this: Stuxnet, Pegasus.
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#14Re: How the “Kim” dump exposed North Korea's credential theft playbook
#15Earlier quoted context omitted.
What alternative do you suggest?
[flagged]
How do they even enforce it? Or is it just an extra law to throw at someone already convicted of something?
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#16Earlier quoted context omitted.
Why is this comment downvoted? You have the right to see China, USSR and NK as immoral regimes but there's nothing non-factual here.
The topic is cybercrime and espionage, not nuclear brinksmanship or colonialism. Whatever parallels can be drawn don't seem to be very relevant, so the comment comes off as an attempt to deflect criticism.
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#17> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?
They are heavily used in penetrationtests and red teaming engagements. Banning such tools from the public just mystifies attackers ways to defenders, while not in any way hindering serious malicious actors. We had that discussion back in the 90s and early 2000s.