Live data from Hacker News

How the “Kim” dump exposed North Korea's credential theft playbook

dti.domaintools.com

101–110 of 196 posts

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#101
post #92
post #76

Earlier quoted context omitted.

In the initial era of the split between North and South Korea, South Korea both was run by a bunch of people who had a history of outright killing leftists, and the United States was involved in similar actions. The lack of serious offramps to reunification, along with not as huge a delta in quality of life between north and south for a long time (aid from other countries sure helps!), allowed the DPRK to establish i…

> see the painful experience of Germany's unification I had thought that Germans from both sides were overwhelmingly supportive of re-unification, even if it would cause short-term pain??

It's my understanding there were plenty of USSR nostalgics in the east given how long it took for the free market to "trickle down" and the east to catch up economically. They never did catch up all the way anyway.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#102

Earlier quoted context omitted.

State sponsored thieves are not a talent pool that anyone wants in a trusted position. The fact is there were only around 40 unique hacks ever invented, and people simply adapt these into new zero day exploits. Notably, this is now mostly a fully automated process. If people want in, they will get in eventually. =3 x C62=:K6 J@F 2C6 AC66>AE:G6=J 5:D28C66:?8 H:E9 E96 DFCAC:D:?8=J =@H 6DE:>2E6 @7 6IA=@:E E2I@?@>J[ 3FE…

> State sponsored thieves are not a talent pool that anyone wants in a trusted position Why? They’re intelligent, crafty and able to make trade-offs. Empirically, ex-spies have a solid history in reaching commanding positions in politics and business.

It is complicated, but Moral Development theory does cover the phenomena of why some won't understand until they personally grow through the stages of development.

Have a great day. =3

https://en.wikipedia.org/wiki/Lawrence_Kohlberg's_stages_of_...

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#103
post #53

Earlier quoted context omitted.

Anything happens to North Korea and all those starving people flood into China. I think that’s why China supports North Korea.

China did not, and still doesn't, want US troops at its border. That's why it originally intervened and why it supports North Korea. At the time there was also a further risk that the US might invade China.

That doesn't have to be the result of it. A more humane regime in NK doesn't mean reunification has to happen. And, part of the reason those US forces are in South Korea is the threat of the North. By threatening US involvement in case of an attack.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#104

Earlier quoted context omitted.

Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well

While that may be true, it’s less true for things like cobalt strike. I’m not saying that banning tooling would be a good thing, but it’s a bad argument to compare Nmap to remote access tools.

Cobalt strike is just an automated script kiddie really. It's a way for red teamers to catch low hanging fruit. And because of that, there's not so much low hanging fruit anyway.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#105
post #35

> The leaked dataset attributed to the “Kim” operator offers a uniquely operational perspective into North Korean-aligned cyber operations. It's puzzling why the NORC hackers didn't use a nearest neighbor hack rather than leaving a trail of bread crumbs all the way back to Pyongyang ;)

Sometimes sending a message is part of the point. And you still have plausible deniability anyway "it was a false flag booo".

The Russians do this a lot. This kind of attack that they want everyone to know they are being without telling you they are behind it and denying it in all colours.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#106
post #4

Earlier quoted context omitted.

They are heavily used in penetrationtests and red teaming engagements. Banning such tools from the public just mystifies attackers ways to defenders, while not in any way hindering serious malicious actors. We had that discussion back in the 90s and early 2000s.

Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well

It's mainly beside nmap detection is a feature of most IDS so it's bound to raise some red flags.

Same with even doing packet sniffing. It can be detected when using wireshark because it does reverse DNS lookups for each ip it sees in its default configuration.

I had legit reasons for it at work so I always mentioned it to the network guys before ding stuff like this. We also had a firewalled lab network. We did get some pushback once when some scans leaked out to the office network. But it was their fault for having the firewall open.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#107
post #69

Earlier quoted context omitted.

If both counties sustain their current trajectories, in 50 years it will be NK re-populating and re-developing SK. And the "if" here is mainly about NK, chances of SK getting out of the death spiral are very thin.

I recently read/watched videos about the "population time bomb" in South Korea and how it's almost irreversible now. It really surprised me, it's one of those things that's hard to visualize. And it's not even long term!

They can always allow more immigration. National populations don't grow only by births.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#108
post #8

Earlier quoted context omitted.

I don't think Chinese support for NK has ever been a secret anymore than the the US support for South Korea has. And it's in China's backyardd so they've got way more of an excuse. And if you think that doesn't matter, look at the Monroe Doctrine [1]. Taken further, the so-called Cuban Missile Crisis should really be called the Turkey Missile Crisis. The US (through NATO) placed Jupiter nuclear MRBMs in Turkey, only…

Why is this comment downvoted? You have the right to see China, USSR and NK as immoral regimes but there's nothing non-factual here.

The causality between missiles in Turkey causing the Cuban Missile Crisis is unsubstantiated by historical facts from the Soviets own perspectives.

It's more that Cuba requested nukes first, the USSR opportunistically took, then they to resolve the crisis they took that opportunity to remove Turkish missiles. It wasn't really a tit for tat on part of the USSR's intentions, Cuba was the primary agent here.

Not that it really mattered later on once ICBMs are developed.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#109
post #32
post #12

Earlier quoted context omitted.

[flagged]

That is fucking insane. Basically Linux itself would be classified as a "hacking tool".

Well we are heading in that direction anyway. With software platforms getting more locked down. Having a rooted phone now is already enough to get banned from bank apps because you're not in the comfortable fluffy death grip of Google.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#110

Earlier quoted context omitted.

The topic is cybercrime and espionage, not nuclear brinksmanship or colonialism. Whatever parallels can be drawn don't seem to be very relevant, so the comment comes off as an attempt to deflect criticism.

It was still a fascinating aside, and it's not like HN stays on topic in a thread. I learned something today.

I do wonder what's the state of history education today when one only learns a basic history event today, and through a layman's forum post which is surely going to have all the complete perspective as opposed to setting out an explicit agenda.
Post reply on HN