Live data from Hacker News

How the “Kim” dump exposed North Korea's credential theft playbook

dti.domaintools.com

41–50 of 196 posts

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#41

Earlier quoted context omitted.

Why is this comment downvoted? You have the right to see China, USSR and NK as immoral regimes but there's nothing non-factual here.

The topic is cybercrime and espionage, not nuclear brinksmanship or colonialism. Whatever parallels can be drawn don't seem to be very relevant, so the comment comes off as an attempt to deflect criticism.

> The topic is cybercrime and espionage, not nuclear brinksmanship or colonialism.

Those are all closely related topics in geopolitics.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#42
post #4

Earlier quoted context omitted.

They are heavily used in penetrationtests and red teaming engagements. Banning such tools from the public just mystifies attackers ways to defenders, while not in any way hindering serious malicious actors. We had that discussion back in the 90s and early 2000s.

Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well

one time i ran nmap against my dev box at facebook. i was definitely worried someone was going to give me a stern talking to.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#43
post #31
post #25

I’ve heard that in North Korea it is difficult for ordinary people to learn or own a computer. It is assumed that a small number of elite operatives are selected and trained to carry out such tasks, and it is somewhat surprising that they possess the latest technology and conduct hacking.

If anything the hackers in north korea are probably world class if the government is getting their students into focused training programs early in their schooling. Western nations have nothing equivalent due to schooling being generalist and undergrad and grad school not really introducing you to the sort of work you'd actually do on the job as a hacker. 22 year old western hacker for a 3 letter agency is going to h…

> 22 year old western hacker for a 3 letter agency is going to have maybe a 6 month softball tangentially related internship of experience under their belt while the north korean might have years and years by that point.

I was with you right up until this bit

The agencies concerned tend to recruit people that have demonstrated ability in that field, and they've usually got it with "self-directed" training :)

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#44
post #25

I’ve heard that in North Korea it is difficult for ordinary people to learn or own a computer. It is assumed that a small number of elite operatives are selected and trained to carry out such tasks, and it is somewhat surprising that they possess the latest technology and conduct hacking.

North Korean teams tend to perform very well in coding contests, so it’s a safe bet that North Korea is quite good at nurturing a small slice of elite computing talent.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#45
post #39
post #37

Earlier quoted context omitted.

Regardless of how unhappy Beijing may be with things Pyongyang does, North Korea is of such obvious strategic importance to China that they are unlikely to ever waver in their support of the regime or even try to hide it.

What's surprising about this? It's not dissimilar to how the US behaves towards their less than savory strategic allies (or, historically, towards dictatorships as long as they were US-aligned).

Not saying it should be surprising. Just trying to answer the question.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#46
post #26

Earlier quoted context omitted.

[flagged]

You better edit the Wikipedia article to remove the propaganda. According to that, since Roosevelt the Monroe doctrine has been repurposed for hegemony in the Western Hemisphere: Starting at https://en.wikipedia.org/wiki/Monroe_Doctrine#Roosevelt_Coro... and further.

It is clear through any remotely honest reading of history that hemispheric hegemony was the whole point since Monroe. If you go back and read the speeches and literature from ~200 years ago from the time of Monroe it is pretty explicitly stated.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#47
post #12

Earlier quoted context omitted.

[flagged]

Wait, installing nmap on your laptop from a Linux distribution's repositories is a crime in Germany?

No, OP loves to claim almost daily how nearly everything is illegal in Germany, and never provides any sources or court cases when asked for proof, just "google it yourself" or "the German criminal code".

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#48
post #3

> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

Isn't Github supposed to be blocking sanctioned countries, like Iran, and North Korea?

https://docs.github.com/en/site-policy/other-site-policies/g...

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#49

That's a fairly detailed analysis of an APT workflow. Now, non-APT actors, if they wanted to up their level of sophistication, might replicate some of these workflows for their own nefarious activities.

There's always a risk of openness creating copycats, but there's also the fact that informed decisions can now be made by people who need to mitigate against these malicious actors.

There's no way to only give the information to one group without the other group getting their hands on it.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#50
post #23

Earlier quoted context omitted.

>Not sure about US law, but in Germany, creating or possessing a hacking tool (including things like nmap) is a criminal offence. Surely that must be wrong, are security certs not a thing in Germany?

Unfortunately that's true: https://www.gesetze-im-internet.de/englisch_stgb/englisch_st...

Hard disagree, I think there is very important context missing here, notably:

> 2. computer programs for the purpose of the commission of such an offence

Big huge emphasis on "for the purpose of", meaning there must be clear intent to cause harm or break the law, especially for a criminal case. This assumes the purpose of the program is not inherently for hacking/criminal purposes, which I do not believe would be hard to argue that nmap is not designed as a "hacking tool".

Germany appears to have a similar standard to US criminal cases where you are presumed innocent until proven guilty "beyond a reasonable doubt": https://law.stackexchange.com/questions/40966/innocent-until...

Post reply on HN