That's a fairly detailed analysis of an APT workflow. Now, non-APT actors, if they wanted to up their level of sophistication, might replicate some of these workflows for their own nefarious activities.
There's always a risk of openness creating copycats, but there's also the fact that informed decisions can now be made by people who need to mitigate against these malicious actors. There's no way to only give the information to one group without the other group getting their hands on it.
How the “Kim” dump exposed North Korea's credential theft playbook
51–60 of 196 posts
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#52This is interesting due to the tying of DPRK and PRC. It seems hard to say how much coordination there is between the two, but whatever it is, it appears to be greater than zero. While not necessarily surprising, I wonder if this public attribution will make it harder for the PRC to deny involvement with both the DPRK's efforts and their own.
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#53This is interesting due to the tying of DPRK and PRC. It seems hard to say how much coordination there is between the two, but whatever it is, it appears to be greater than zero. While not necessarily surprising, I wonder if this public attribution will make it harder for the PRC to deny involvement with both the DPRK's efforts and their own.
Regardless of how unhappy Beijing may be with things Pyongyang does, North Korea is of such obvious strategic importance to China that they are unlikely to ever waver in their support of the regime or even try to hide it.
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#54Earlier quoted context omitted.
Not really, so long as you don't use it for anything 'bad'. i.e. if you're just running against your local network, who's gonna report it?
Surely then it's the 'use', not the 'possession' that's a criminal offence? Or is it still a criminal offence to possess it, but you're fine as long as no one finds out? Because that doesn't stop it being a criminal offence.
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#55> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?
Isn't Github supposed to be blocking sanctioned countries, like Iran, and North Korea? https://docs.github.com/en/site-policy/other-site-policies/g...
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#56Earlier quoted context omitted.
Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well
one time i ran nmap against my dev box at facebook. i was definitely worried someone was going to give me a stern talking to.
It was just a summer internship and FB was like 'only' 80 engineers back then. But they still took it seriously.
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#57Earlier quoted context omitted.
Isn't Github supposed to be blocking sanctioned countries, like Iran, and North Korea? https://docs.github.com/en/site-policy/other-site-policies/g...
Do you have any reason to suspect GitHub isn't blocking those countries? How long do you think an offensive-security sponsor/passport-issuing nation might take to get around GitHub IP-blocks?
You could hypothetically make it work, but it would mean an extremely different Internet and device landscape than exists today. (And even then I doubt it stops a nation-state level attacker, they can always use old fashioned espionage to get someone in meat space and get around any technical barrier)
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#58Earlier quoted context omitted.
They are heavily used in penetrationtests and red teaming engagements. Banning such tools from the public just mystifies attackers ways to defenders, while not in any way hindering serious malicious actors. We had that discussion back in the 90s and early 2000s.
Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well
Re: How the “Kim” dump exposed North Korea's credential theft playbook
#59Earlier quoted context omitted.
Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well
one time i ran nmap against my dev box at facebook. i was definitely worried someone was going to give me a stern talking to.