Live data from Hacker News

How the “Kim” dump exposed North Korea's credential theft playbook

dti.domaintools.com

61–70 of 196 posts

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#61
post #44
post #25

I’ve heard that in North Korea it is difficult for ordinary people to learn or own a computer. It is assumed that a small number of elite operatives are selected and trained to carry out such tasks, and it is somewhat surprising that they possess the latest technology and conduct hacking.

North Korean teams tend to perform very well in coding contests, so it’s a safe bet that North Korea is quite good at nurturing a small slice of elite computing talent.

They just identify talented individuals and send them to schools in China or elsewhere to learn the latest tech.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#62
post #25

I’ve heard that in North Korea it is difficult for ordinary people to learn or own a computer. It is assumed that a small number of elite operatives are selected and trained to carry out such tasks, and it is somewhat surprising that they possess the latest technology and conduct hacking.

> somewhat surprising that they possess the latest technology and conduct hacking.

Why does this surprise you? As you said, selecting capable people is not a problem. And then these capable people get the best possible motivation. I would say it is expected to get qualified hackers in such conditions, who are proficient in all latest technologies.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#63
post #54

Earlier quoted context omitted.

Surely then it's the 'use', not the 'possession' that's a criminal offence? Or is it still a criminal offence to possess it, but you're fine as long as no one finds out? Because that doesn't stop it being a criminal offence.

My basic understanding is that a 'dual use' tool is moreso based on intent; using the same analogy as when this came up on HN over a decade ago [0], a good kitchen knife can be at least as dangerous as a lot of explicitly 'banned' knives but because it has a non-illegal use it doesn't fall into the same category as, say, a DDOS tool. And AFAIK there hasn't (yet) been a case where NMAP has gotten someone in Germany in…

This might be akin to lockpicks in the United States. Not illegal in and of themselves, but if you are possessing them with intent, it's a different matter.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#64
post #3

> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

Isn't Github supposed to be blocking sanctioned countries, like Iran, and North Korea? https://docs.github.com/en/site-policy/other-site-policies/g...

About Iran & GitHub:

https://docs.github.com/en/site-policy/other-site-policies/g...

    > GitHub now has a license from OFAC to provide cloud services to developers located or otherwise resident in Iran. This includes all public and private services for individuals and organizations, both free and paid.

    > GitHub cloud services, both free and paid, are also generally available to developers located in Cuba.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#65

Earlier quoted context omitted.

Agreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well

While that may be true, it’s less true for things like cobalt strike. I’m not saying that banning tooling would be a good thing, but it’s a bad argument to compare Nmap to remote access tools.

I don't disagree, but GP is asking about all offensive tools, not just Cobalt strike. IMHO a platform like GitHub should not be picking and choosing which projects are offensive enough to remove. Yes, there are some tools that are pretty clearly more offensive than others, but creating a policy would not be clear-cut

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#66
post #53
post #37

Earlier quoted context omitted.

Regardless of how unhappy Beijing may be with things Pyongyang does, North Korea is of such obvious strategic importance to China that they are unlikely to ever waver in their support of the regime or even try to hide it.

Anything happens to North Korea and all those starving people flood into China. I think that’s why China supports North Korea.

I mean, same could be said about South Korea. It would instantly drag their GDP per capita down by more than half, and that's not even counting how much money would need to be spent to re-develop NK.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#67
post #66
post #53

Earlier quoted context omitted.

Anything happens to North Korea and all those starving people flood into China. I think that’s why China supports North Korea.

I mean, same could be said about South Korea. It would instantly drag their GDP per capita down by more than half, and that's not even counting how much money would need to be spent to re-develop NK.

Genuine question that I'm trying to learn about - the industrialisation of Japan and South Korea led to huge wealth creation and increases in quality of living. I know some of that is stagnating now and especially in South Korea things are difficult, but why isn't North Korea ever spoken of in those terms rather than always the GDP hit to South Korea?

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#68
post #66
post #53

Earlier quoted context omitted.

Anything happens to North Korea and all those starving people flood into China. I think that’s why China supports North Korea.

I mean, same could be said about South Korea. It would instantly drag their GDP per capita down by more than half, and that's not even counting how much money would need to be spent to re-develop NK.

If both counties sustain their current trajectories, in 50 years it will be NK re-populating and re-developing SK. And the "if" here is mainly about NK, chances of SK getting out of the death spiral are very thin.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#69
post #66

Earlier quoted context omitted.

I mean, same could be said about South Korea. It would instantly drag their GDP per capita down by more than half, and that's not even counting how much money would need to be spent to re-develop NK.

If both counties sustain their current trajectories, in 50 years it will be NK re-populating and re-developing SK. And the "if" here is mainly about NK, chances of SK getting out of the death spiral are very thin.

I recently read/watched videos about the "population time bomb" in South Korea and how it's almost irreversible now. It really surprised me, it's one of those things that's hard to visualize. And it's not even long term!

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#70
post #44

Earlier quoted context omitted.

North Korean teams tend to perform very well in coding contests, so it’s a safe bet that North Korea is quite good at nurturing a small slice of elite computing talent.

They just identify talented individuals and send them to schools in China or elsewhere to learn the latest tech.

source? interesting if true.
Post reply on HN