Live data from Hacker News

How the “Kim” dump exposed North Korea's credential theft playbook

dti.domaintools.com

1–10 of 196 posts

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#3
> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs.

What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#4
post #3

> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

They are heavily used in penetrationtests and red teaming engagements. Banning such tools from the public just mystifies attackers ways to defenders, while not in any way hindering serious malicious actors. We had that discussion back in the 90s and early 2000s.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#5
post #3

> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

I think they get heavily used by security researchers, and other people that do regular Penetration Testing.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#6
This is interesting due to the tying of DPRK and PRC. It seems hard to say how much coordination there is between the two, but whatever it is, it appears to be greater than zero. While not necessarily surprising, I wonder if this public attribution will make it harder for the PRC to deny involvement with both the DPRK's efforts and their own.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#7
post #3

> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?

What alternative do you suggest?

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#8
post #6

This is interesting due to the tying of DPRK and PRC. It seems hard to say how much coordination there is between the two, but whatever it is, it appears to be greater than zero. While not necessarily surprising, I wonder if this public attribution will make it harder for the PRC to deny involvement with both the DPRK's efforts and their own.

I don't think Chinese support for NK has ever been a secret anymore than the the US support for South Korea has. And it's in China's backyardd so they've got way more of an excuse.

And if you think that doesn't matter, look at the Monroe Doctrine [1].

Taken further, the so-called Cuban Missile Crisis should really be called the Turkey Missile Crisis. The US (through NATO) placed Jupiter nuclear MRBMs in Turkey, only hunddreds of miles from Moscow. The USSR responded by doing the exact same thing, by placing nuclear weapons in Cuba. And the US almost started World War 3 over it.

It was the USSR who stepped back from the brink and, as a result of a secret agreement, the Jupiter MRBMs were quietly removed from Turkey [2].

[1]: https://en.wikipedia.org/wiki/Monroe_Doctrine

[2]: https://www.wilsoncenter.org/blog-post/jupiter-missiles-and-...

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#9
post #8
post #6

This is interesting due to the tying of DPRK and PRC. It seems hard to say how much coordination there is between the two, but whatever it is, it appears to be greater than zero. While not necessarily surprising, I wonder if this public attribution will make it harder for the PRC to deny involvement with both the DPRK's efforts and their own.

I don't think Chinese support for NK has ever been a secret anymore than the the US support for South Korea has. And it's in China's backyardd so they've got way more of an excuse. And if you think that doesn't matter, look at the Monroe Doctrine [1]. Taken further, the so-called Cuban Missile Crisis should really be called the Turkey Missile Crisis. The US (through NATO) placed Jupiter nuclear MRBMs in Turkey, only…

Why is this comment downvoted? You have the right to see China, USSR and NK as immoral regimes but there's nothing non-factual here.

Re: How the “Kim” dump exposed North Korea's credential theft playbook

#10
post #8

Earlier quoted context omitted.

I don't think Chinese support for NK has ever been a secret anymore than the the US support for South Korea has. And it's in China's backyardd so they've got way more of an excuse. And if you think that doesn't matter, look at the Monroe Doctrine [1]. Taken further, the so-called Cuban Missile Crisis should really be called the Turkey Missile Crisis. The US (through NATO) placed Jupiter nuclear MRBMs in Turkey, only…

Why is this comment downvoted? You have the right to see China, USSR and NK as immoral regimes but there's nothing non-factual here.

The topic is cybercrime and espionage, not nuclear brinksmanship or colonialism. Whatever parallels can be drawn don't seem to be very relevant, so the comment comes off as an attempt to deflect criticism.
Post reply on HN