11 ms·
How the “Kim” dump exposed North Korea's credential theft playbook
- huflungdung 1y ago[dead]
- tremon 1y ago> The dump also revealed reliance on GitHub repositories known for offensive tooling. TitanLdr, minbeacon, Blacklotus, and CobaltStrike-Auto-Keystore were all cloned or referenced in command logs. What's the rationale for allowing the development of offensive tooling on github? Is this a free-speech thing, or are these repositories relevant for scientific research in some way?
- StrauXX 1y agoThey are heavily used in penetrationtests and red teaming engagements. Banning such tools from the public just mystifies attackers ways to defenders, while not in any way hindering serious malicious actors. We had that discussion back in the 90s and early 2000s.
- freedomben 1y agoAgreed. Plus it's not always a clear line between offensive and legitimate usage. For many years nmap was banned on most corporate networks, but it's an invaluable tool for legitimate use too, despite being useful for offensive cases as well
- randall 1y agoone time i ran nmap against my dev box at facebook. i was definitely worried someone was going to give me a stern talking to.
- varenc 1y agoI ran 'neoprint.php' on myself at Facebook in 2007 and immediately got a stern email about it... It was some script that collected info for responding to law enforcement requests. But after chastising me, the email said "I was gratified that you ran it on yourself". (as opposed to snooping on someone else!) It was just a summer internship and FB was like 'only' 80 engineers back then. But they still took it seriously.
- Thorrez 1y agoI think that's a little different. It sounds like neoprint.php is an internal Facebook tool for looking up data on Facebook users. So improper usage of it is a privacy problem for users. It's something misbehaving employees might run against celbrities, exes, etc. (e.g. https://www.gawkerarchives.com/5637234/gcreep-google-engineer-stalked-teens-spied-on-chats https://www.gawkerarchives.com/5637234/gcreep-google-enginee... ) Otoh nmap isn't a privacy problem for users of Facebook (or any other tech company).
- varenc 1y agoYea totally agree. Mainly just wanted to shoehorn in my own story about stern emails at FB! Also I think running nmap on your own development machine is totally legitimate. Lots of reasons you might want to do it.
- SoftTalker 1y agoI use nmap routinely at work to see what’s on a subnet, has anything new appeared, or where it should not be.
- bravetraveler 1y ago+1. If I can't run nap or netcat, or have to justify it each time, I can't do my job. Better off elsewhere. I've departed early at least twice over this. Draconian IT serves nobody. Been doing this long enough I deliberately poke any new employer; see what's in store. Nobody cares, though. EDR appliances sell without careful administration. The industry will outlive us all.
- hsbauauvhabzb 1y agoWhile that may be true, it’s less true for things like cobalt strike. I’m not saying that banning tooling would be a good thing, but it’s a bad argument to compare Nmap to remote access tools.
- freedomben 1y agoI don't disagree, but GP is asking about all offensive tools, not just Cobalt strike. IMHO a platform like GitHub should not be picking and choosing which projects are offensive enough to remove. Yes, there are some tools that are pretty clearly more offensive than others, but creating a policy would not be clear-cut
- wkat4242 1y agoCobalt strike is just an automated script kiddie really. It's a way for red teamers to catch low hanging fruit. And because of that, there's not so much low hanging fruit anyway.
- wkat4242 1y agoIt's mainly beside nmap detection is a feature of most IDS so it's bound to raise some red flags. Same with even doing packet sniffing. It can be detected when using wireshark because it does reverse DNS lookups for each ip it sees in its default configuration. I had legit reasons for it at work so I always mentioned it to the network guys before ding stuff like this. We also had a firewalled lab network. We did get some pushback once when some scans leaked out to the office network. But it was their fault for having the firewall open.
- laveur 1y agoI think they get heavily used by security researchers, and other people that do regular Penetration Testing.
- traverseda 1y agoWhat alternative do you suggest?
- immibis 1y ago[flagged]
- rpdillon 1y agoWait, installing nmap on your laptop from a Linux distribution's repositories is a crime in Germany?
- to11mtm 1y agoNot really, so long as you don't use it for anything 'bad'. i.e. if you're just running against your local network, who's gonna report it?
- dwattttt 1y agoSurely then it's the 'use', not the 'possession' that's a criminal offence? Or is it still a criminal offence to possess it, but you're fine as long as no one finds out? Because that doesn't stop it being a criminal offence.
- to11mtm 1y agoMy basic understanding is that a 'dual use' tool is moreso based on intent; using the same analogy as when this came up on HN over a decade ago [0], a good kitchen knife can be at least as dangerous as a lot of explicitly 'banned' knives but because it has a non-illegal use it doesn't fall into the same category as, say, a DDOS tool. And AFAIK there hasn't (yet) been a case where NMAP has gotten someone in Germany in trouble with the law for possessing or using within their local subnet. [0] - https://news.ycombinator.com/item?id=3797151 https://news.ycombinator.com/item?id=3797151
- awesome_dude 1y agoIsn't Github supposed to be blocking sanctioned countries, like Iran, and North Korea? https://docs.github.com/en/site-policy/other-site-policies/github-and-trade-controls https://docs.github.com/en/site-policy/other-site-policies/g...
- overfeed 1y agoDo you have any reason to suspect GitHub isn't blocking those countries? How long do you think an offensive-security sponsor/passport-issuing nation might take to get around GitHub IP-blocks?
- dmoy 1y agoRight exactly. The only way IP blocks work is if there's no vulnerable machines to take over anywhere. That is - it basically doesn't work for any motivated attacker. You could hypothetically make it work, but it would mean an extremely different Internet and device landscape than exists today. (And even then I doubt it stops a nation-state level attacker, they can always use old fashioned espionage to get someone in meat space and get around any technical barrier)
- throwaway2037 1y agoAbout Iran & GitHub: https://docs.github.com/en/site-policy/other-site-policies/github-and-trade-controls https://docs.github.com/en/site-policy/other-site-policies/g... > GitHub now has a license from OFAC to provide cloud services to developers located or otherwise resident in Iran. This includes all public and private services for individuals and organizations, both free and paid. > GitHub cloud services, both free and paid, are also generally available to developers located in Cuba.
- sieabahlpark 1y ago[dead]
- sgnelson 1y agoThis is interesting due to the tying of DPRK and PRC. It seems hard to say how much coordination there is between the two, but whatever it is, it appears to be greater than zero. While not necessarily surprising, I wonder if this public attribution will make it harder for the PRC to deny involvement with both the DPRK's efforts and their own.
- jmyeet 1y agoI don't think Chinese support for NK has ever been a secret anymore than the the US support for South Korea has. And it's in China's backyardd so they've got way more of an excuse. And if you think that doesn't matter, look at the Monroe Doctrine [1]. Taken further, the so-called Cuban Missile Crisis should really be called the Turkey Missile Crisis. The US (through NATO) placed Jupiter nuclear MRBMs in Turkey, only hunddreds of miles from Moscow. The USSR responded by doing the exact same thing, by placing nuclear weapons in Cuba. And the US almost started World War 3 over it. It was the USSR who stepped back from the brink and, as a result of a secret agreement, the Jupiter MRBMs were quietly removed from Turkey [2]. [1]: https://en.wikipedia.org/wiki/Monroe_Doctrine https://en.wikipedia.org/wiki/Monroe_Doctrine [2]: https://www.wilsoncenter.org/blog-post/jupiter-missiles-and-endgame-cuban-missile-crisis-sealing-deal-italy-and-turkey https://www.wilsoncenter.org/blog-post/jupiter-missiles-and-...
- churchill 1y agoWhy is this comment downvoted? You have the right to see China, USSR and NK as immoral regimes but there's nothing non-factual here.
- charonn0 1y agoThe topic is cybercrime and espionage, not nuclear brinksmanship or colonialism. Whatever parallels can be drawn don't seem to be very relevant, so the comment comes off as an attempt to deflect criticism.
- torben-friis 1y ago
- deleted 1y ago[deleted]
- jmyeet 1y agoSo this is interesting from a technical perspective. Some of this infrastructure is used by pen testers and the likes, which just goes to show that there is no such thing as a defensive weapon. I'll let you ponder why that might be pertinent. Unfortunately, it quickly turns into a discussion of how bad NK and China are and how China shouldn't support NK (because, again, they're bad). I'll offer two words to expose the hypocrisy of this: Stuxnet, Pegasus.
- lawgimenez 1y agoI believe these are the hackers responsible for this leak: https://phrack.org/issues/72/7_md#article https://phrack.org/issues/72/7_md#article
- _def 1y ago> I am a Hacker and I am the opposite to all that you are. In my realm, we are all alike. We exist without skin color, without nationality, and without political agenda. We are slaves to nobody. Classic elitist take ignoring that this this space where "all are alike" can only work for certain kinds of people.
- sim7c00 1y agoBrian: We are all different! Guy: I'm not! its always just some cheesy hacker words put to seem mysterious or whatever -_-. we are legion, we are one etc. anything like that fall apart quickly if you attach identity to something doesnt it. i guess by being anonymous online some forget they are not anonymous irl. a lot of being alone with the terminal ^^> gotta read between all the fluff tho.
- helqn 1y agoOn the Internet, nobody knows you’re a dog. Unless you make it your whole personality telling everybody that you are a dog. Maybe stop doing that.
- dobin 1y agoNo tolerance for the intolerant.
- drtgh 1y agoYour quote it is out of context, they are talking to North Korea's -sociopathic- government accomplice: << Kimsuky, you are not a hacker. You are driven by financial greed, to enrich your leaders, and to fulfill their political agenda. You steal from others and favour your own. You value yourself above the others: You are morally perverted. >> North Korean citizens are kidnapped by a dictatorship. They are talking to someone who supports crimes against humanity.
- aussieguy1234 1y agoThat's a fairly detailed analysis of an APT workflow. Now, non-APT actors, if they wanted to up their level of sophistication, might replicate some of these workflows for their own nefarious activities.
- awesome_dude 1y agoThere's always a risk of openness creating copycats, but there's also the fact that informed decisions can now be made by people who need to mitigate against these malicious actors. There's no way to only give the information to one group without the other group getting their hands on it.
- fragmede 1y agoThere's levels between not sharing it with anybody, and dumping it up on the public web for everyone to see. There are private disclosure lists they could have used, if they wanted to.
- deleted 1y ago[deleted]
- hexpeek 1y agoI’ve heard that in North Korea it is difficult for ordinary people to learn or own a computer. It is assumed that a small number of elite operatives are selected and trained to carry out such tasks, and it is somewhat surprising that they possess the latest technology and conduct hacking.
- asdff 1y agoIf anything the hackers in north korea are probably world class if the government is getting their students into focused training programs early in their schooling. Western nations have nothing equivalent due to schooling being generalist and undergrad and grad school not really introducing you to the sort of work you'd actually do on the job as a hacker. 22 year old western hacker for a 3 letter agency is going to have maybe a 6 month softball tangentially related internship of experience under their belt while the north korean might have years and years by that point.
- awesome_dude 1y ago> 22 year old western hacker for a 3 letter agency is going to have maybe a 6 month softball tangentially related internship of experience under their belt while the north korean might have years and years by that point. I was with you right up until this bit The agencies concerned tend to recruit people that have demonstrated ability in that field, and they've usually got it with "self-directed" training :)
- Joel_Mckay 1y agoState sponsored thieves are not a talent pool that anyone wants in a trusted position. The fact is there were only around 40 unique hacks ever invented, and people simply adapt these into new zero day exploits. Notably, this is now mostly a fully automated process. If people want in, they will get in eventually. =3 x C62=:K6 J@F 2C6 AC66>AE:G6=J 5:D28C66:?8 H:E9 E96 DFCAC:D:?8=J =@H 6DE:>2E6 @7 6IA=@:E E2I@?@>J[ 3FE 9F>2? DE2E:DE:42= 3692G:@C :D 2=D@ ?@E 2D 4@>A=6I 2D >2?J 36=:6G6]
- 1y ago
- Pocomon 1y ago> The leaked dataset attributed to the “Kim” operator offers a uniquely operational perspective into North Korean-aligned cyber operations. It's puzzling why the NORC hackers didn't use a nearest neighbor hack rather than leaving a trail of bread crumbs all the way back to Pyongyang ;)
- wkat4242 1y agoSometimes sending a message is part of the point. And you still have plausible deniability anyway "it was a false flag booo". The Russians do this a lot. This kind of attack that they want everyone to know they are being without telling you they are behind it and denying it in all colours.
- curtisszmania 1y ago[dead]
- sim7c00 1y agointeresting stuff but the china angle is a bit overstated with option A/B. it could simply be the guy maintains presence there because he has access. NK has no public internet so he might simply enjoy internet access -_- rather than neccesarily be either pretending to be chinese or working for them...
- jamedjo 1y ago> Attribution Scenarios: Option A: DPRK Operator Embedded in PRC > Use of Korean language, OCR targeting of Korean documents, and focus on GPKI systems strongly suggest North Korean origin. I'm don't follow how needing OCR to read Korean documents points to them being North Korean? Could also point in the opposite direction of them needing to copy the text for translation.
- Thorrez 1y agoTheir shell history shows them using OCR tools. AFAIK it doesn't show them using translation tools.
- RT-Saber 1y agoActually KIM was also using Google Translate (discovered through his browsing history)
- jamedjo 1y agoFair, and appears I missed the first part "Use of Korean language". The OCR still tells us more about the target than the actor, but I guess they are suggesting the choice of target itself is the indicator.
- RT-Saber 1y agoWe believe KIM is Chinese but working for both Chinese and North Korean interests/governments, he speaks only very little Korean, he translates Korean websites into simplified Chinese using Google Translate and use OCR to translate Korean documents into Chinese.
- codedokode 1y agoWhy everyone working with the government doesn't use hardware keys without passwords so that fishing is useless?
- bornfreddy 1y agoBecause hardware keys are so 2000 - we have apps now. With Play Protect Premium Enterprise to make sure the phone is secure. /s
- ac29 1y agoI know some people in the US government who definitely need a hardware key to access computing resources including email. They work for the Dept of the Interior on science stuff, nothing related to national security or otherwise sensitive info. They mentioned this was a pain in the ass, and a very weird restriction since technically any member of the public can ask for a copy of their emails via FOIA.
- sulandor 1y agosounds like the primary goal was better attestation
- alt227 1y agoSurely people can still phish for the user to insert their hardware key to approve something malicious?
- p0w3n3d 1y agoThis is some clickbait. At least to me. I've recently read an article that when Kim Jong Un takes dump he does it in a N.Korea secret service owned toilet that is being dragged always with him. Hence "Kim dump" sounds really... Physical...