Live data from Hacker News

Equation Group Cyber Weapons Auction

theshadowbrokers.tumblr.com

61–70 of 151 posts

Re: Equation Group Cyber Weapons Auction

#62
post #55

Earlier quoted context omitted.

Please ignore; corrected below. ~~A silent penny auction :|~~

Its not silent. Its completely public. https://blockchain.info/address/19BY2XCgbDe6WtTVbTyzM9eR3LYr...

Thank you for the correction. Complete oversight on my part.

Re: Equation Group Cyber Weapons Auction

#63

Earlier quoted context omitted.

It should be noted that it is only suspected that the Equation Group is related to the NSA. I only bring this up not because I don't think it is but rather to emphasize that it has not been proven yet.

If this leak is real, it points to one of two things. Either it isn't the NSA and is a company or some quasi-governmental group - owing to the fact that any of this shit the NSA makes would be on JWICS terminals and absolutely not accessible to the internet, or it means there's a leak from the NSA that dumped these files and has decided to sell them. I'd lean more towards the former.

Snowden did tweet what looked like an AES key last week.

Re: Equation Group Cyber Weapons Auction

#64
post #9

The structure of this auction is amazing! 1. All bids are paid up front, and you never get your money back, even if you aren't the highest bidder. So if people bid $50, $70, and $100, they collect $220. 2. No one can verify what is actualy up for sale before the auction. 3. There is no way for the world to know that they actualy delivered the goods after the auction. 4. There is no way for the highest bidder to know…

Not to mention the complete insults to anyone who would want to buy it. A government would handle this by trying to chase down the autioneers. If they wanted the data, they would buy it from Kaspersky, assuming it's real.

The auctioneers indicate that they have the "server side" code. Kaspersky would only have the "client side" code.

...The client gets infected with malware and sends the data home... to some server. The server side.

Re: Equation Group Cyber Weapons Auction

#65
post #6

Earlier quoted context omitted.

Equation Group is the name given by AV vendors to a group of attacks thought to be carried out by NSA. This is, apparently, a dump of internal files (mostly exploits and command & control scripts) that someone got ahold of. They're now apparently trying to auction them off. If it's a fake, it's a very good one – the code words match up to things we've seen in the Snowden leaks, e.g. Jetplow ( https://www.schneier.com…

It should be noted that it is only suspected that the Equation Group is related to the NSA. I only bring this up not because I don't think it is but rather to emphasize that it has not been proven yet.

For the curious, the Equation Group Wikipedia article has a section dedicated to Possible links to Stuxnet and the NSA: https://en.wikipedia.org/wiki/Equation_Group#Possible_links_....

If nothing else, I found this compelling*

> In addition, timestamps in the malware seem to indicate that the programmers worked overwhelmingly Monday–Friday in what would correspond to a 08:00–17:00 workday in an Eastern United States timezone.

*assuming you trust the timestamps.

Re: Equation Group Cyber Weapons Auction

#66
post #43

This reeks of misdirection. Nobody could be both smart enough to hack Equation Group and dumb enough to think that they could just cash out through bitcoin and walk away.

Smart people screw up all the time..

If they're real, that's probably how these files got out there in the first place.

If you got your hands on something like this, you probably think you're pretty smart, and you'd probably try to come up with some smart way to make some money off this, and this is the plan you'd come up with...

See my first sentence...

Re: Equation Group Cyber Weapons Auction

#68

Wikipedia link for the lazy folks like me that didn't know the Equation Group: https://en.wikipedia.org/wiki/Equation_Group

> The malware used in their operations, dubbed EquationDrug and GrayFish, is found to be capable of reprogramming hard disk drive firmware. Wow. We really are f----d all the way down the stack.

http://spritesmods.com/?art=hddhack

Re: Equation Group Cyber Weapons Auction

#69

Ha. I was targeted by this auction specifically. The odd thing is whoever is behind this went through the trouble of posting it to the SecureDrop instance behind BerlinLeaks. https://heartsucker.com/blog/children-at-play

Whoever wrote this possibly "made" all the mistakes on purpose, not to be fingerprinted by its writing style (it's a common technique).

I wonder if software already exists for this, like, purposely filling a text with random mistakes so that the identity of the writer is safe.

Re: Equation Group Cyber Weapons Auction

#70
post #66
post #43

This reeks of misdirection. Nobody could be both smart enough to hack Equation Group and dumb enough to think that they could just cash out through bitcoin and walk away.

Smart people screw up all the time.. If they're real, that's probably how these files got out there in the first place. If you got your hands on something like this, you probably think you're pretty smart, and you'd probably try to come up with some smart way to make some money off this, and this is the plan you'd come up with... See my first sentence...

Anyone who did even cursory research on Bitcoin would know that it's trivially traceable when redeemed.
Post reply on HN