Live data from Hacker News

WADA Confirms Attack by Russian Cyber Espionage Group

wada-ama.org

71–80 of 89 posts

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#72
post #52

Earlier quoted context omitted.

So, what are the most common methods for this?

Extremely large scale instrumentation of endpoints and networks that unpack and fingerprint every transmitted executable across a decent sized fraction of the whole planet. Attack tools are deployed cliquishly, and different groups have different tradecraft; they leave fingerprints.

This is fascinating stuff. I am going to ask more dumb questions :) I guess most of it is secret but still.

To do this kind of fingerprinting one needs to be able to inspect a large chunk of traffic of the whole Internet. I thought that was not really possible for private companies (except maybe a few).

How do you fingerprint malicious executables if the traffic is encrypted?

I suppose attempts to cover your tracks and to impersonate other groups are common. Are they feasible?

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#73
post #52

Earlier quoted context omitted.

Extremely large scale instrumentation of endpoints and networks that unpack and fingerprint every transmitted executable across a decent sized fraction of the whole planet. Attack tools are deployed cliquishly, and different groups have different tradecraft; they leave fingerprints.

This is fascinating stuff. I am going to ask more dumb questions :) I guess most of it is secret but still. To do this kind of fingerprinting one needs to be able to inspect a large chunk of traffic of the whole Internet. I thought that was not really possible for private companies (except maybe a few). How do you fingerprint malicious executables if the traffic is encrypted? I suppose attempts to cover your tracks a…

Companies like Crowdstrike instrument, in effect, the victims of these attacks. Think of them as a kind of antivirus software, with desktop installations across an enterprise, coupled with a C&C channel that funnels all the executables they find back to a central analysis system.

By the time something like Crowdstrike or FireEye is seeing an executable, it's already been decrypted.

It's totally possible to impersonate another hacking group, but you have to know a lot about their tradecraft to do so with any fidelity.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#74
post #47
post #16

Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.

Here's a description of Russian state sponsored trolling. It's worth a read, even though it's long. http://www.stratcomcoe.org/internet-trolling-hybrid-warfare-... Especially page 60 onwards is useful.

Some of us do it for free [lulz] tho.

COngrats, u've been Russian-trolled :V

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#75
post #9

Earlier quoted context omitted.

nothing in that article suggested that Fancy Bear was acting as the nation of Russia. the game is to sell the data to any nation that bids the highest

The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) was linked to the FSB (Russian Intelligence) during the German Parliament attack http://www.lse.co.uk/AllNews.asp?code=kwdwehme&headline=Russ...

okay, but the article didn't say that

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#76
post #71

Another question is why doping tests data paid by taxpayers of the World are not public? Why do we need for hackers (thanks a lot guys dependless on your nation, race, gender etc) to know the truth?

Lots of things are paid for with tax dollars that shouldn't be automatically public. Health care, school results - just because someone is an athlete doesn't mean they lose all right to privacy.

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#78
post #62
post #31

Earlier quoted context omitted.

You just want to argue, don't you. I don't have time for this.

That comment wasn't civil nor thoughtful as HN requires of each one of us that want to be part of this experiment. I hope next time you give us a piece of your mind it'll more representative of the best part of it.

This is a personal attack. We've banned this account, and we'll ban your main one if you do it again.

https://news.ycombinator.com/newsguidelines.html

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#79
post #51
post #42

Earlier quoted context omitted.

Probably you should read a data, leaked from WADA about US sportsmen and the drugs they used before talking about my credibility.

Can you provide this data to enlighten the rest of us?

Hackers website: http://fancybear.net/.

There is documents, that WADA allowed Serena Williams to take oxycodone and hydromorphone (opioids), prednisone, prednisolone, and methylprednisolone. Her sister Venus Williams was allowed to take prednisone, prednisolone, triamcinolone and formoterol. This is very strong grungs, they should lay in hostpital if they need then for living (owning some of this drugs will cause a 14 years sentence in EU). There is also info about Simone Biles and Elena Delle Donne and they promise more :)

Re: WADA Confirms Attack by Russian Cyber Espionage Group

#80
post #16

Why the hell US government, US media and pro-US organizations (ex. WADA) says that the Russian government was behind all hacking attacks in the last 6 month (maybe year or even more)? It sounds like a broken joke from 60s... Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.

Maybe because the evidence both online and offline implicates them? Lest we forget the events of Sochi. http://m.bbc.com/sport/36823453

Yeah, but think about this points: a) this report is based on words of the man, that run away from Russia after the Prosecutor's office started an investigation about his actions on RUSADA president position. Charges against him includes selling a restricted drugs. His sister was sent to prison for selling a restricted drugs several year ago, but the investigators wasn't able to find "her dealer". b) this report is done by Richard Mclaren, who was one of the first people, that started to talk about such awful events is the sport world. So he i not the correct person to investigate such situation. c) Richard Mclaren and WADA said that the have a solid proves of the accusations in Sochi report, but still they declined to show them anybody including Tomas Bah. I don't support any of conspiracy theories, but this one smells very-very bad. b) Will the judge of any US court accept similar case with no evidence? If yes, then probably there is no any kind of problems with law in Russia...
Post reply on HN