Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

1–10 of 502 posts

Re: Technical report on DNC hack [pdf]

#2
>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing.

I think I might have missed it, but how did they conclude that it was 'APT28' ?

> APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.

Aren't these standard phishing 101 techniques. What makes them specific to 'APT28'. This 'report' looks like someone googled 'phishing 101' and 'web security 101' and copy pasted bunch of stuff from wikipedia.

Re: Technical report on DNC hack [pdf]

#4
There doesn't seem to be much new information there. A bunch of IP addresses, file hashes to look for, and general network security advice, in addition to a history of the attacks which was already public, and an explicit attribution to the Russians.

They mention a phishing attack which took place after the election, but don't give any further details.

Re: Technical report on DNC hack [pdf]

#5
post #2

>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing. I think I might have missed it, but how did they conclude that it was 'APT28' ? > APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.…

Earlier news reports said they came to that conclusion by comparing the RAT artifacts on the compromised machines.

ETA: Also, the bit.ly URLs used in the phishing attacks indicated sharing of resources with other APT28 hacks.

http://motherboard.vice.com/read/how-hackers-broke-into-john...

Re: Technical report on DNC hack [pdf]

#6
post #2

>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing. I think I might have missed it, but how did they conclude that it was 'APT28' ? > APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.…

That report is due in january.

Re: Technical report on DNC hack [pdf]

#7
post #2

>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing. I think I might have missed it, but how did they conclude that it was 'APT28' ? > APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.…

An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future.

They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.

Re: Technical report on DNC hack [pdf]

#8
This report is a joke. I didn't find any reasoning about attribution.

Here is the only valuable part:

" rule PAS_TOOL_PHP_WEB_KIT { meta: description = "PAS TOOL PHP WEB KIT FOUND" strings: $php = " 20KB and filesize < 22KB) and #cookie == 2 and #isset == 3 and all of them } "

Re: Technical report on DNC hack [pdf]

#9

This report is a joke. I didn't find any reasoning about attribution. Here is the only valuable part: " rule PAS_TOOL_PHP_WEB_KIT { meta: description = "PAS TOOL PHP WEB KIT FOUND" strings: $php = " 20KB and filesize < 22KB) and #cookie == 2 and #isset == 3 and all of them } "

I guess you missed https://www.us-cert.gov/sites/default/files/publications/JAR...
Post reply on HN