Live data from Hacker News

If you only work on your malware on weekdays, you might be a CIA hacker

qz.com

1–10 of 25 posts

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#2
That's actually pretty funny.

Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times.

Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#3
post #2

That's actually pretty funny. Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times. Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.

It also might be on purpose -- if you have a signature, then unsigned things aren't you, right?

I suspect it was largely accidental, though. Heck, there's been private entities I know who have ended up with tells that pinned them to timezones.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#5
post #2

That's actually pretty funny. Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times. Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.

It also might be on purpose -- if you have a signature, then unsigned things aren't you, right? I suspect it was largely accidental, though. Heck, there's been private entities I know who have ended up with tells that pinned them to timezones.

Easy to do with e.g. postings to forums, including those about bitcoin...

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#6
post #2

That's actually pretty funny. Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times. Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.

The issue is that when you have analysts combing over your attack there are so many different ways information can be leaked that it's impossible to try and elude everything. To properly conceal your identity to prevent fingerprinting you'd have to rewrite all your malware from scratch every time using completely different techniques, and choose targets largely at random so your motives don't become obvious. So APT groups have to prioritize on what information you absolutely don't want to get out and go from there, and look at the trade offs involved. To conceal working hours you'd have to either make everyone work random hours (which wouldn't be very popular) or perform certain activities like domain registration on a random time delay (which you may not always want, some things really need humans on keyboards to monitor). So it's a lot of effort to conceal an attribute that, while telling, isn't actually enough to implicate you.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#8
Symantec had already concluded that Longhorn was a group based in North America. That was partly based on the American time zones they saw, but also on the finding that Longhorn primarily targeted devices in Europe, Asia, Africa, and the Middle East—and seemed particularly averse to American computers.

Now the CIA is going to claim that for national security reasons, they're going to have to hack American computers too.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#9
post #5

Earlier quoted context omitted.

It also might be on purpose -- if you have a signature, then unsigned things aren't you, right? I suspect it was largely accidental, though. Heck, there's been private entities I know who have ended up with tells that pinned them to timezones.

Easy to do with e.g. postings to forums, including those about bitcoin...

I've generally given up trying to conceal anything above what city I'm in.

There are just too many information leaks that can be used to track people back to regions, and I honestly don't care if people know I'm one of millions of people.

(Whoops, there goes another -- there's only 53 US metros above 1mil people and 34 above 2mil.)

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#10
If every government entity can fake/scrub/modify time zones, how are time zones are a "tell" at all?

Let's say the US uses French time zones and France uses US eastern time zones. You've discovered malware that for whatever reason has time stamps for US Eastern.

Is it really from the US or is it from France? How would you deduce such a fact? I posit it would be better to see who the malware is targeting: entities may be averse to targeting their own countries.

Post reply on HN