Live data from Hacker News

FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

twitter.com

31–40 of 76 posts

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#31
post #28

Earlier quoted context omitted.

I haven't tried this, but I imagine a situation where computer A uses SSH to connect to VPS B and computer C connect to VPS B using SSH. If both SSH connections port-forward a VNC port, you can use VNC.

Yes technically it could work, but I cannot ask the users to use SSH and configure VNC. The force of team viewer is that you download it, open it, and give number over the phone and it works.

Chrome remote desktop works pretty well

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#32
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

Anybody know of a UDP-based alternative? VNC is TCP.

Is there a reason why you need UDP specifically?

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#34
> This group of hackers uses highly sophisticated malware variants, primarily developed for espionage, so we consider it unlikely that any State is sponsoring its operations,” Glyer says.

> The web application security expert adds that, based on detected activities and attack methods, in addition to the unusual interest that APT41 has shown in attacking the video game industry, its attacks could not be politically motivated; instead, they’re focused on economic gains.

I’d like to know how can one simply assume this given a potential payoff of billions of devices...

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#35
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

In the same boat, and I have heard good things about https://www.dwservice.net/fr/home.html, but I haven't tried it myself yet.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#36
post #34

> This group of hackers uses highly sophisticated malware variants, primarily developed for espionage, so we consider it unlikely that any State is sponsoring its operations,” Glyer says. > The web application security expert adds that, based on detected activities and attack methods, in addition to the unusual interest that APT41 has shown in attacking the video game industry, its attacks could not be politically mo…

Especially given that the "Video Game Industry" probably represents a pretty large group of heterogenous, idiosyncratic chat protocols, which I certainly would be interested in if I were the Chinese Govt.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#37
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

I don't know how smooth it is, since I haven't tried it myself yet, but apparently Nextcloud talk can do it. I think it needs a browser extension but that might not be nearly as much of an imposition as vnc + ssh. It's also pretty easy to self host on a vps or other server of your own.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#38
TeamViewer devs are especially to blame for this. You can’t install it without admin permissions even if you just want to control another desktop. Unless you manually extract the .app from the .pkg, in which case it works fine.

Anyways, this isn’t the first time TeamViewer has been hacked. Wonder what their beef is against E2EE between connected computers.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#39
post #18
post #17

Earlier quoted context omitted.

What do you mean by tracking?

check out the *.pixel.archive.is lookups

Fascinating, they embed a tracking pixel of: http://onion.[SOME_NUMERIC_ID].pixel.archive.today/pixel.gif for Tor endpoint (archivecaslytosk.onion) connections but https:// [YOUR_IP].[COUNTRY_CODE].[SHORT_ALPHANUMERIC_ID].[SOME_NUMERIC_ID].pixel.archive.is/pixel.gif for regular (archive.is/archive.fo/archive.today/etc) connections.

So at least this lets archive.is correlate your IP with your DNS server (which must pass EDNS Client Subnet to get any meaningful response, this is the reason why Cloudflare DNS is not that great for accessing archive.is; more: https://news.ycombinator.com/item?id=19828317).

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#40
post #32

Earlier quoted context omitted.

Is there a reason why you need UDP specifically?

It's far smoother.

What protocol do you notice this with? In my experience, Microsoft RDP (the only protocol I know with configurable udp and tcp) with and without udp is imperceptible during typical use (eg. server administration).
Post reply on HN