Earlier quoted context omitted.
WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...
I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…
U.S. Treasury breached by hackers backed by foreign government – sources
361–370 of 389 posts
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#362How do they know it was backed by a foreign government? I would immediately suspect China or North Korea but that seems too obvious and a bit of a setup?
I don’t know a lot about how states conduct cyber espionage against one another, but it does feel a bit off to be told that this was the work of a nation state with zero proof as to why.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#363My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…
We actually had something similar happen, almost to a “T”. Individual’s account was compromised and was used to send emails to their address book asking them to review an RFP. They would then delete the emails that were sent and the account owner was none the wiser. I am not 100% certain as to how the initial compromise happened, but it was an O365 environment and MFA was on. O365 did pick it up and send an alert, bu…
I work for Abnormal Security (https://abnormalsecurity.com), and we build products to try and catch these type of account takeover attacks.
You can reach me at egreenstein@abnormalsecurity.com.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#364Earlier quoted context omitted.
> As a overly generic rule, trust (or don't) the Institution over the individuals. That is precisely the same line of reasoning that started the Iraq War based on lies. The New York Times claimed to have intel from anonymous sources showing that Saddam Hussein had nuclear weapons, and their false reporting is what led the US to declare war. That snafu didn't happen all that long ago, and yet most people in 2020 seem…
The difference is that it wasn't hard to work out the claims were nonsense. WMDs are hugely expensive, and the Iraqi economy was running on fumes at that point. That combined with US belligerence against Iraq made the claims improbable. But Russia actually does have a strong black hat culture, with links to the political establishment. Putin is a technologically savvy kind of despot who likes sneaky low-cost high-ret…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#365Earlier quoted context omitted.
Yeah if I were a blackhat I would launch all my attacks from a cheap VPS in Tehran and sprinkle random Russian gibberish throughout my binaries. Guaranteed nobody will come looking for me. Sincerely yours, Evil mastermind
Twenty-five year ago that would fool people. Now things are complex enough that you can't help but leave clues even as you're trying to plant them. The DPR was caught in part from a post on Stack Overflow where he was asking a question unique to his platform. Imagine how hard it would be to write the Flame malware. Now imagine the NSA and CIA hunting for traces afterword. Building that malware required deep informati…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#366Earlier quoted context omitted.
Twenty-five year ago that would fool people. Now things are complex enough that you can't help but leave clues even as you're trying to plant them. The DPR was caught in part from a post on Stack Overflow where he was asking a question unique to his platform. Imagine how hard it would be to write the Flame malware. Now imagine the NSA and CIA hunting for traces afterword. Building that malware required deep informati…
You can try to blame somebody else (or even multiple people) by leaving deliberate traces. Cyberwarfare is the most assymetric warfare that we have.
And I don't mean computer viruses.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#367Earlier quoted context omitted.
I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…
Copying my reply to GP: This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation. But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translat…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#368Earlier quoted context omitted.
How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for.
>How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for. Police are credited with making arrests, but are almost never credited with treating people with respect. By your logic, po…
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#369Earlier quoted context omitted.
To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you initially obtained the software? There's not much that can stop attacks like this. Preventing lateral movement, escalation, exfiltration, detection, and remediation, among other things, would be the way to go.
> There's not much that can stop attacks like this. Not giving people RCE on your machine will stop attacks like this.
Unless, as I said, your idea is to block updates completely, which is... not really viable.
What should these companies have done better for the update side? Sure, there were other controls that could have limited the effectiveness of this once the update was in place, but I'm not seeing anything that would block the update itself.
Re: U.S. Treasury breached by hackers backed by foreign government – sources
#370Earlier quoted context omitted.
FWIW, I'm also sceptical of comments like yours. A nation state involved in a lot of hacking would be interested in spreading your kind of doubts on social media. I'm not trying to accuse you personally, I don't know you from Putin, I'm just wondering why this response has become so popular recently.
I'm not usually very distrustful of mainstream news (at least, by internet standards) but I am very distrustful of the news' capacity to vet very technical issues correctly. Remember that Bloomberg "the Chinese put spy microchips on our motherboards" story? I'm not accusing the WaPo of being distrustful here, I just think that in these cases the potential for manipulation, half-truths and technical mistakes from thei…