Live data from Hacker News

U.S. Treasury breached by hackers backed by foreign government – sources

reuters.com

361–370 of 389 posts

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#361
post #175

Earlier quoted context omitted.

WaPo reporting it is APT29. https://www.washingtonpost.com/national-security/russian-gov...

I wish we had more concrete evidence than "according to people familiar with the matter" though. That's kind of my issue: if these attackers are so sophisticated, how can they be sure it's this particular group? I realize that there are probably many good reasons for not sharing deep technical details in such cases, but from the point of view of an external observer it's really hard to know who should be trusted and…

So far as I understand it, "hacker groups," private or state-level, are generally identified by the tools they use. The same groups will re-use the tools and exploits they have over and over, including some known libraries. Security researchers capture the malware sent out from those groups and reverse engineer them. These allow groups of malware signatures to be created, which allows researchers to start to identify potential actors. It didn't take long for the security community to start blaming certain organizations for Stuxnet, despite there being little proof of their claims...

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#362

How do they know it was backed by a foreign government? I would immediately suspect China or North Korea but that seems too obvious and a bit of a setup?

I don’t know a lot about how states conduct cyber espionage against one another, but it does feel a bit off to be told that this was the work of a nation state with zero proof as to why.

Maybe when they hacked it they accidentally left behind a todolist.txt of "First we hack Solarwinds, then we go after Moose and Squirrel..."

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#363
post #92

My company was the target of a rather interesting office 365 hack. I would not be surprised if the hackers gained access to the Treasury the same way. A link sent from an existing trusted sender was sent to one of our employees from a vendor’s procurement director, inviting us to an RFP. The link took the user to a “notion.io” page. I do not recall the contents of the page (may have been a login spoof, but it didnt m…

We actually had something similar happen, almost to a “T”. Individual’s account was compromised and was used to send emails to their address book asking them to review an RFP. They would then delete the emails that were sent and the account owner was none the wiser. I am not 100% certain as to how the initial compromise happened, but it was an O365 environment and MFA was on. O365 did pick it up and send an alert, bu…

Would either of you be willing to chat about your experience?

I work for Abnormal Security (https://abnormalsecurity.com), and we build products to try and catch these type of account takeover attacks.

You can reach me at egreenstein@abnormalsecurity.com.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#364

Earlier quoted context omitted.

> As a overly generic rule, trust (or don't) the Institution over the individuals. That is precisely the same line of reasoning that started the Iraq War based on lies. The New York Times claimed to have intel from anonymous sources showing that Saddam Hussein had nuclear weapons, and their false reporting is what led the US to declare war. That snafu didn't happen all that long ago, and yet most people in 2020 seem…

The difference is that it wasn't hard to work out the claims were nonsense. WMDs are hugely expensive, and the Iraqi economy was running on fumes at that point. That combined with US belligerence against Iraq made the claims improbable. But Russia actually does have a strong black hat culture, with links to the political establishment. Putin is a technologically savvy kind of despot who likes sneaky low-cost high-ret…

That's all well and good, but it fails to account for potential action by state actors other than Russia. Everything you have said applies just as much to China, if not more so.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#365

Earlier quoted context omitted.

Yeah if I were a blackhat I would launch all my attacks from a cheap VPS in Tehran and sprinkle random Russian gibberish throughout my binaries. Guaranteed nobody will come looking for me. Sincerely yours, Evil mastermind

Twenty-five year ago that would fool people. Now things are complex enough that you can't help but leave clues even as you're trying to plant them. The DPR was caught in part from a post on Stack Overflow where he was asking a question unique to his platform. Imagine how hard it would be to write the Flame malware. Now imagine the NSA and CIA hunting for traces afterword. Building that malware required deep informati…

Yeah I'd be safe. If they were looking for me they would find me, but as soon as somebody shouts "Teh Russianz Did It!" everybody stops looking!

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#366

Earlier quoted context omitted.

Twenty-five year ago that would fool people. Now things are complex enough that you can't help but leave clues even as you're trying to plant them. The DPR was caught in part from a post on Stack Overflow where he was asking a question unique to his platform. Imagine how hard it would be to write the Flame malware. Now imagine the NSA and CIA hunting for traces afterword. Building that malware required deep informati…

You can try to blame somebody else (or even multiple people) by leaving deliberate traces. Cyberwarfare is the most assymetric warfare that we have.

No, virological warfare gets that award.

And I don't mean computer viruses.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#367
post #47

Earlier quoted context omitted.

I had to look up the difference, and I don't think that distinction is something most people are aware of. I've only ever known "nation state" to mean "country", and suspect I'm in the majority. I don't think most people use that term intentionally, because few countries would qualify. That list gets even shorter when you limit it to countries that might be antagonistic to the US, and even shorter when you get to tho…

Copying my reply to GP: This is a US-vs-everyone-else terminology difference. In most of the world "state" refers to a sovereign entity, "nation" refers to an ethnic group, and "nation-state" is a state identified with an ethnic nation. But all of that terminology solidified in the 19th century, so outside of academic political science the US uses "state" to refer to individual entities in a federation (e.g. translat…

This confusion is easily avoided by saying “country,” or if you still want your writing to be verbose you could say “government” or “government-backed actor.”

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#368

Earlier quoted context omitted.

How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for.

>How can you blame software engineers when they are given literally 0 credit for developing software with security in mind and 100 percent credit for simply shipping as quickly as possible. Developing with security in mind will take longer and is literally the opposite of what companies ask for. Police are credited with making arrests, but are almost never credited with treating people with respect. By your logic, po…

This is equivalent to me saying I blame security researchers because they don't develop software which forces all software paradigms to follow rules that implement perfectly secure software

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#369
post #330

Earlier quoted context omitted.

To be clear, given that one never knows if or when a provider has been compromised... is the plan to just not update? What if they were compromised before you initially obtained the software? There's not much that can stop attacks like this. Preventing lateral movement, escalation, exfiltration, detection, and remediation, among other things, would be the way to go.

> There's not much that can stop attacks like this. Not giving people RCE on your machine will stop attacks like this.

That's not the case here. Updates going back as far as what, March?, with no indication that the update included this, were involved here. What I'm saying is that whether you, or an automated update process are performing the update... You still are susceptible.

Unless, as I said, your idea is to block updates completely, which is... not really viable.

What should these companies have done better for the update side? Sure, there were other controls that could have limited the effectiveness of this once the update was in place, but I'm not seeing anything that would block the update itself.

Re: U.S. Treasury breached by hackers backed by foreign government – sources

#370
post #338

Earlier quoted context omitted.

FWIW, I'm also sceptical of comments like yours. A nation state involved in a lot of hacking would be interested in spreading your kind of doubts on social media. I'm not trying to accuse you personally, I don't know you from Putin, I'm just wondering why this response has become so popular recently.

I'm not usually very distrustful of mainstream news (at least, by internet standards) but I am very distrustful of the news' capacity to vet very technical issues correctly. Remember that Bloomberg "the Chinese put spy microchips on our motherboards" story? I'm not accusing the WaPo of being distrustful here, I just think that in these cases the potential for manipulation, half-truths and technical mistakes from thei…

I have the exact same attitude. Reading WaPo, Bloomberg, and even NYT (though I think NYT has a slight edge here) report on technical issues make me cringe. You can tell they're trying to hardest to understand and to explain it in a comprehensible way but it's just so bad. Then I think to myself, if that's the way it is for computing, what about other technical/STEM/specialized fields? I trust them for their reporting on those but what if they have missing the important nuances there too?
Post reply on HN