Live data from Hacker News

How to catch a wild triangle

securelist.com

11–20 of 46 posts

Re: How to catch a wild triangle

#11
>Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validators, an implant and its modules.

Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] was behind this but my money's on the NSA.

[1] https://eugene.kaspersky.com/2011/11/02/the-man-who-found-st...

[2] https://www.washingtonpost.com/world/national-security/israe...

Re: How to catch a wild triangle

#12
post #7

Earlier quoted context omitted.

A bit further down in the same article: "Unfortunately, this method did not allow us to intercept HTTPS traffic of Apple services (including iMessage), as iOS implements SSL pinning for this"

It would have allowed them to intercept those bogus malware domains though.

It did.

Re: How to catch a wild triangle

#13

> Unfortunately for us, all the communications with the servers in question happened over HTTPS, so we could not recover any additional details from the traffic. This is why your corporate network should MitM all TLS connections by default.

The risk of getting your MitM box compromised is too high IMO

Re: How to catch a wild triangle

#14
post #11

> Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validators, an implant and its modules. Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] w…

no way in hell the NSA forcibly tries to reinfect targets over and over, that's not their modus operandi. Instead they would have spend money to find a persistence on the infected device.

The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.

Re: How to catch a wild triangle

#17
post #14
post #11

> Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validators, an implant and its modules. Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] w…

no way in hell the NSA forcibly tries to reinfect targets over and over, that's not their modus operandi. Instead they would have spend money to find a persistence on the infected device. The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.

Persistence on iOS is really, really hard.

Re: How to catch a wild triangle

#18
post #14
post #11

> Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validators, an implant and its modules. Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] w…

no way in hell the NSA forcibly tries to reinfect targets over and over, that's not their modus operandi. Instead they would have spend money to find a persistence on the infected device. The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.

It wasn't clear to me from reading the blogpost that persistence _wasn't_ achieved?

Re: How to catch a wild triangle

#19

I wasn't expecting this. I was expecting just a simple post about some errant process or something. What I ended up reading was a digital version of a sherlock holmes novel. Complete with the mouse trap. The use of mitmproxy to intercept and unpack https requests like a russian doll is the most russian solution, and it worked like a charm. Thanks for including the juicy bits that make these discoveries actually worth…

Use of mitmproxy is very fragile. Cert Pinning is increasing common.

Re: How to catch a wild triangle

#20
I've always felt that security/exploit devs are just different.

This kind of constant striving and failing until finally succeeding would be such an incredibly frustrating experience for me.

Kudos to them though, it's serious perseverance.

Post reply on HN