Live data from Hacker News

An inside look at NSA tactics, techniques and procedures from China's lens

inversecos.com

1–10 of 76 posts

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#4
> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays.

Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays.

> Two zero-days were used to breach any company with SunOS-exposed systems in neighbouring countries to China

SunOS? Wonder if it's because it's genuinely used still quite a bit or they simply had zero-days for it since many of those are old and unpatched?

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#6
This is really interesting. I wonder how red-teams in State sponsored teams operate in real life. I guess every one has an NDA, but would love to get a general idea.

I assume it's a jungle out there, so teams need to protect themselves 24/7/365 and I'm surprised to find no activities in holidays.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#7
post #5
post #3

[flagged]

> can I comment freely here Sure, we all have the freedom of speech here. Will you have freedom after speech though, I don't know? It depends on your particular situation ;-)

nothing it's just two biggest intelligence agencies fighting, I think keeping quiet is the safest bet

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#9
glad to see the same basic tradecraft from 90s hacking, only very refined and industrialized. it's a durable skill. the focus on switches and routers is very pro, as they are the most opaque infra with the fewest forensic capabilities. iot is less reliable as RE'ing cheap devices and firmware for IoCs is accessible, where almost nobody outside the IC did core gear (word to phenolit from back in the day tho).

the traffic redirection is interesting in that i would be curious if they rate limited it or used on device selectors in their implant to redirect traffic. the trade off between memory caching packets to sort on selectors vs.stealthy throughput would have been a fun design meeting.

hunting these kinds of actors would be supremely fun. the main thing that protects them is few outside massive bureaucracies really care enough or find it economical, as the rewards are more in finding new zero day and not hunting state level threat actors. the exceptions who do (p0, citizenlab etc) are attached to massive orgs and dont really led themselves to privateering. amazing write up anyway.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#10
post #8

It seems like the most efficient way of detecting NSA tools is a regular expression of two all caps dictionary words

BadJoke LoveIt.

Similarly, 0day ABNF to identify probable NSA front companies:

[optional-firstname] [optional-adjective]

Post reply on HN