> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays. Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays. > Two zero-days were used to breach any company with SunOS-exposed system…
An inside look at NSA tactics, techniques and procedures from China's lens
11–20 of 76 posts
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#12> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays. Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays. > Two zero-days were used to breach any company with SunOS-exposed system…
If I were in charge of things I'd like to think that this sort of thing would be the first step I'd take to cover my tracks, but I still hear cyber security firms using it in their attributions.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#13[flagged]
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#14It seems like the most efficient way of detecting NSA tools is a regular expression of two all caps dictionary words
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#15Someone doing extensive research on Weixin might ordinarily realize that it's called "Wechat" in English.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#16> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays. Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays. > Two zero-days were used to breach any company with SunOS-exposed system…
Assuming they mean Solaris, it's still technically maintained, at least in the Oracle sense (of both "technically" and "maintained").
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#17> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays. Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays. > Two zero-days were used to breach any company with SunOS-exposed system…
The same strategy is used to attribute attacks against US based targets by Russian, N.Korean and Iranian and other state or state sponsored actors. Time of day, holidays, etc. are (in tandem with other evidence) considered to be surprisingly reliable. If I were in charge of things I'd like to think that this sort of thing would be the first step I'd take to cover my tracks, but I still hear cyber security firms using…
It also may not be worth it. Generally APT's want to stay under the radar while they are executing. But after the goals have been reached, most of the time it doesn't matter much if they get attributed. We have yet to see real consequences against any APT's. So paying your employees more to work night shifts, likely doesn't stack up against the consequences of attribution.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#18Re: An inside look at NSA tactics, techniques and procedures from China's lens
#19> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays. Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays. > Two zero-days were used to breach any company with SunOS-exposed system…
It seems like such a lapse in tradecraft that, absent other indicators, I would just assume it's a crude false flag attempt.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#20> These insights stem from extensive research I did on Weixin Someone doing extensive research on Weixin might ordinarily realize that it's called "Wechat" in English.