Live data from Hacker News

An inside look at NSA tactics, techniques and procedures from China's lens

inversecos.com

21–30 of 76 posts

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#21
I originally came here to comment how crazy it seems that DoD employees at NSA cannot be bothered to cover their tracks by working nonstandard hours/holidays (obviously Mil & Intel folks do this, they even get deployed!). But the thought occurred to me that attribution to NSA was likely a desired outcome here (“We can hack you too”) and there are probably many people at NSA working nonstandard hours/days to prevent attribution.

I think the English language aspect is much more interesting and difficult/impossible to prevent.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#22

I originally came here to comment how crazy it seems that DoD employees at NSA cannot be bothered to cover their tracks by working nonstandard hours/holidays (obviously Mil & Intel folks do this, they even get deployed!). But the thought occurred to me that attribution to NSA was likely a desired outcome here (“We can hack you too”) and there are probably many people at NSA working nonstandard hours/days to prevent a…

I agree, but I would go further and say (written) English language is as easy to emulate. There are technical people with great written English skills who will give away their non-Anglophone identities at the first sentence they speak.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#23
post #16

Earlier quoted context omitted.

Assuming they mean Solaris, it's still technically maintained, at least in the Oracle sense (of both "technically" and "maintained").

I assumed that much, SunOS is pretty ancient, last version was what, in early 1990s? Though, Solaris still would report a SunOS 5.$solarisver version or something like that. So I guess we can say it is a "SunOS" box if we wanted to.

SunOS 4.x is the BSD lineage and SunOS 5.x the Solaris lineage, or at least was when i worked at Sun.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#24
> Chinese cyber organizations openly acknowledge and publicize their partnerships. This openness was particularly interesting to observe and may be influenced by cultural factors, such as the Confucian emphasis on shared knowledge and a political framework that encourages collective efforts.

I or anyone outside obviously cannot verify the technical details. However, the above statement struck as particularly uninformed. As any engineer in East Asia can tell you, there is nothing especially collaborative about tech in Confucian culture; if anything, the engineers in that region admire the free speech and discussion traditionally prized in the Western culture. Calling Chinese political framework, especially in the context of national security, conducive to open public discussion was quite ironic to see.

Edit: the punchline is this. If a friend who is always secretive and deceptive about his personal life is suddenly openly discussing his life, what does that say about the details he just disclosed and/or the situation he is currently in?

source: I regularly work with engineers from that culture and studied relevant geopolitics.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#25
post #19
post #4

> No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays. Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays. > Two zero-days were used to breach any company with SunOS-exposed system…

>A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA It seems like such a lapse in tradecraft that, absent other indicators, I would just assume it's a crude false flag attempt.

It's a Schrödinger's false-flag! Just incompetent enough to look like a false flag. But at the same time, it's coming from the heart of US bureaucracy, which finds cash to build multi-billion dollar hidden data centers, but is also inflexible enough properly pay for overtime and off-schedule work.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#26
post #17

Earlier quoted context omitted.

The same strategy is used to attribute attacks against US based targets by Russian, N.Korean and Iranian and other state or state sponsored actors. Time of day, holidays, etc. are (in tandem with other evidence) considered to be surprisingly reliable. If I were in charge of things I'd like to think that this sort of thing would be the first step I'd take to cover my tracks, but I still hear cyber security firms using…

The type of work the people working at an APT do, is mainly office work, while it still is very much "hands-on-keyboard" work (so you cannot set an action to automatically occur when nobody is checking the results in the middle of the night). You might want to try shuffling this up when you are in charge, but your (usually highly skilled and expensive) employees probably don't want to be working weird shifts all the…

I have a hard time imagining these APT attacks are manual at the keyboard typing. That seems like an invention for entertainment whereas I'd expect reality to be "run script & establish an ongoing backdoor" or "run script & perform attack". You might need on-call to flag if anything has gone wrong, but I'd have a hard time imagining the entire team is involved for that so the cost of paying extra for an on-call is quite trivial vs the overall cost of the team. In industry that's not even compensated since salaried employees don't get overtime although I imagine that for government work the unions have negotiated this better.

EDIT: Huh, I guess sometimes it is like the movies: > One of the frameworks used by TAO that was forensically uncovered during the incident named “NOPEN” requires human operation. As such, a lot of the attack required hands-on-keyboard and data analysis of the incident timeline showed 98% of all the attacks occurred during 9am – 16pm EST (US working hours).

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#27

I originally came here to comment how crazy it seems that DoD employees at NSA cannot be bothered to cover their tracks by working nonstandard hours/holidays (obviously Mil & Intel folks do this, they even get deployed!). But the thought occurred to me that attribution to NSA was likely a desired outcome here (“We can hack you too”) and there are probably many people at NSA working nonstandard hours/days to prevent a…

Technical talent with transferable skills for higher paying work aren't incentivized to work on deployment schedule. But really, why assume NSA capable of obfuscating against PRC also stacked with talent. The parsimonious answer is then why bother, everyone knows they're deep in each others networks for decades and will continue to be. So let the hackers have their weekends.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#28
> In total, 54 jump servers and 5 proxy servers were used to perform the attack coming from 17 different countries including Japan, South Korea, Sweden, Poland and Ukraine with 70% of the attacks coming from China’s neighbouring countries.

I'm guessing this is so when they do data exfiltration (and hosted MITM) it's not sending a ton of data to a single server, but spreads them out.

> SECONDDATE: This tool was allegedly used by TAO (NSA) to hack into the office intranet of the University. Attribution of SECONDDATE was discovered through collaboration with other industry partners. They found thousands of network devices running this spyware – where the communications went back to NSA servers located in Germany, Japan, South Korea and Taiwan. This tool was used to redirect user traffic to the FOXACID platform.

> SECONDDATE – Backdoor installed on network edge devices such as gateways and border routers to filter, and hijack mass amounts of data in a MiTM. This was placed on the border routers of the University to hijack traffic to redirect to NSA’s FOXACID platform.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#29
post #17

Earlier quoted context omitted.

The type of work the people working at an APT do, is mainly office work, while it still is very much "hands-on-keyboard" work (so you cannot set an action to automatically occur when nobody is checking the results in the middle of the night). You might want to try shuffling this up when you are in charge, but your (usually highly skilled and expensive) employees probably don't want to be working weird shifts all the…

I have a hard time imagining these APT attacks are manual at the keyboard typing. That seems like an invention for entertainment whereas I'd expect reality to be "run script & establish an ongoing backdoor" or "run script & perform attack". You might need on-call to flag if anything has gone wrong, but I'd have a hard time imagining the entire team is involved for that so the cost of paying extra for an on-call is qu…

On-Call for mission of this size sounds fairly unlikely, doesn't it?

You wouldn't spend hundreds of thousands of dollars on large scale attacks with lots of (temporary) infrastructure and planning to then yolo it at the last minute and hope that everything goes well and you have the results back when you come back on Monday.

Post reply on HN