Live data from Hacker News

Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

vanityfair.com

11–20 of 31 posts

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#11

A better account of the story at the McAfee Blog: http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady...

In the comments of this the blogger notes that malware put in place to launch the exploits were all for Windows machines. It sounds like it mostly works by getting unwitting users to click on unknown emails. It's been 15 years and we're still doing that?

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#12
post #5

While I support the opinions with regard to security and disclosure as presented, the rest of the article is regrettably lacking in detail, specifics, evidence, or attributable quotes on what has actually occurred. It's hard to say if this is just the typical style of a piece for general audiences on this topic, or the tail wagging the dog on attributing these things to china in the public eye. Frankly, what's more a…

While your claim is a reasonable one, Dmitri Alperovitch's analysis (link in metachris's comment) of Operation Shady RAT strongly suggests that China is behind this operation.

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#13
post #4

> As spring gave way to summer, bloggers and computer-security experts found evidence that the attack on RSA had come from China They never say what evidence, which is the most interesting part of the article. Does anyone have a more detailed description of how they identified it was China?

I worked on the technical side of the RSA attack analysis and not the attribution/political side but some guy on Twitter (https://twitter.com/yuange1975) who pretends to be Chinese has claimed responsibility for the RSA 0-day and some other high profile 0-day exploits on his Twitter feed in a way that makes him the credible original source of those exploits.

I am sure the people on the attribution side dug deeper than this (for example they most likely tried to verify that this guy is really Chinese and not just pretend-Chinese) but I don't know anything about the non-technical side of things.

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#14
post #11

A better account of the story at the McAfee Blog: http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady...

In the comments of this the blogger notes that malware put in place to launch the exploits were all for Windows machines. It sounds like it mostly works by getting unwitting users to click on unknown emails. It's been 15 years and we're still doing that?

There are plenty of non-tech-savvy people employed by the federal government/large companies. It's easy to underestimate how large a percentage it still is.

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#15
post #11

A better account of the story at the McAfee Blog: http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady...

In the comments of this the blogger notes that malware put in place to launch the exploits were all for Windows machines. It sounds like it mostly works by getting unwitting users to click on unknown emails. It's been 15 years and we're still doing that?

Not quite 'unknown' e-mails as I would think of them - these were e-mails that appeared to be from co-workers and addressed specifically to another individual, hence spear-phishing, rather than just phishing. For all intents and purposes, it probably had all the appearances of a legit e-mail.

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#16
post #5

While I support the opinions with regard to security and disclosure as presented, the rest of the article is regrettably lacking in detail, specifics, evidence, or attributable quotes on what has actually occurred. It's hard to say if this is just the typical style of a piece for general audiences on this topic, or the tail wagging the dog on attributing these things to china in the public eye. Frankly, what's more a…

The truth is that both are happening. When you talk to people who are pragmatic and watch the strategic elements they are often saying things like "or someone operating with chinese cover". There is definitely evidence that other actors are using chinese IPs, working hours and techniques to muddy the water. But at the same time, a preponderance of evidence suggests strongly that a majority of these attacks are from chinese sources. Keep in mind that military and national security investigators - even private sector investigators - have access to a lot more intelligence about these matters than simply what IP launched what. So, yes, while some intrusions from china are undoubtedly the work of non-chinese it still makes sense to focus a lot of your efforts on the dragon in the room.

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#17
post #8

The most shocking revelation IMO is that "less than 10 percent of [RSA's] customers have requested replacement tokens". IOW, everybody knows the entire SecurID system was compromised, yet 90% of its users decided to do nothing about it !

I believe that is weasely at best, I've been given the impression previously that over 50% of the tokens in active use had been switched out before the public announcement of the free replacements was made. Perhaps they're doing something like counting every company that bought a few for an eval and aren't using them.

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#18
post #11

A better account of the story at the McAfee Blog: http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady...

In the comments of this the blogger notes that malware put in place to launch the exploits were all for Windows machines. It sounds like it mostly works by getting unwitting users to click on unknown emails. It's been 15 years and we're still doing that?

The documents and addresses used for high end spear phishing usually come from a recent previous compromise. You'll see a sender that you frequently get mail from and know personally and the document attached will be a new version of something they previously sent, or something new that person is working on that would be of particular interest. It is quite difficult to completely insulate even the smartest and most prepared organizations from persistent attacks like this - someone only has to screw up once, and people screw up a lot more than that.

Re: Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered

#20
post #5

While I support the opinions with regard to security and disclosure as presented, the rest of the article is regrettably lacking in detail, specifics, evidence, or attributable quotes on what has actually occurred. It's hard to say if this is just the typical style of a piece for general audiences on this topic, or the tail wagging the dog on attributing these things to china in the public eye. Frankly, what's more a…

> I find the Chinese explanation a little too convenient and a little too amenable to typical national defense thinking. What this article really says to me is that if you want to hack an American company, own a Chinese box first. Nobody will look any further.

Would you also limit your targets to things that would seem to be of overwhelming interest to the chinese government?

Post reply on HN