This doesn’t sound like a botnet so much as a (possibly Russian) child of Stuxnet.
Botnet that hid for 18 months
11–20 of 25 posts
Re: Botnet that hid for 18 months
#12Re: Botnet that hid for 18 months
#13Earlier quoted context omitted.
I bet sometimes they kick out bots that are competing for resources. Or at least scan for the other bots and carve it out, otherwise when there's two that's when they both start mining full blast, they each try to cash in the crypto keys on the computer before the other one does, and the user gets around to reinstalling the OS because his computer is unusable.
Based on the places where they were putting their threats I doubt mining was their goal. It sounds more that they were spelunking in case they wanted to ransomware and/or just wanting the information in a straightforward way. I wonder if also they were just using these servers as a foothold to attack something else. If you are mixing your traffic among an org's business presence it would be difficult to chase as a ho…
Re: Botnet that hid for 18 months
#14Is this what it takes for IoT devices to finally get DMZ'd away from main networks at enterprises?
But what would likely have helped is a focus on strong controls around identity and access management. Especially in the form of passwordless auth. Would certainly make lateral moves harder.
Re: Botnet that hid for 18 months
#15Interesting -- not targeting defense contractors or governments.. > In this blog post, we introduce UNC3524, a newly discovered suspected espionage threat actor that, to date, heavily targets the emails of employees that focus on corporate development, mergers and acquisitions, and large corporate transactions. On the surface, their targeting of individuals involved in corporate transactions suggests a financial moti…
Re: Botnet that hid for 18 months
#16Interesting -- not targeting defense contractors or governments.. > In this blog post, we introduce UNC3524, a newly discovered suspected espionage threat actor that, to date, heavily targets the emails of employees that focus on corporate development, mergers and acquisitions, and large corporate transactions. On the surface, their targeting of individuals involved in corporate transactions suggests a financial moti…
insider trading without insider trading - the netflix engineers who got busted by the DoJ last year did well over 3 million USD on just subscriber data - imagine what access to exec inbox would look like -
Or are these people going on r/wallstreetbets to write long DD upvoted by bots, purchased accounts, awards, under VPN to make their purchases seem organic?
Still wouldn't it be obvious somebody doing that routinely and establishing a pattern of unusually high win rates before earnings?
Sort of like how poker companies catch cheaters, simply by knowing the average win rate to be within a specific distribution, even the slightest deviation or outlier would send its risk management scrutinizing play by play to determine a pattern.
Wouldn't large state actors with web of shell companies be able to obfuscate and get away with impunity? Literally printing money and also weaponizing a foreign financial market.
Re: Botnet that hid for 18 months
#17Earlier quoted context omitted.
Based on the places where they were putting their threats I doubt mining was their goal. It sounds more that they were spelunking in case they wanted to ransomware and/or just wanting the information in a straightforward way. I wonder if also they were just using these servers as a foothold to attack something else. If you are mixing your traffic among an org's business presence it would be difficult to chase as a ho…
Based on the article they were targeting Office 365 on prem email instances for market mover events (acquisitions, new clients, etc)
Re: Botnet that hid for 18 months
#18Earlier quoted context omitted.
insider trading without insider trading - the netflix engineers who got busted by the DoJ last year did well over 3 million USD on just subscriber data - imagine what access to exec inbox would look like -
but wouldn't it be easy to catch people with lot of near expiry far OTM put options for instance? Or are these people going on r/wallstreetbets to write long DD upvoted by bots, purchased accounts, awards, under VPN to make their purchases seem organic? Still wouldn't it be obvious somebody doing that routinely and establishing a pattern of unusually high win rates before earnings? Sort of like how poker companies ca…
Re: Botnet that hid for 18 months
#19Earlier quoted context omitted.
insider trading without insider trading - the netflix engineers who got busted by the DoJ last year did well over 3 million USD on just subscriber data - imagine what access to exec inbox would look like -
but wouldn't it be easy to catch people with lot of near expiry far OTM put options for instance? Or are these people going on r/wallstreetbets to write long DD upvoted by bots, purchased accounts, awards, under VPN to make their purchases seem organic? Still wouldn't it be obvious somebody doing that routinely and establishing a pattern of unusually high win rates before earnings? Sort of like how poker companies ca…
Re: Botnet that hid for 18 months
#20Interesting -- not targeting defense contractors or governments.. > In this blog post, we introduce UNC3524, a newly discovered suspected espionage threat actor that, to date, heavily targets the emails of employees that focus on corporate development, mergers and acquisitions, and large corporate transactions. On the surface, their targeting of individuals involved in corporate transactions suggests a financial moti…
> Is there enough money in high finance to support the development of sophisticated tools to rig trading markets? Yes, but a well timed economic WMD on countries heavily reliant on efficient capital markets would greatly distract them from interfering in international events.