Earlier quoted context omitted.
They’ve been around for a while and identified by several governments. “NOBELIUM is an advanced persistent threat group also known as APT29, which is publicly attributed to the Russian government and specifically to the Foreign Intelligence Service of the Russian Federation (SVR)” https://blogs.blackberry.com/en/2023/03/nobelium-targets-eu-...
It still doesn't answer how they know that: 1) they were hacked by that exact group 2) that group is sponsored by the Russian government. The only evidence I've seen before in cases like this one was that they found that the hacks happened during Russia's working hours (i.e. Moscow timezone), and that they found some word in Cyrillic in some of the shell scripts. Which is honestly not hard to pull off if you want to…
Microsoft actions following attack by nation state actor Midnight Blizzard
191–200 of 204 posts
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#192Earlier quoted context omitted.
As we've seen, many of the cybersecurity teams have been pwned, so a large part of the breadcrumbs they'd pattern match are already out there. Additionally, if security is poor enough, there can be more than one hacker into a system, which is another way they could accumulate breadcrumbs. This has precedent - there has been malware that uninstalls other malware.
Many? I'm only aware of the Equation group, believed to be the NSA, whose extremely powerful tools were made public. What other threat actor's internals (and I mean more then chat logs) have been made public?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#193Earlier quoted context omitted.
Many? I'm only aware of the Equation group, believed to be the NSA, whose extremely powerful tools were made public. What other threat actor's internals (and I mean more then chat logs) have been made public?
Why would they have to be made public? They only have to be known to a handful of other nation states.
I already conceded in my original response that if you hacked another group first, then yes, you can leave fake breadcrumbs.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#194"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
Not to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events. Azure was owned pretty hard a while back, very little was ever heard of it again. Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?
From what I recall, it was a Chinese APT (designated as Storm-0558, which I think means they could not reliably attribute it to any group: https://malpedia.caad.fkie.fraunhofer.de/actor/storm-0558), that was sitting on developers’ workstations long enough to get access to master signing key from a memory dump that ended up on one of the workstations. They then used it to access US government officials’ emails (Department of State if I recall correctly), which supposedly gave China a strategic advantage and a better understanding of inner workings of US foreign policy.
You will not see it in news that China got favourable terms in some negotiations with a country in Africa (are of Chinese interests) and US got least favourable terms than they could’ve gotten because the Chinese negotiators knew something.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#195Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#196Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#197Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#198Earlier quoted context omitted.
[flagged]
Got a reference for that? To be clear: I've never heard of any such thing. I happen to work for Google, but I'm open the possibility that this happened and I didn't hear about it.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#199Earlier quoted context omitted.
yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…
This kind of attack can happen on any tech stack where bad passwords have ever been allowed. The dunking is obviously fun, but the fact that the underlying technology happened to be Microsoft’s is largely irrelevant.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#200"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.