Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

51–60 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#52
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

In defense of "branding" vulnerabilities ... Heartbleed was the first instance where "normal" people were asking me if I had heard about it and if it effected me/my business. Attribution and PR aside, branding these helps educate the public and give them something tangible to call it/discuss.

And it really makes life easier when you have to explain downtime to your clients, who are often "normal people" and won't understand what SSL is but will have seen Heartbleed on the news and will probably remember it when you say the name. (I'm not sure Shellshock got quite the same coverage, but maybe I'm wrong there.)

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#54
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

At least Heartbleed and Shellshock made sense. Sandworm is just trying to play up fear for a boring not-really-remote vuln. And, the vulnerability is not a worm. It's shitty marketing.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#55
post #7

How does > When exploited, the vulnerability allows an attacker to remotely execute arbitrary code go along with > [...] will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it [...] Is this a fucking joke? Looks like some company just want to push their name out there and get some free media exposure.

From the article: The vulnerability exists because Windows allows the OLE packager (packager .dll) to download and execute INF files. In the case of the observed exploit, specifically when handling Microsoft PowerPoint files, the packagers allows a Package OLE object to reference arbitrary external files, such as INF files, from untrusted sources. So the process is initiated through a spearphish, and when the file is…

Hey! I implemented that DLL in Wine! :) Doesn't currently parse INF files, heh.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#56
post #10

Earlier quoted context omitted.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission. Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.

It was bound to happen as most things well suited to the market.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#57

but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it What's next, "Zero-day Impacting All Versions of All Operating Systems - allows users to download and execute arbitrary code"? I suppose if you're a fan of user-hostile walled-garden trusted-computing models you might consider that a vulnerability, but I think it's safe to assume that…

The exploit seems to leverage PowerPoint files which are generally considered safe, and thus are allowed through mail systems and most normal good-practice behaviors. It uses a sideband exploit that allows PowerPoint to download and execute arbitrary content via a system service.

That is absolutely an exploit, similar to if I linked to an imgur jpeg that actually ran a trojan on your machine.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#58
post #53

Is it responsible to announce this the day before all windows systems are auto-patched? Why not the 15th?

If it is in the wild then it is most responsible to let firms know right now. Now the administrators can choose if they want to block said files until the patch is released.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#59
post #7

How does > When exploited, the vulnerability allows an attacker to remotely execute arbitrary code go along with > [...] will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it [...] Is this a fucking joke? Looks like some company just want to push their name out there and get some free media exposure.

Yeah, it seems this is nothing more than yet another Microsoft Office bug (PowerPoint this time) which can be used for an email worm.

I think they're trying to get on the Heartbleed and Shellshock bandwagon by trying to get a name all over the media for a fairly minor exploit.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#60
post #6

Is it me or is the linked article remarkably content free given the about of security babble it contains? The nice aspect of the Heartbleed branding was its simple and clear message, not having opaque sentences such as "Visibility into this campaign indicates targeting across the following domains" and self serving platitudes such as "As part of our normal cyber threat intelligence operations, iSIGHT Partners is trac…

I guess it is actually about the context in this case, not about the issue itself. Exploits via outlook and office existed for a long time. This is hardly something new. Targeting a specific region / company / group of people, based on politics, without spamming everyone in the world with this vulnerability is a relatively new thing. It looks like they really did want to stay hidden for a long time.

You wont get far spamming random people with PowerPoint vulnerability. It is entirely possible they simply targeted most likely PP users first.
Post reply on HN