7 ms·
The alleged NSA malware developers are at risk to be identified
- yousry 10y agoI'm currently working on anomaly detection algorithms and used the good opportunity (the Shadow Brokers release) to analyze a number of malware applications at once.
- bitxbitxbitcoin 10y agoI'd love to see your results once you're ready to share them!
- alfiedotwtf 10y agoAfter seeing this post, the malware devs may have unfollowed/unstarred the repos used in order to evade discovery. It would have been interesting to have GitHub's star/follow history...
- andruby 10y agoGithub has a comprehensive open dataset [1]. I'm not sure if it keeps historical data, but I'm sure there are people hitting the API's and keeping the data archived :) [1] https://www.githubarchive.org/ https://www.githubarchive.org/
- pulse7 10y agoTLDR: Assumptions: "The developers of the malware are leading experts in the area of Linux, Network and Security development." and "They were discovered and not trained."
- mSparks 10y agoFrom reading the spec. pretty sure (at least to a level of certainty greater than Ross Ulbricht being DPR) the poster actually identified them. just didnt go all the way and name names in the post. Can only hope he sends the full analysis to the various interested governments who want to string the scum that wrote the malware up by the balls. I guess Germany is pretty mad with their antics and the most likely to push for an international arrest warrant. But probably better for everyone if its a country similar to the US that doesnt have a problem with torture and mutilation. Maybe Pakistan could save the world a lot of trouble and drone strike their terrorist arses. full addresses available in the OPM hack. Can but dream anyway. (this message explicitly for the excusers of recent US behaviour) But at the very least now they live in fear of getting exactly what they deserve.
- ascorbic 10y agoNice. Advocating the torture and murder of coders working for the US government.
- duncan_bayne 10y agoI thought working for a Government department was already widely recognised as a form of torture ;)
- lostboys67 10y agoEveryone has read the laudryfiles right ;-)
- deleted 10y ago[deleted]
- mSparks 10y agoOne word for you. Manning. If the US has that little respect for its own citizens. Why should these guys expect better treatment from rest of the world?
- ascorbic 10y agoRight... So because the US government treats some people badly, all of its employees are fair game for torture and murder. Which other countries' civil servants would you also like to see killed?
- mSparks 10y agoThat isn't what I said at all and you know it. We're not talking about "some people the US government employs". We're talking about cyber criminals of the highest order of the kind the US wants everyone to believe even Guantanamo bay and the raft of torture there is too good for, committing the kind of crimes that attract multiple life sentences. Why shouldn't somewhere like Germany order their extradition and subject them to the same fate similar European citizens have been subject too. I'm sure they tell themselves "its OK cos its patriotic". Rest of the world doesn't/shouldn't see it that way.
- matt_wulfeck 10y agoThe author appears to run "strings" on the binaries and then goes on to shoot a few theories in the dark: > The developers of the malware are leading experts in the area of Linux, Network and Security development. > They were discovered and not trained. > Because the archive contains a collection of applications, the calculated result-set is reasonable small for further investigations.
- drvdevd 10y agoAlso: > LinkedIn will show you the professional discipline, GitHub the shared libraries and their publicity. I would guess that NSA has a firm grasp on this sort of basic OSINT problem and code attribution techniques.
- wjnc 10y agoRetroactively scrubbing a programmers published work and social media participance is a red flag in itself.
- dogma1138 10y agoIndeed from what we also know or is suspected at least this is a group which is external to the NSA. It could consist of former NSA employees and military personnel but it's not clear if this is a fully sanctioned group or just really good hackers for hire.
- lostboys67 10y agoLike many NSA or GCHQ developers will have a public account on github
- micaksica 10y agoThis post seems lacking in the data required to make such a claim; I do not understand how it has gained so much traction. Where is the actual research, and where are the probable identified candidates? Did I miss a data analysis part somewhere that explained the methodology, and probable attribution to actual people? This appears to be a basic string search of the code and some simple syntax analysis. There are learning algorithms for stylometry, and they can probably be adapted to code. This article appears to state that "it might be possible to use these anomalies as clues", but does not elaborate on, how, why, or what any hypothesis is other than this.
- exo762 10y agoHaven't analyzed author's claims, but in general programmer identification is solved problem: https://www.youtube.com/watch?v=YMa04HovKfs https://www.youtube.com/watch?v=YMa04HovKfs [De-anonymizing programmers 32c3]
- CoryG89 10y agoLooks to me like the author is posting initial findings (and if I am reading this right, withholding some). It doesn't look like a crazy amount of time/resources have gone in, but it looks like a basic proof of concept to me. Perhaps it will get the ball rolling and someone else who reads this will figure it out.
- zigzigzag 10y agoHowever, in contrast to 3.5 billions Internet users, only a few hundred experts have to be identified. This is the sentence that lets you know the post can be safely ignored. Anyone who thinks there are only a few hundred people in the world capable of writing Linux exploits doesn't have a grip on the scale of the world at all.
- micaksica 10y agoAgreed. There are probably 5-25K (yes, large range, but still order of magnitude higher) people in the Bay Area alone that are capable of writing exploits.
- deleted 10y ago[deleted]
- mseebach 10y agoAlso, there's a huge difference in the number of people capable of secretly building exploits alone in their bedrooms at night (probably committing a crime), and those building them as a day job, where you can solicit feedback and advice from peers, reference well-organised documentation and study the original source code of previously successful exploits and freely discuss ideas and approaches with colleagues over lunch. Which of course partially challenges this assumption in the article: The developers of the malware [..] were discovered and not trained.
- lawnchair_larry 10y agopeople capable of secretly building exploits alone in their bedrooms at night (probably committing a crime) No, that isn't how exploit research works. I don't understand why one would think that writing exploits is associated with being a criminal.
- mseebach 10y agoResearch, no, but turning it into malware is.
- avh02 10y agoa naive question: would sending this code through an obfuscater not mess up this methodology? (other than lib identification) It clearly hasn't happened here, but wouldn't that be a reasonable step to cover tracks given this kind of analysis?
- sschueller 10y agoWhy is it a problem if they are identified? It is probably the only case where writing Malware doesn't get your in trouble with the government because they paid you to do it.
- carlsborg 10y agoNice forensic analysis and tutorial. Note that parsing out strings from a binary and finding names from it gives you mainly false positives. e.g. from glibc https://fossies.org/dox/glibc-2.24/C-identification_8c_source.html https://fossies.org/dox/glibc-2.24/C-identification_8c_sourc...
- shitposter 10y agoDOX THE NSA. CYBER WAR NOW.
- sctb 10y agoPlease don't create accounts to violate the guidelines with. If it happens repeatedly not only do we ban the throwaways, but the main account as well.