8 ms·
Winnti: Hackers attacking the heart of German industry
- iagovar 7y agoThis group of german companies founded their own security group [German Cyber Security Organization (DCSO)]. That speaks a lot about their trust in their public services. The only time I've been involved in a hacking attempt (it was ransomware) the company I work for contacted the CCN-CERT. I wonder if US companies contact NSA/Other gov agencies or deal with it themselves with security companies. Also, while I understand the care and concern they put into securing their networks, many german companies basically gift their tech to china, like Deutsche Bahn, or being bought and transfered there, like it happend with Kuka. So be it by hacking into your network or "partnering", they'll copy your tech and kick you out of their market sooner or later.
- ChuckNorris89 7y agoProbably because when it comes to anything cyber-related, the German government, like most big companies there, is a dinosaur, greatly inferior to it's British and Swiss counterparts.
- TeMPOraL 7y agoGermany at least has the CCC, which it sometimes asks for advice and, occasionally, listens to.
- tsss 7y agoWhen they aren't trying to put them in jail that is.
- hobofan 7y agoI'm not sure what the social aspects in Britain and Switzerland are like, but in Germany, working for the BND or other governmental cyber security institutions is frowned upon in the cyber-security circles (at least that's my view from someone not too deep in the field).
- turbinerneiter 7y agoYeah, because the BND is the enemy. They are the ones who keep the vulnerabilities open instead of closing them. We have the CCC to trust in.
- vageli 7y ago> This group of german companies founded their own security group [German Cyber Security Organization (DCSO)]. That speaks a lot about their trust in their public services. > The only time I've been involved in a hacking attempt (it was ransomware) the company I work for contacted the CCN-CERT. I wonder if US companies contact NSA/Other gov agencies or deal with it themselves with security companies. In the US, most large companies that have suffered breaches contact the FBI.
- ga-vu 7y agoIs this a good way of tracking an APT? Just from bytecode? Isn't that easy to fake? What if they were tracking Russian hackers instead?
- janekm 7y agoIf I'm understanding the article correctly, the hackers are using a easily reversed cypher for storing configuration data for their malware, which was reversed by assuming the presence of the string "C:\Windows\System". In the following decrypted data the name of the respective company targeted was found. Yes I suppose it would be easily faked if the faker had performed a similar analysis on the malware...
- tobiasu 7y agoWhat an obnoxious presentation. And I'm paying for this garbage.
- deleted 7y ago[deleted]
- akuji1993 7y agoNot really sure what is so obnoxious about this. The whole article is made up like the NYTimes interactive articles are. Quite a high design standard to compare to and they're doing pretty well. No idea what you are talking about.
- sparkling 7y ago> The whole article is made up like the NYTimes interactive articles are. Not him, but for me: yes and thats the problem. I don't need Infotainment wrapped, information wrapped in some storytelling timeline with broken scrolling. Just give me a well done article without the nonsense, Jesus. These animation, hex code dumps etc. add ZERO value to the article.
- mschuster91 7y agoUs techies are not the target group for such articles, they're made for the "normal" population.
- hakantan 7y agoHi. One of the author(s) of the article here. The plain article with information-only is over here: https://www.tagesschau.de/investigativ/ndr/winnti-101.html https://www.tagesschau.de/investigativ/ndr/winnti-101.html We released a longer version, because we do hear very often that people don't understand how these intrusions are actually working. Also, we tried to show the scale. -> both long form and shorter version hope that helps.
- yorwba 7y ago
- lnsru 7y agoAs of today we still use shared network drives for everything in major German company. We don’t use slack/irc/Skype/zoom/whatever. Phone calls and conferences(!) from the middle of open office is normal. Asana/Trello/Jira are not known at all. GitHub is paid for, but never used. I am single weirdo in multi department project using github ticket system. The code with prefix is copied for colleagues to project’s shared folder. PostIt tickets on the table works good enough for others. Talking about bugs is impossible since nobody knows what’s fixed and what’s not, the bugs have date in the best case. Everything else is done in Excel sheets using in house written scripts. They usually end in a mess since some people use German regional settings and other English ones. That’s state-of-art situation in very rich and big company today. I don’t see any possible changes in future. Old boy club fights all the time against proposed improvements. You can forgot topics like information security, phishing, being silent about work topics outside the office. Hackers are known from the American movies only. On the other hand I also worked in opposite unhealthy paranoid environment. I was hired to design Ethernet camera, but Wireshark usage in their office was prohibited. Packet analysis was seen as the worst thing in the company. I quit after few months trying to explain, that I need to analyze the packets during design phase. I think, it’s very normal, that other countries abuse illiteracy of German industry.
- ChuckNorris89 7y agoGermany's tech illiteracy is a self-inflicted consequence of its pitiful salaries in this field, treating IT like a cost center that has to be outsourced to wherever is cheaper and companies' tradition of rewarding management incompetence over technical competence. Consequently, Germany's most brilliant tech minds leave for The Valley, Zurich or London. You reap what you sow.
- mschuster91 7y ago> treating IT like a cost center that has to be outsourced to wherever is cheaper As if outsourcing wasn't a common trend across Western companies "thanks" to globalization and the utter dominance of US-american neoliberalism. > and companies' tradition of rewarding management incompetence over technical competence Again, quite common - the "old" Soziale Marktwirtschaft moguls with decades-long visions would not let today's next-quarter-only shit fly for long. > Consequently, Germany's most brilliant tech minds leave for The Valley, Zurich or London. Care to have a source for SV and London? People avoid SV/USA due to the current President and London due to the Brexit uncertainity - in fact, whoever can flees from the UK before Johnson drives everything into the ground. Only correct point is Switzerland but that's not surprising since their wages run way, way higher than Germanys across the board...
- bobjordan 7y ago"Modern-day espionage operations have one big advantage: Instead of painstakingly planting agents in companies, digital spies are simply sending prepared emails." We face this threat in my business - daily fishing attempts or schemes to get employees to open files. It never stops. This is a primary reason when we started designing our new web app at bomquote.com a few years ago, we first focused on communication tools which reduce our use of email both internally and in our dealings with our customers. Sure, there will be attempts to hack our app servers, but from my view we can deal with that easier than preventing our accounting admin from clicking on a well crafted email.
- mtgx 7y agoUsing U2F security keys is one way to stop phishing if the app you're supposed to log into requires it. https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/ https://krebsonsecurity.com/2018/07/google-security-keys-neu...
- tgsovlerkhgsel 7y agoUnfortunately "phishing" nowadays is used to describe any kind of social engineering, including all variants of tricking the victim into executing malware on their machine. U2F won't save you there, it will just make the attack a bit more annoying.
- mehdix 7y agoIs there any business out there that does not use email?
- solarkraft 7y agoGood article. I am not so bothered by the effects, I think they complement the article well. I sure like that what may seem like decoration to some readers is actually real - I find it very interesting to find out that they find the malware using nmap. Now where do I get that script? More detail would of course always be nice.
- yorwba 7y agoGit repo was linked by OP in this [dead] subthread: https://news.ycombinator.com/item?id=20514267 https://news.ycombinator.com/item?id=20514267 The nmap script was written by ThyssenKrupp's security division and can be found here: https://github.com/TKCERT/winnti-nmap-script/blob/master/winnti-detect.nse https://github.com/TKCERT/winnti-nmap-script/blob/master/win...
- jamesmadison66 7y agopretty decent tech write-up from the German NPR
- logari 7y agoFinally, somebody said it. The English also very good, nay, excellent.
- rolltiide 7y ago> Winnti is a highly complex structure that is difficult to penetrate. The term denotes both a sophisticated malware and an actual group of hackers. Hacking groups are corporations and spread risk away from indictable individuals just as efficiently, with a separation of liability and actions and knowledge This needs to be understood