7 ms·
Solarwind, Fireeye, Microsoft and Cisco leaks are offered for sale
- jamescun 6y agoBear in mind that the "results" of a notorious hack are often offered for sale as a diversionary technique, and in particular this offers up nothing beyond commercially sensetive information, if even legitimate at all.
- ryanlol 6y ago>often I really don’t like doing this, but [citation needed]
- semicolon_storm 6y agoWhat evidence is there that this is actually the SolarWinds hackers and not someone who uploaded some random encrypted files and is hoping to trick people into sending them money? There’s a PGP signature, but as far as I’ve head the attackers didn’t leave behind any other messages to prove it was signed with the same key.
- piracy1 6y agoAnd it does not seem a very serious attempt either. The only way to make this deal is through a single listed protonmail address that if this gets any traction will be closed in all likelihood. Not like an onion site with a contact page or something.
- sudosysgen 6y agoNot really. The message is PGP signed. If the protonmail address is taken down, then another message will be put out with alternate means of contact that will have a correct PGP signature. If you read the message there is indeed an onion address as backup in case things get taken down. The PGP address is the important part. No matter what gets taken down, if they can get attention to another message with a valid PGP signature, then they can carry on easily. EDIT: This is actually how Cicada3301 of all people operated. The PGP key allowed them to post a message even on Pastebin or /x/ and they would still be contactable and effectively uncensorable, because their identity was persistent and their messages were replicated.
- brobdingnagians 6y agoI've always wondered how effective this sort of info security is. Could a state actor track down there sorts of operations, or can infosec be good enough to really leave no trace?
- sudosysgen 6y agoIt's not that hard to do this kind of thing without leaving any solid trace at all. A way to do it for example would be to use a stolen credit card to subscribe to a few VPN with hops on Tor in between and use that to set up a VPS that puts this up after a few weeks The devil is in the details, but if you're careful you can leave absolutely no trace.
- deleted 6y ago[deleted]
- bouncycastle 6y agoAlthough, the more they interact with the internet, the more clues they leave behind. Things like Tor can be deanonymized, and even Tor has a warning. Quote: "Generally it is impossible to have perfect anonymity, even with Tor." Source: https://support.torproject.org/faq/staying-anonymous/ https://support.torproject.org/faq/staying-anonymous/
- Proven 6y agoRight, I'm sure they don't know about this and continue to use Tor from the comfort of their homes.
- monsieurbanana 6y ago> Although, the more they interact with the internet, the more clues they leave behind Interacting with a tor browser would be amateurish at this point. Just connect to tor (not on a browser, tor directly), use a script to upload to some random pastebin, disconnect from tor.
- autoro 6y agoI think we can't know for sure unless they will release some of it like the shadow brokers did. But the shadow brokers show that it is possible for hackers with high valuable leaks to post it for sale in the public Internet.
- forgotmypw17 6y agoStrange that there is no public key provided... You can't verify a signature without a public key.
- sudosysgen 6y agoYou can extract the public key from the signature. This public key is E2C73BC53B9118A0. If you want to have a go at it yourself, run gpg -vv and paste the entire message, it will give you the public key.
- forgotmypw17 6y agoNo, you cannot extract the public key from the signature. It is only telling you the fingerprint of the key the message claims to have been signed with, but there is no verification happening. You can change part of the message or the encoded fingerprint (which is a bit longer than the portion you pasted), and it will still report it the same way. However, you will not be able to mathematically verify that this message and another one was signed by the same key. If you look carefully at what GPG is telling you, probably see a line like this, unless you have the key in keyring: gpg: Can't check signature: No public key
- sudosysgen 6y agoYes, you're right, this is only the ID, you'd need to get the actual key off a keyserver.
- forgotmypw17 6y agoAlso, let us not forget the possibility that there may not even be a key to begin with. :)
- malwarebytess 6y agoUsually for this kind of thing samples are provided. This attacks feels too sophisticated for a mere sale. At best, if this is legitimate, it's misdirection.
- jinkyu 6y agoneeds proof of life. none of the "vendors" will consider it without proof. in-fact they would likely verify if they were real dumps.
- buildbot 6y agoWindows source is open to most people at Microsoft IIRC, so I’m not sure why you’d pay 500k for that...
- xtanx 6y agoIf that was true, I am pretty sure that the entire windows source would be all over the internet.
- deleted 6y ago[deleted]
- intern4tional 6y agoDisclaimer: Am Microsoft. Windows source is open to most people at MS. MS is not joking when it says we practice an "inner source" policy, in that we do not rely on the security of our source code to secure our products.
- SteveNuts 6y agoMy question then is why is windows not just open source entirely? Be like Red Hat where the OS is open but you pay for support, I don't know why that model wouldn't work for MS.
- sbarre 6y agoNot OP (and not Microsoft), but I would say it's a complicated road to get there. I do believe we will see open source Windows in... the next decade? Anyone want to take a longbet with me? ;-)
- ampdepolymerase 6y agoI am willing to add to the pool, I am also betting core components of Windows will be open sourced soon.
- deleted 6y ago[deleted]
- liquidify 6y ago"Serious buyers only: solarleaks@protonmail.com - - Q: Is this really happening? Can you provide proof? A: Yes and yes. Q: Why no more details? A: We aren't fully done yet and we want to preserve the most of our current access. Consider this a first batch. Q: I'm [vendor] and want my data back? A: Talk to us. Q: Why not leak it for free? A: Nothing comes free in this world. Q: How to buy? A: Contact us for more information." These don't sound like things that the Russian government or any nation state would be saying. Makes the U.S. intelligence / media look stupid. And if it turns out that it is some individuals that happen to live in Russia, it still makes the U.S. look stupid.
- willxinc 6y agoAre the US intelligence community / media saying that the attack was by the Russians?
- 1MachineElf 6y agoYes https://thehill.com/policy/cybersecurity/532756-us-intel-agencies-blame-russia-for-massive-solarwinds-hack https://thehill.com/policy/cybersecurity/532756-us-intel-age...
- willxinc 6y agoAh, thanks for the source / context.
- zwp 6y agoWashington Post attributed the attack to Russian actor APT29/Cozy Bear on Dec 14th [1], quoting unnamed sources. FireEye [2] Dec 13th & Volexity [3] Dec 14th were more cautious, citing an unknown actor that they dubbed UNC2452, and Dark Halo, respectively. Recorded Future made a fair but ultimately inconclusive case for Chinese attribution [4], Dec 30th. US gov/CISA continues to claim "Russian linked" [5], Jan 5th. Kaspersky reported a link to the Kazuar malware used by Russian actor Turla [6], Jan 11th. CrowdStrike's report on the malware injector [7], Jan 11th says "does not attribute the SUNSPOT implant, SUNBURST backdoor or TEARDROP post-exploitation tool to any known adversary". [1] https://www.washingtonpost.com/national-security/russian-government-spies-are-behind-a-broad-hacking-campaign-that-has-breached-us-agencies-and-a-top-cyber-firm/2020/12/13/d5a53b88-3d7d-11eb-9453-fc36ba051781_story.html https://www.washingtonpost.com/national-security/russian-gov... [2] https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html https://www.fireeye.com/blog/threat-research/2020/12/evasive... [3] https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/ https://www.volexity.com/blog/2020/12/14/dark-halo-leverages... [4] https://www.recordedfuture.com/solarwinds-attribution/ https://www.recordedfuture.com/solarwinds-attribution/ [5] https://www.cisa.gov/news/2021/01/05/joint-statement-federal-bureau-investigation-fbi-cybersecurity-and-infrastructure https://www.cisa.gov/news/2021/01/05/joint-statement-federal... [6] https://securelist.com/sunburst-backdoor-kazuar/99981/ https://securelist.com/sunburst-backdoor-kazuar/99981/ [7] https://www.crowdstrike.com/blog/sunspot-malware-technical-analysis/ https://www.crowdstrike.com/blog/sunspot-malware-technical-a...
- jasonhansel 6y agoWhy isn't mega.nz removing these?
- pfundstein 6y agoI think they have a pretty strong anti-censorship stance, and due to the way the data is en/decrypted on the client side, they have no visibility what the data consists of. On top of that, the data here (which is posted with the mega.co.nz decryption keys standard as part of the URL) has an additional layer of encryption by the uploader, so for all anyone can prove it's pictures of cats, and not anything illegal.
- djkoolaide 6y agoOn the other hand, they know exactly what the uploader claims the files are. If they don't take the files down and these turn out to be real, they could be held responsible.
- Thorrez 6y agoIt looks like mega.nz has now removed them.
- sudosysgen 6y agoThe PGP key is E2C73BC53B9118A0. I can't find it on any keyserver, yet.
- shakna 6y agoThat key isn't the one linked to the Protonmail account either. [0] (You'll get a payload of all linked public keys with that link). [0] https://api.protonmail.ch/pks/lookup?op=get&search=solarleaks@protonmail.com https://api.protonmail.ch/pks/lookup?op=get&search=solarleak...
- bflesch 6y agoThis is a nice way to verify Protonmail addresses. Is this API publicly documented?
- shakna 6y agoThat particular part is detailed on the knowledge base [0], so... Yes? For just this bit. But I don't think the full API is documented. There are some attempts to reverse engineer an API from the WebClient [1], but they tend to be... Brittle. [0] https://protonmail.com/support/knowledge-base/download-public-private-key/ https://protonmail.com/support/knowledge-base/download-publi... [1] https://github.com/ProtonMail/WebClient https://github.com/ProtonMail/WebClient
- ROARosen 6y agoWonder if mega.nz will not block this download.
- beprogrammed 6y agoIt appears they have. " The file you are trying to download is no longer available. This link is unavailable as the user’s account has been closed for gross violation of MEGA’s Terms of Service. "
- collsni 6y agoData also off root. http://solarleaks.net/feye.tgz.enc http://solarleaks.net/feye.tgz.enc
- lemonspat 6y agoautoro- I have to ask, did you publish this yourself? It’s your only submission and your only comment
- autoro 6y agoYes, I did (off course this message can't prove it in any way). I am usually a silent reader in NH but I saw there was no submission to this topic so I submitted it.
- f430 6y agoSo what sort of return would someone buying this expect?
- dmix 6y agoBuying a .net domain with a cryptocurrency I presume? Anyone know what service they'd use for this?
- snypher 6y agoDns is with https://njal.la/ https://njal.la/
- bdd 6y agoLooks like they used Njalla (https://njal.la https://njal.la) a provider that seems to focus on "privacy aware" domains and virtual private servers hosted in Sweden. According to their FAQ, when you register a domain name through them, they own the domain but they respect the agreement between them and the customer to let the customer have "full usage rights". They seem to provide rather fun named name servers. Reads "you can get no info". dig +short ns solarleaks.net | sort 1-you.njalla.no. 2-can.njalla.in. 3-get.njalla.fo. They accept a bunch* of cryptocurrencies and then PayPal. [*]: "Bitcoin, Litecoin, Monero, ZCash, DASH, Bitcoin Cash, Ethereum"
- pfundstein 6y agoInteresting tidbit: This "dns by proxy" service was founded by The Pirate Bay founder, Peter Sunde.
- hikerclimber 6y agonice! hopefully there are more leaks!
- Jerry2 6y agoSo, this was not a nation state hack?
- perlgeek 6y agoOr this is a distraction to make it look like not a nation state hack.
- mNovak 6y agoI guess I'm curious to understand who has the money and motivation but not risk to spend $1M on stolen data?
- King-Aaron 6y agoI'm actually interested to know what the (+ Bonus) is
- ALittleLight 6y agoSeems expensive and you'd have to trust that admitted data thieves would give you the data after you paid them.
- nix23 6y agoIs it just me or does that not sound as if it's a "state sponsored attack"? Or maybe a tactic to distract from one?
- mcintyre1994 6y agoIIRC the Russian NotPetya attack on Ukraine was disguised as ransomware requesting Bitcoin, so there is some precedent for a state sponsored attack pretending to be criminals trying to make money.
- deleted 6y ago[deleted]
- Closi 6y ago...So they want 16k USD non-refundable just to talk, before they even show any proof? Lol.