5 ms·
Operation Shady Rat Is The Largest Cyber Attack Ever Uncovered
- hluska 15y agoThanks for posting this - perfect read for right before bed!
- com 15y agoFascinating reading - my take-home is that US corporates are going to have to have disclosure rules whether they want to or not. The question is whether this will come from Congress or the regulators.
- est 15y ago> As spring gave way to summer, bloggers and computer-security experts found evidence that the attack on RSA had come from China They never say what evidence, which is the most interesting part of the article. Does anyone have a more detailed description of how they identified it was China?
- sp_ 15y agoI worked on the technical side of the RSA attack analysis and not the attribution/political side but some guy on Twitter (https://twitter.com/yuange1975 https://twitter.com/yuange1975) who pretends to be Chinese has claimed responsibility for the RSA 0-day and some other high profile 0-day exploits on his Twitter feed in a way that makes him the credible original source of those exploits. I am sure the people on the attribution side dug deeper than this (for example they most likely tried to verify that this guy is really Chinese and not just pretend-Chinese) but I don't know anything about the non-technical side of things.
- est 15y agoThat's cool. Much better than the blah acticle. 袁哥 is actually a very skilled hacker and reputable in China. IIRC He works for NSFocus, NSFocus used to be the de facto operator of China's G.F.W., it was replace by another firm after a Taiwan spy issue. edit: http://jeffreycarr.blogspot.com/2011/06/18-days-from-0day-to-8k-rsa-attack.html http://jeffreycarr.blogspot.com/2011/06/18-days-from-0day-to...
- dreww 15y agoWhile I support the opinions with regard to security and disclosure as presented, the rest of the article is regrettably lacking in detail, specifics, evidence, or attributable quotes on what has actually occurred. It's hard to say if this is just the typical style of a piece for general audiences on this topic, or the tail wagging the dog on attributing these things to china in the public eye. Frankly, what's more alarming; the dedicated resources of a single state actor, or a complex, emergent network of self-interested individuals and groups persuing their own aims? I find the Chinese explanation a little too convenient and a little too amenable to typical national defense thinking. What this article really says to me is that if you want to hack an American company, own a Chinese box first. Nobody will look any further.
- metachris 15y agoWhat this article really says to me is that if you want to hack an American company, own a Chinese box first. Nobody will look any further. Exactly -- it's pretty easy to rent a chinese box from one of the many botnets out there, and I guess that would be the first choice of an intruder to hide his trails.
- microarchitect 15y agoWhile your claim is a reasonable one, Dmitri Alperovitch's analysis (link in metachris's comment) of Operation Shady RAT strongly suggests that China is behind this operation.
- trotsky 15y agoThe truth is that both are happening. When you talk to people who are pragmatic and watch the strategic elements they are often saying things like "or someone operating with chinese cover". There is definitely evidence that other actors are using chinese IPs, working hours and techniques to muddy the water. But at the same time, a preponderance of evidence suggests strongly that a majority of these attacks are from chinese sources. Keep in mind that military and national security investigators - even private sector investigators - have access to a lot more intelligence about these matters than simply what IP launched what. So, yes, while some intrusions from china are undoubtedly the work of non-chinese it still makes sense to focus a lot of your efforts on the dragon in the room.
- metachris 15y agoA better account of the story at the McAfee Blog: http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady-rat http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady...
- dhimes 15y agoIn the comments of this the blogger notes that malware put in place to launch the exploits were all for Windows machines. It sounds like it mostly works by getting unwitting users to click on unknown emails. It's been 15 years and we're still doing that?
- checker 15y agoThere are plenty of non-tech-savvy people employed by the federal government/large companies. It's easy to underestimate how large a percentage it still is.
- jrwoodruff 15y agoNot quite 'unknown' e-mails as I would think of them - these were e-mails that appeared to be from co-workers and addressed specifically to another individual, hence spear-phishing, rather than just phishing. For all intents and purposes, it probably had all the appearances of a legit e-mail.
- dhimes 15y agoIf I understand it, then, someone opens the initial payload which allows malware to be downloaded- and this downloaded malware orchestrates the "spear phishing?" I haven't seen this as I've been out of an organization for quite a while. Thanks for clarifying.
- trotsky 15y agoThe documents and addresses used for high end spear phishing usually come from a recent previous compromise. You'll see a sender that you frequently get mail from and know personally and the document attached will be a new version of something they previously sent, or something new that person is working on that would be of particular interest. It is quite difficult to completely insulate even the smartest and most prepared organizations from persistent attacks like this - someone only has to screw up once, and people screw up a lot more than that.
- mrb 15y agoThe most shocking revelation IMO is that "less than 10 percent of [RSA's] customers have requested replacement tokens". IOW, everybody knows the entire SecurID system was compromised, yet 90% of its users decided to do nothing about it!
- patrickk 15y agoPerhaps some of them got replacements from RSAs competitors? (I'm not an expert in this area, that was my take on it.)
- trotsky 15y agoI believe that is weasely at best, I've been given the impression previously that over 50% of the tokens in active use had been switched out before the public announcement of the free replacements was made. Perhaps they're doing something like counting every company that bought a few for an eval and aren't using them.
- InclinedPlane 15y agoShocking perhaps but it shouldn't be terribly surprising. Cargo cult behavior (imitation devoid of knowledge or critical thinking) tends to be the norm rather than the exception. In security as in elsewhere.
- niyazpk 15y agoThe sidebar can be slightly NSFW. Here is a version of the same article without the distractions: http://www.vanityfair.com/culture/features/2011/09/chinese-hacking-201109?printable=true http://www.vanityfair.com/culture/features/2011/09/chinese-h...
- lobo_tuerto 15y agoSo much drama, handwaving and name calling in this VF's article...
- NY_Entrepreneur 15y agoLet's review Computer Security 101 with a case study in Mainstream Media Morality Play Nonsense 102: The article is garbage. Nonsense. Brain-dead. Trying to jerk people around by the gut. 'Vanity Fair' is for what, overly emotional, determinedly non-technical, easily scared, fundamentally incompetent and, thus, dependent, young woman who want to gossip about fashion and celebrities? If the article had anything, then it would have explained something solid; since nothing solid was explained, it must not have had anything. So, the article starts with: "Lying there in the junk-mail folder, in the spammy mess of mortgage offers and erectile-dysfunction drug ads, an e-mail from an associate with a subject line that looked legitimate caught the man’s eye. The subject line said '2011 Recruitment Plan.' It was late winter of 2011. The man clicked on the message, downloaded the attached Excel spreadsheet file, and unwittingly set in motion a chain of events allowing hackers to raid the computer networks of his employer, RSA. RSA is the security division of the high-tech company EMC. Its products protect computer networks at the White House, the Central Intelligence Agency, the National Security Agency, the Pentagon, the Department of Homeland Security, most top defense contractors, and a majority of Fortune 500 corporations." and in particular: "The man clicked on the message, downloaded the attached Excel spreadsheet file, and unwittingly set in motion a chain of events allowing hackers to raid the computer networks of his employer, RSA." Garbage. Absolute reeking, fuming, bubbling, flaming, smelly, gooey, sticky, yucky nonsense. So, he received an e-mail message. Okay, we're talking likely post office protocol 3 (POP 3). Back when I was using OS/2 and had no decent e-mail software, I took out an afternoon and wrote my own POP 3 client e-mail software. I used it for years. I'm about to ditch Outlook 2003 and return to what I wrote (in Rexx) on OS/2. Gotta tell you, no way, not a chance, was there any way to infect my computer by sending me e-mail. Not in this galaxy. Send me anything you want, pictures, viruses, root-kits, Flash, infected, 'active' PDF files, EXE files, Active-X files, spreadsheets, etc., and no way will my computer be 'infected'. Just impossible. Why: First, the data that comes via POP 3 is lines of text of just 8 bit characters. Period. At the beginning are the 'header lines'. The end of the header lines is denoted by one blank line. The rest of the e-mail is just the 'body', and it is just more lines of text of 8 bit characters. Harmless. It's just some simple minded data as lines of 8 bit characters. Can put the data in an ordinary file, edit it with an ordinary editor, view it on the screen, print it out, etc. All harmlessly. The body may have a PDF file, a movie, some audio, some Flash, and EXE file, a spreadsheet, etc., and still it's all just harmless data. Period. If there is one or more 'attachments', then each of these is delimited by a line with some text indicated in the header. Each such attachment is just more lines of text. To permit sending any data at all, these lines of text consist of just 65 simple-minded, old ASCII printable characters. You can print them out, and they won't hurt you, steal your bank records, install software on your computer, etc. They are 100% harmless. Those 65 characters are part of a scheme called 'base 64 encoding' which is part of the e-mail 'multi-media internet mail extensions' (MIME). For such an attachment. can follow the base 64 rules and 'decode' the attachment back to the original data in the file. The file, then, will be a sequence of 8 bit bytes. Give the file any name you want and put it in any directory ('folder') you want. Yes, you do NOT want to put the file where other software will use that file without your knowledge; but why would you do that? E.g., don't overwrite some important operating system DLL file. The file may be in the format of an EXE file, JPG file, GIF file, PNG file, XLS file, etc. Still it is just a file, just a sequence of bytes. Like any other sequence of bytes, it's harmless, will not cause blindness, falling hair, black toenails, or an infected computer. You can copy it, back it up, send it as an attachment via e-mail, etc. all harmlessly. The file can be a virus, a root-kit, a Trojan, malicious, malevolent, nasty, etc., but STILL is just 100% harmless, safe, and innocuous. No rubber gloves needed. Now, if the computer is being used by a total dummy, idiot, drooling on the keyboard, licking the screen, etc., then there might be a threat: The rube might permit such a file to execute as software on their computer. Dumb. Stupid. Brain-dead. Don't do that. Never do that. First rule of computer security: Never, ever permit data from an untrusted source to execute as software. Never. Ever. Don't do that. So, if there was a computer security problem, then it was NOT the e-mail, the attachment, or the spreadsheet but JUST some total idiot who let such an attachment execute as software. Any author of any e-mail program that lets data execute as software without very explicit approval of a user should be dragged through the streets while peasants throw garbage, two week old dead animals, night soil, upchuck, toxic witch's brew, effluent from tanning animal skins, etc., racked, excoriated, eviscerated, drawn, quartered, hung, dried, roasted, and fed to sick animals.