3 ms·
What exactly does this NSA tool do? Every story I've seen glosses over how it works.
by mgalka 9y ago
What exactly does this NSA tool do? Every story I've seen glosses over how it works.
- jgaa 9y agoIt seems this one was designed to shut down hospitals ;)
- erikbye 9y agoThe tools in reference are from the Equation Group dump the Shadow Brokers did. Equation Group is believed to be the NSA (a group within). EG activity dates back to at least 1996. More info on EG: https://securelist.com/files/2015/02/Equation_group_questions_and_answers.pdf https://securelist.com/files/2015/02/Equation_group_question... The dump contains many tools; but the ones used in this attack are two exploits for vulnerabilities in Windows SMB (Server Message Block, a file sharing protocol) implementation. Microsoft patched this in March, but as we all know, many systems remain unpatched. The vulnerabilities allowed for remote code execution. Practical exploit info: https://www.exploit-db.com/docs/41896.pdf https://www.exploit-db.com/docs/41896.pdf The two exploits, EternalBlue and EternalChampion targets respectively SMBv2 and SMBv1. That's not how the ransomware gets inside the network in the first place though, that is done by a user executing a file received via email, or downloaded from a received URL. But, through these two exploits, once inside, it can spread through the network (subnet) worm-like. Actually, the ransomware first checks for the existence of the backdoor (also from the same dump of tools) called DoublePulsar. If the ransomware does not find it to be implanted, it will use one of the two aforementioned exploits, based on which ports and protocols it makes a connection to. The DoublePulsar backdoor is installed on at least 400,000+ systems worldwide. You can read more about it here: https://countercept.com/our-thinking/analyzing-the-doublepulsar-kernel-dll-injection-technique/ https://countercept.com/our-thinking/analyzing-the-doublepul...