4 ms·
> That is my question as well, without getting their hands on the machine, how do the attackers start the attacks? And in case of AWS, since everything is so vi
by 394549 8y ago
> That is my question as well, without getting their hands on the machine, how do the attackers start the attacks? And in case of AWS, since everything is so virtualized, does it make sense to install a hardware backdoor if it cant even map to your true target?
Nation states have the manpower for spray-and-pray attacks. They have less need for precise targeting.
> It could probably make more sense as a backdoor when the hackers get hold the access to the physical device, it is however quite incredible to me that this hack is designed for a remote network access, and could go unnoticed from infosec within the company if it is truly sending packets outside the firewall...
How is it incredible? Infosec isn't perfect. Equifax was hacked in part because their IDS system was offline due to an out-of-date certificate [1]. That system would have caught the exfiltration of data if it had been active.
Also, Amazon AWS must have all kinds of crazy traffic flowing through its network due to its customers. My gut feel is that it would be incredibly hard to characterize that traffic in order to proactively detect many kinds of nefarious traffic. The Bloomberg article stated they were easily able to find the traffic from these implants...but only after they knew what to look for.
[1] https://www.bankinfosecurity.com/postmortem-behind-equifax-breach-multiple-failures-a-11480 https://www.bankinfosecurity.com/postmortem-behind-equifax-b...