4 ms·
How are they finding out in the first place? Either they have the capability to watch and decrypt the overall public traffic or they are already inside themselv
by solotronics 7y ago
How are they finding out in the first place? Either they have the capability to watch and decrypt the overall public traffic or they are already inside themselves.
- netsharc 7y agoParanoid much? Other ways could be intelligence work: the FBI might be monitoring "hacker" hangouts and someone bragged about it/is selling access. If it was a nation state: The CIA might be inside their system (technically or personnel-wise) and saw evidence, and told the FBI.
- streb-lo 7y agoOr someone trying to sell credentials or info from xyz.com tips people off in a hurry. Do we always need to jump straight to conspiracy...
- NickNameNick 7y agoUsually it will be because they were investigating something else, and either seized a hackers device, or gained access to a hackers servers. Device or servers will then have evidence of the other things the hacker and thier associates have been doing. Sometimes criminals brag about things. Other times, the compromised infrastructure is used in other criminal activity that gets detected by the next victim, and the law enforcement agencies work thier way back.
- mox1 7y agoThe NSA will pass information like this to the FBI as well (through the NCIJTF). They usually omit / redline enough information to make it Unclassified.
- kortilla 7y agoDuring other takedowns the FBI will seize a C&C server. They can then see which IP addresses it has talking to it.
- Spooky23 7y agoThere are a few programs where they get visibility. The fusion centers in each state, for example can detect some of this type of activity.
- miscPerson 7y agoThe FBI has a whole threat intel sharing program — actually, several. In this case, it could be as simple as another company noticed a breach that was reporting back to Citrix-hosted C2 and contacted the FBI, who passed the message along. Hosting C2 on compromised Citrix assets would be a great way to evade detection in a corporate environment.