3 ms·
I have no stake in this, but here are my points of opposition to that linkedin article: 1. don't need GPS permissions for location data (IP address is still va
by codezero 6y ago
I have no stake in this, but here are my points of opposition to that linkedin article:
1. don't need GPS permissions for location data (IP address is still valuable intelligence especially if I'm spear phishing my target(s))
2. the claim that the app is outdated and doesn't use the internet misses the point (I would add emphasis if I could)
re 2: what crowdstrike describes is an effort to get people to download a fake version of the same app, which has added features/tracking.
note the disparity in quotes:
Linked Quote (link is broken, but from Crowdstrike CEO): Russian hackers … tricked Ukrainian servicemen into downloading a contaminated version of the software - https://www.telegraph.co.uk/news/2016/12/22/russia-linked-dnc-hackers-targeted-ukrainian-army/ https://www.telegraph.co.uk/news/2016/12/22/russia-linked-dn...
Poster: Crowdstrike claimed that the GRU identified a targeting app, wrote malware for it, and used the compromised apps to geolocate and bomb their artillery.
See - this is not what's being said, we're mincing words. The attack, as I understand it, is they found an app they knew their target used. Made a fake version, and spear phished people (let's say, all new recruits) into downloading their malware version. What happens after that is wide open. GPS, location, network connection, anything, we can't say (probably Crowdstrike can) so the Ukranian soldier who made the app saying his version wasn't compromised is totally besides the point.