5 ms·
So your theory is, because they didn't release the Cozy Bear signatures, that it must be CIA/NSA? That's a huge stretch to the opposite side of the conspiracy.
by lemonspat 6y ago
So your theory is, because they didn't release the Cozy Bear signatures, that it must be CIA/NSA? That's a huge stretch to the opposite side of the conspiracy. How do you explain the hacking of the Treasury and other government agencies in your scenario?
- djsumdog 6y agoI'm just wondering what the hell a "signature" is in this context? You think Cozy Bear is leaving their name in the binary? It's just a lot of security-by-obscurity hand waving. It's FireEye spewing out stuff as "facts" with very little evidence.
- iou 6y agoA signature in this context nearly always means an IoC: https://en.wikipedia.org/wiki/Indicator_of_compromise https://en.wikipedia.org/wiki/Indicator_of_compromise Which in weak cases can be an artifact observed throughout the attacks though not necessary for the behaviour to occur (e.g. compiler timestamp), and in strong cases the artifact is tied directly to the malicious behaviour (e.g. explicit registry key or anti-infection marker)
- jc01480 6y agoOr obfuscating your C&C communications in mundane hash functions that appear to be routine periodic checks of file integrity. Exfiltrating your data the same way. They lived off the land and modified code. Pure genius, yet they poked a beehive. Wait for the full disclosure on this one. Impacted agencies and businesses are still assessing the scope of compromise. If you look around and see government businesses that were down over the holidays “upgrading their environment”, that would be a clue. What is frustrating is the number of agencies fully compromised in every respect yet they’ve not disclosed anything. Congress is gonna mindblow in about 6 months. And quite a few state legislative bodies as well. All those orgs hiding what we already know.
- FPGAhacker 6y agoYou can’t seriously expect intelligence gatherers to disclose something like that to the general public. It would become worthless. They’d never be able to use it again.
- kordlessagain 6y agoOh "they" can and will dream up stuff like this and then hash it over and over again, even though there was a post about this just yesterday how rehashing things over and over is pretty pointless. Even if US intellegence is pinning it on Russia or it was someone else, there's no way we're going to know about it right now.
- jc01480 6y agoThis event will be a central security topic in academic studies for years to come. It is a literally fascinating design.
- kordlessagain 6y agoThe cloud is seriously the most irrational thing we've done to ourselves and the investors merrily agreed to it's fascinating design and threw money at it makin the problem worse, maybe.
- intern4tional 6y agoAt the moment, this is an active incident with response still going on. The attackers likely have persistence in multiple places in target networks. Releasing attribution evidence right now will not happen as that would intrude on the response. Instead you will get signatures for specific pieces of malware or generalized yara rules to look for indicators of compromise. The specific indicator that allowed for attribution may never be released as then this particular adversary could work around it. FireEye is a reputable security organization that is publicly traded. If they were lying and it was discovered as a company their business would go away rapidly and some of their executives might even go to prison. If you have legitimate evidence that casts doubt on their statements please share it. Finding something that significant would shake up the industry. Attribution is most likely a combination of evidence and forensic data collected both from the initial breach (SolarWinds) and other breached entities. Things like how data was exfiltrated and to where to who purchased and setup the domain names, any other malware that was loaded (was it signed, compiled, contain a certificate, etc). While Snowden did reveal interesting things, there is zero basis to support anything other than a Russian state actor at this time.
- oxygenjoe 6y ago>FireEye is a reputable security organization that is publicly traded. If they were lying and it was discovered as a company their business would go away rapidly and some of their executives might even go to prison. I think a more likely outcome would be their stock price would drop for a few weeks, maybe executives would resign, and then it would be forgotten.
- ralph84 6y ago> FireEye is a reputable security organization that is publicly traded So was RSA when they accepted $10 million from NSA to backdoor their crypto library. As long as FireEye keeps the customers who pay the bills happy they'll be fine, just like RSA was.
- wp381640 6y agoIt's hilarious to say that RSA were ever reputable - they were the butt of every insider infosec joke for decades. We _knew_ at the time that Dual EC_DRBG was bad - there is an entire openssl mailing list archive from the moment it was announced/proposed talking about it being bad FireEye / Mandiant are _the_ team within infosec who are experts in the field of attributing state threat actors - you won't find many experts who openly disagree with them
- strictnein 6y agoWeird that you're on this thread saying it's not the SVR, and you're on the vaccine thread saying that's a bunch of nonsense. I'm sure that's just random though. SANS isn't some secret government group - I have a colleague who is an instructor there. Those recordings aren't some top secret briefings. I and a lot of other industry professionals attended them > " It's FireEye spewing out stuff as "facts" with very little evidence." An APT has certain TTPs that allow you to start to figure out who is behind attacks. FireEye has tracked the attacker as UNC2452, which means it is "uncategorized" in their view. Others have come forward pointing fingers at the SVR. Finally, just a tip: if you want to sound like you know what you're talking about, it's not a "CNC" it's a "C2".
- djsumdog 6y agoI'd appreciate it if you kept arguments to the topic on this thread. Looking up other topics and condemning people for their opinions is not cool. It's becoming a large problem in a lot of online forums. All of us have a lot of different opinions and they vary. This isn't Reddit. > SANS isn't some secret government group I understand that, but the video/livestream they released at the time was Unlisted on YouTube and had a watermark saying it wasn't for general release. I realize they didn't intend to have it up permanently and am familiar with the roles SANS has in the security industry. I was just commenting on the video and things I think they got wrong. > Finally, just a tip: if you want to sound like you know what you're talking about No need to be insulting. I've heard them called Command and Control servers before. I don't currently work in security; haven't in years. I'm just speaking as as developer/sysadmin.
- deleted 6y ago[deleted]
- nl 6y ago> I'm just wondering what the hell a "signature" is in this context? If you genuinely don't know how companies like FireEye do attribution then one has doubt the level of insights you have. Notably in this case FireEye said they COULD NOT attribute the attack to any group initially: "FireEye wouldn't confirm the APT29 attribution and gave the group a neutral codename of UNC2452, although several sources in the cyber-security community told ZDNet the APT29 attribution, done by the US government, is most likely correct, based on current evidence" https://www.zdnet.com/article/microsoft-fireeye-confirm-solarwinds-supply-chain-attack/ https://www.zdnet.com/article/microsoft-fireeye-confirm-sola...
- dillondoyle 6y agoand there's serious planning right now on appropriations to fix this... e.g. buying a huge amount of new computers and hardware + staff time seems very very far fetched. i guess if i got caught breaking a ton of laws against my own government I might want to misdirect too this seems like the same trolling type comment farm crap we see anytime these countries come up