6 ms·
At the moment, this is an active incident with response still going on. The attackers likely have persistence in multiple places in target networks. Releasing
by intern4tional 6y ago
At the moment, this is an active incident with response still going on. The attackers likely have persistence in multiple places in target networks.
Releasing attribution evidence right now will not happen as that would intrude on the response. Instead you will get signatures for specific pieces of malware or generalized yara rules to look for indicators of compromise. The specific indicator that allowed for attribution may never be released as then this particular adversary could work around it.
FireEye is a reputable security organization that is publicly traded. If they were lying and it was discovered as a company their business would go away rapidly and some of their executives might even go to prison. If you have legitimate evidence that casts doubt on their statements please share it. Finding something that significant would shake up the industry.
Attribution is most likely a combination of evidence and forensic data collected both from the initial breach (SolarWinds) and other breached entities. Things like how data was exfiltrated and to where to who purchased and setup the domain names, any other malware that was loaded (was it signed, compiled, contain a certificate, etc).
While Snowden did reveal interesting things, there is zero basis to support anything other than a Russian state actor at this time.
- oxygenjoe 6y ago>FireEye is a reputable security organization that is publicly traded. If they were lying and it was discovered as a company their business would go away rapidly and some of their executives might even go to prison. I think a more likely outcome would be their stock price would drop for a few weeks, maybe executives would resign, and then it would be forgotten.
- ralph84 6y ago> FireEye is a reputable security organization that is publicly traded So was RSA when they accepted $10 million from NSA to backdoor their crypto library. As long as FireEye keeps the customers who pay the bills happy they'll be fine, just like RSA was.
- wp381640 6y agoIt's hilarious to say that RSA were ever reputable - they were the butt of every insider infosec joke for decades. We _knew_ at the time that Dual EC_DRBG was bad - there is an entire openssl mailing list archive from the moment it was announced/proposed talking about it being bad FireEye / Mandiant are _the_ team within infosec who are experts in the field of attributing state threat actors - you won't find many experts who openly disagree with them
- jessaustin 6y agoIt could be that no one disagrees with them because they're always right. Another possibility is that there's only so much "attribution" business to go around, and the customer is always right. The very idea of worrying more about who walked in the open door than about closing the door is a sure sign that "politics" has taken over completely.
- jc01480 6y agoGiven the fact their CEO is former USAF OIS and has handled this event magnificently using ethics and morals as a guide I seriously doubt they’re hiding anything. They discovered the biggest cyber espionage campaign in the 21st century. And took a few punches to the gut in the process. They are setting a model disclosure example. Unlike the other compromised organizations that won’t admit a damn thing until they’re seated in front a legislative board of inquiry or grand jury.