4 ms·
Convince me it’s more sophisticated than Stuxnet.
by jdxcode 6y ago
Convince me it’s more sophisticated than Stuxnet.
- rafale 6y agoAgreed. It's amazing how they managed to infect air gapped computers. How do you even test something like that before the actual attack.
- millzlane 6y agoCompromise an employee.
- wwww4all 6y agoMost people know which countries developed stuxnet and used compromised human agents to place the infected drives into the target system. The sophistication of the malware required state powers and assistance of the industrial company that manufactured the control systems. Those systems are not cheap and reverse engineering the control system software required detailed knowledge of the embedded hardware and software.
- talhah 6y agoFrom what I've read and heard about the attack in the past, they had managed to find the supplier and had confiscated some blueprints or the actual structures (nuclear reactor?) that was used and then reverse engineered it from there with the help of nuclear scientists to find vulnerabilities in it.
- _kbh_ 6y agofrom what I understand, they have the same controller that was being used in the centrifuges on their desk to develop the payload the rest was just a way to get to the controllers of the centrifuge which was rather standard.
- stevemk14ebr 6y agoIt's not a zero sum game. It is interesting in that it marks the first _wide spread_ attack on a supply chain via cyber space. The malware's DNS signaling protocol is pretty neat, which you can look at here: https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html https://www.fireeye.com/blog/threat-research/2020/12/sunburs...
- bawolff 6y agoThe headline is "most sophisticated ever" not "totally boring". SolarWinds can both be a very interesting thing and the headline can also be hyperbole.
- code-scope 6y agohttps://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach https://en.wikipedia.org/wiki/2020_United_States_federal_gov... On December 8, 2020, the cybersecurity firm FireEye announced that red team tools had been stolen from it by what it believed to be a state-sponsored attacker.[106][107][108] FireEye was believed to be a target of the SVR, Russia's Foreign Intelligence Service.[27][109] FireEye says that it discovered the SolarWinds supply chain attack in the course of investigating FireEye's own breach and tool theft.[110][111] After discovering that attack, FireEye reported it to the U.S. National Security Agency (NSA), a federal agency responsible for helping to defend the U.S. from cyberattacks.[1] The NSA is not known to have been aware of the attack before being notified by FireEye.[1] The NSA uses SolarWinds software itself.[1]
- lamestreetmedia 6y agoAt it's core, Stuxnet is basic. Stuxnet didn't do what that Blugarians did. Stuxnet was not polymorphic.
- xxpor 6y agoThe delivery was the really impressive part of stuxnet, IMO. Which wasn't technical at all.