15 ms·
DEV-0537 targeting organizations for data exfiltration and destruction
- judge2020 5y agoHas there been any other high-profile uber-public data leaks before LAPSUS? Before the last few months it seemed like every data breach was simply documented with the assumption being that the dump would be sold on tor hidden services, but now it’s in an open-access telegram with thousands of benign citizens waiting for the next treasure trove of data to be dropped.
- octoberfranklin 5y agothousands of benign citizens who couldn't figure out how to install the tor browser bundle?
- Shank 5y ago> but now it’s in an open-access telegram with thousands of benign citizens waiting for the next treasure trove of data to be dropped. The extortion model is interesting because you can flip-the-script and just extort the company and if they don't pay, you leak it. The upshot to this approach is that for LAPSUS$, it increases their reputation and credibility for future attacks. In the "old model" where you try to sell the data leak itself, you still have to find a willing buyer and negotiate a price. The nice thing about the new model is that it eliminates the search for a buyer and a price, and leaking the data is free marketing. It's kind of a win/win. Either they get paid in cash or they get paid in clout. There have been high profile uber-public data leaks before LAPSUS$, but I don't think many have been married to a "business model" like this. E.g., Epik got hacked, but that was ideological. Same with Hacking Team, Equation Group, arguably all of Snowden's stuff. LulzSec was infamous for just doing things for fun, not for cash.
- toyg 5y agoI don't see the novelty. This was already happening in the 90s, and it fell out of favour only because interacting with the victim is risky: like in the movies, the second call you make to the family, after kidnapping somebody, will have the authorities listening in. Shopping data around the underground is much less likely to attract attention. The fact these guys prefer to go back to basics imho is a sign of inexperience or extreme certainty they won't suffer consequences (i.e. because they're unreachable by US authorities).
- batch12 5y agoShadow Brokers is one https://en.m.wikipedia.org/wiki/The_Shadow_Brokers https://en.m.wikipedia.org/wiki/The_Shadow_Brokers
- j4yav 5y ago> Their tactics include … intruding in the ongoing crisis-communication calls of their targets. That’s certainly a bombastic way to go about things.
- daenz 5y agoThis is wild. What is the psychology behind this group? If they're not deploying ransomware, it seems like their purpose is to penetrate companies "because they can." Publicly offering to pay employees for credentials is a dynamic that I've never heard, and in a rule-less game, seems like it breaks new rules.
- learndeeply 5y agoIt's not ransomware, but just extortion. Pay up or your files will be released. https://www.wired.com/story/lapsus-hacking-group-extortion-nvidia-samsung/ https://www.wired.com/story/lapsus-hacking-group-extortion-n...
- staticautomatic 5y agoWhat’s especially scary is the possibility that any employee whose credentials are stolen may be investigated for conspiracy.
- encryptluks2 5y agoSeems like maybe there is some political ambitions behind the group. Maybe anarchy aspirations?
- mardifoufs 5y agoYeah they are selling some of the exploits (the low hash rate enable on nvidia cards) but even then they say that with what they released it up until now it would be possible to figure out the way to do it by yourself. So the "for the lulz" element is very much central to their breaches and honestly that's a bit... refreshing? Not that I side with them or anything, but this is definitely more fun than ransomware.
- skilled 5y agoI’m sorry to say but this article reads very bad even if the authors had the best intentions. If they don’t feel like sharing actual data on what they found then why waste peoples time with that tone. Sounds like someone just rushed to press the Publish button.
- cookiengineer 5y agoI've been inspecting their dumps since the iPhone X leaks. As it turns out, they got access to huawei, apple, nvidia, samsung, microsoft bing/maps/notes and probably (unconfirmed) vodafone, lge, impresa, mercadolibre and others. They actively infiltrate organizations with Windows monoculture that never updates, most exploits they seem to have used were running on _really_ outdated systems that are targeting enterprise monoculture as well, like atlassian software, and pretty much everything with an ADS integration. As I commented previously, it's likely that the SOCs (Security Operations Center) are part of this, too, because _if the certification_ of the targeted organizations isn't utter BS, then they must have caught an incident like this. A server transferring more than 200GB to a single IP? C'mon, firewalls of the 90s detected that. They also shamed okta in response to their blog post a lot for having wrong security in place, aka publicly accessible slack channels that have more than ~9k members, where even AWS secrets are posted regularly. I mean, attack scenarios like this are bound to happen when management decides it's cheaper to hire an external SOC with VPN access for everything. As long as management thinks there has to be a ROI of investment into the blueteam/cyber defense part, nothing will change. Better laws have to be written to enforce the incentive, because clearly, even Microsoft was too late to catch them in the act. This is what you get for being "cloud native" and there's no way to prevent it. Infrastructure out of your control has to be treated as such, everyone in cybersec was talking about the dangers of using AWS and hire SOCs and external support teams from India for decades already, and nobody listened.
- kingcharles 5y ago200GB is nothing these days though. I'm on a cell connection and I move that a day.
- cookiengineer 5y agoIf a single IP produces that much traffic to a build system, and is an external resident IP...it's 100% either a DDoS attempt or a malicious actor that is in the process of exfiltrating data. There's not a single scenario where a traffic this size to an internal buildbot machine to/from a single unknown resident IP is legit.
- 5y ago
- cosmiccatnap 5y ago
- Trias11 5y agoLAPSUS, likely from russian: "ляпсус" translated as Blunder
- thematrixturtle 5y agoIt's originally Latin, and hence borrowed into lots of European languages including English (lapse). https://en.wiktionary.org/wiki/lapsus#Latin https://en.wiktionary.org/wiki/lapsus#Latin
- tuwtuwtuwtuw 5y agoLapsus is from latin. And yes, it could mean blunder. But apart from being Latin the word is used in the English language as well. So why would it be "likely from Russian"?
- phone8675309 5y agoBecause you can't talk about organized cybersecurity breaches of American corporations without someone blaming it on Russia because they drank the Kool Aid that only state-sponsored organizations have the skills to beat corporate cybersecurity drones.
- bencollier49 5y agoAre there any other modern languages where the transliteration is literally "lapsus"? Genuine question. I mean, doesn't prove anything. If they're smart they'd use the wrong language for their name. Or a double bluff...
- MaxBorsch228 5y agoSuppose a hacker group get their hands on a valuable exploit. They are like LAPSUS$ and are going to make the exploit public access, but also want to make some $. I wonder if the following scheme is theoretically possible: 1. Put the encrypted exploit file into some kind of Blockchain 2. Create a crypto wallet and announce a fundraising 3. As soon as the sum on the wallet reaches, say, $5M, the exploit is automatically and consensually decrypted by the Blockchain system and released to the public.
- gouggoug 5y agoAnd what purpose does the blockchain serve in your example?
- darawk 5y agoIs there another system that allows you to implement an anonymous assurance contract without a trusted third party?
- gouggoug 5y agoHow do I know that the encrypted payload actually contains the exploit and not the picture of a cat?
- darawk 5y agoYou don't. You have to rely on reputation for that piece. Blockchain solves the problem of the assurance contract.
- gouggoug 5y agoSo, whether a blockchain is used or not, there's no way to know that I'll get what I paid for or an empty text file. So the blockchain serves no purpose in this instance. Asking people to send you money, and them trusting you'll send them the exploit is exactly the same and no blockchain is needed (except maybe the bitcoin one, since of course you don't want to use paypal)
- rapht 5y agoNot a computer security engineer here but reading the article feels like in most organisations there are no safeguards in place for modifying global highly privileged accounts (the article cites introducing a global Office 365 admin and then removing existing global admins, etc). Are there not procedures like double/triple validation of sensitive changes (like "creating new global admin account") by accredited humans? I mean, in my line of work (finance), this is something that is enforced in multiple sensitive contexts such as money transfers - at certain thresholds, even the highest privileged person in the organisation cannot single-handedly authorise the operation.
- laurent92 5y agoBut it’s annoying to program. You need the same records as an undo/redo system, except they’re only applied after approval. Finance does it because everyone knows finance is boring already, but I’m not sure it would be possible to retain a JS programmer in another sector if the 6-eye principle had to be applied for every modification. It’s already hard to motivate them for i18n…
- iRobbery 5y agoTheir name makes me think they work on asus laptops all the time, probably just me. :)
- exyi 5y agoI can't unsee it now (:
- maybe_pablo 5y agoI thought it had some relation to the Brazilian health system, "Sistema Único de Saúde" (known as SUS).
- pid-1 5y agoMe too, as it was one of their first targets. From their audience and the way they write, it's quite likely they are (or started as) a group of BR hackers.
- lifeisstillgood 5y agoSo there is plenty of open guides on running a server, locking down a single server, but I do not know of guides for locking down an organisation - basically the RFC on how to run a SOC/Noc. Does such a thing exist? I am not looking for a white paper on Cisco network monitoring but ... somethining opinionated. A blank sheet of paper approach that would only have Fido access, maybe limited to openBSD or whatever. Something that as a small company one could build something not embarrassing.
- bob1029 5y agoOur strategy as a startup (<10 employees) is to operate as if our entire infrastructure can disappear instantly. 99% of what we need to rebuild lives in git, which is extremely resilient considering the number of pcs and build machines involved with recent checkouts. We do not store any customer secrets or other PII that could actually require a breach disclosure. At the end of the day it would just be a stupid messy fight with the hackers and then we'd be back in business the following on a clean azure tenant. Trying to run your business like some perfect unhackable thing is probably not sustainable, especially if you are small. The next best thing is limiting blast radius and making sure you can pick yourself up off the floor quickly enough.
- adamhp 5y agoThis is why security professionals operate based on risk and risk mitigation, not pass-fail.
- fxtentacle 5y ago"Our team was already investigating the compromised account based on threat intelligence when the actor publicly disclosed their intrusion. This public disclosure escalated our action allowing our team to intervene and interrupt the actor mid-operation, limiting broader impact." Does that mean that Microsoft only managed to stop the hack-in-progress because LAPSUS publicly bragged about hacking Microsoft?
- ratg13 5y agoIt reads like they were trying to catch the employee in the act of doing something nefarious.
- toyg 5y agoProbably they were monitoring the behaviour of certain accounts to find all systems that intruders had compromised.
- rolph 5y agothis says something about how MS rolls out,,, it seems they sniff around first and get info, rather than just kill the account and its processes.
- q1w2 5y agoMS is keeping the details intentionally vague, so it's unlikely we'll ever know the scope of the breach and data exfiltration.
- tjpnz 5y ago>social engineering tactics include spamming a target user with multifactor authentication (MFA) prompts If you're required to use your personal device for MFA this tactic could prove very effective.
- mrkramer 5y agoI was researching cybercrime for years and yea motivations of this adversary are confusing and incoherent so I would rather say they are group of real life and/or internet friends who are having fun showing off and practicing their skills something like hackers who deface websites "en masse". From what Microsoft said DEV-0537 is opportunistic; they are Purchasing credentials and session tokens from criminal underground forums Paying employees at targeted organizations (or suppliers/business partners) for access to credentials and MFA approval Searching public code repositories for exposed credentials and they are exploiting publicly known exploits in order to infiltrate organizations. Like somebody already mentioned they are similar to LulzSec in a way they are partially financially motivated, partially hacktivist and partially bragging around but all in all they are doing it for the "lulz".
- ianhawes 5y agoI guarantee this is a group of less than 8, most of whom are under 23 and grew up in middle-class Brazilian families and have had access to computers (unfiltered and unmoderated) since age 10.
- smilespray 5y agoThat's interestingly specific...
- notuger 5y agothe telegram channel name is related to a big hack activity in brazil last year, they always share brazilian news..
- chockchocschoir 5y agoIt's also a relatively easy, cheap and common opsec strategy to mask your geographic location by constantly sharing news from a place you're not actually located at. Same as saying "good morning" every day to your "team" when actually it's night at your location.
- arminiusreturns 5y agoMicrosoft is a criminal organization targeting users.
- nicolas_t 5y agoWhat happened after they issued their ultimatum to Nvidia regarding opensourcing the drivers? Did the hackers follow through?
- alternatetwo 5y agoThere is a torrent with some GBs of data containing nvidia data (I haven't downloaded it) on their telegram channel. So ... yes?
- nimbius 5y ago>The activity we have observed has been attributed to a threat group that Microsoft tracks as DEV-0537, also known as LAPSUS$ i guess nothing leaves redmond before getting hit with the marketing sugar stick. >Unlike most activity groups that stay under the radar, DEV-0537 doesn’t seem to cover its tracks. yes, its almost as though the pending narrative of the insidious black hat hacker we're trying to spin is proving difficult from the get go. >Microsoft also found instances where the group successfully gained access to target organizations through recruited employees so the downside to "bullshit jobs" is they become a threat vector. the countermeasure is to pay more and offer better benefits or...do what Okta did and just ignore the whole thing while players like Cloudflare try to stack the fallout squarely on you, and players like Microsoft try to make a buck off a crisis you cant handle.
- andromaton 5y agoSeems leader is 17 yo Albanian living in the UK. https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/ https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lap...