5 ms·
The name that keeps coming up is Jia Tan (https://github.com/JiaT75/ https://github.com/JiaT75/) but we have no way of knowing if this is a real name, pseudonym
by toasteros 3y ago
The name that keeps coming up is Jia Tan (https://github.com/JiaT75/ https://github.com/JiaT75/) but we have no way of knowing if this is a real name, pseudonym, or even a collective of people.
- pphysch 3y agoGiven the sophistication of this attack it would indeed be downright negligent to presume that it's the attackers' legal name and that they have zero OPSEC.
- xvector 3y agoHe used ProtonMail. I wonder if ProtonMail can pull IP logs for this guy and share them.
- eklitzke 3y agoIt might be worth looking into, but: 1) Probably by design protonmail doesn't keep these kinds of logs around for very long 2) Hacking groups pretty much always proxy their connection through multiple layers of machines they've rooted, making it very difficult or impossible to actually trace back to the original IP
- xvector 3y agoFor [1], unfortunately it does. True regarding the second point. [1]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities/ https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
- ajross 3y agoIt's also worth pointing out, given the almost two years of seemingly valuable contribution, that this could be a real person who was compromised or coerced into pushing the exploit.
- stefan_ 3y agoIt’s also worth pointing out that parts of the RCE were prepared almost two years ago which makes this entirely implausible.
- ajross 3y agoWere they? The attacker has had commit rights for 1.5 years or so, but my understanding is that all the exploit components were recent commits. Is that wrong?
- agentdrek 3y agoInteresting to look through the "starred" repos of that account ... seems like a hit list: https://github.com/JiaT75?tab=stars https://github.com/JiaT75?tab=stars