3 ms·
Everyone keeps saying this but it seems unlikely to me that they'd do this for a relatively short window of opportunity and leave their methods for all to see.
by TheBlight 3y ago
Everyone keeps saying this but it seems unlikely to me that they'd do this for a relatively short window of opportunity and leave their methods for all to see.
- avidiax 3y agoYou are judging this by the outcome, as though it were pre-ordained, and also assuming that this is the only method this agency has. It is much more likely that this backdoor would have gone unnoticed for months or years. The access this backdoor provides would be used only once per system, to install other APT (advanced persistent threats), probably layers of them. Use a typical software RAT or rootkit as the first layer. If that is discovered, fallback to the private keys you stole, or the social engineer the company directory you copied. If that fails, rely on the firmware rootkit that only runs if it's timer hasn't been reset in 6 months. Failing that, re-use this backdoor if it's still available.
- TheBlight 3y agoIt was found in a few weeks so why is it more likely it wouldn't have been noticed for months/years with more people running the backdoored version of the code?
- ufo 3y agoWe were lucky that the backdoor called attention to itself, because it impacted the performance off ssh and introduced valgrind warnings.
- AtNightWeCode 3y agoMy guess is that a ransomware group is behind this. Even if the backdoor had gone into production servers it would have been found fairly quickly if used at some scale.
- TheBlight 3y ago>My guess is that a ransomware group is behind this. My bet would be that they were after a crypto exchange(s) where they've already compromised some level of access and want to get deeper into the backend. >Even if the backdoor had gone into production servers it would have been found fairly quickly if used at some scale. I agree. Yes it's possible the backdoor could've gone unnoticed for months/years but I think the perp would've had to assume not.