5 ms·
The list of infected countries might tell us a thing about the attacker: Russia and Saudi Arabia at the top: classical US intelligence targets. Pakistan and Af
by MatthiasP 12y ago
The list of infected countries might tell us a thing about the attacker:
Russia and Saudi Arabia at the top: classical US intelligence targets.
Pakistan and Afghanistan: Likely anti-islamists effort.
Austria, Belgium, Iran: Opec, IEAE, tons of EU-institutions - someone who wants better intel about the nuclear talks with Iran?
Ireland, Mexico, India: Hard to find political reasons for those countries, but if you look at it economically: Ireland is the main hub for US companies into the EU, Mexico is a neighbouring country to the US, India: rival to China
My totally far-fetched guess would be that this trojan comes from the NSA or the GCHQ, I don't see China caring that much about Saudi Arabia and AfPak.
- throwawayaway 12y agothe high percentage of telecoms and private individuals targetted is reminiscent of this: http://arstechnica.com/tech-policy/2013/11/uk-spies-continue-quantum-insert-attack-via-linkedin-slashdot-pages/ http://arstechnica.com/tech-policy/2013/11/uk-spies-continue...
- jacquesm 12y agoAnd a very fat finger points at the US/UK because if they were simply present in statistically normal quantities in the samples they would be amongst the largest of the groups encountered. The fact that they are not suggests a conscious decision not to target those countries, likely emanating from a law rather than from a desire. If this were done by China then the US would be represented strongly.
- csandreasen 12y agoLikewise, if this were done by the US then China would be represented strongly... I'm at a loss to guess attribution behind this one.
- api 12y agoHmm... good point there. Could also be a private entity -- governments aren't the only ones out there doing this kind of thing. There's a lot of money to be made on commodities markets, for example.
- justincormack 12y agoIt is quite highly correlated with oil producing countries, other than Ireland. OPEC HQ is Vienna.
- api 12y agoI agree that US/UK are most likely but I see other possibilities too: Israel, or one of the other EU states. Israel might not have any qualms about targeting American targets -- at the very least they would have no legal restriction against doing so. But they might not do so for pragmatic reasons: lack of interest, or to generate the impression that the threat is U.S. based.
- jacquesm 12y agoI think you can rule out the other EU states based on capability alone. Israel is a good one, hadn't thought of that. China as a target is a hard one. In part this is because they have relatively little IT infrastructure relative to the size of the population and because the number of juicy targets is rather limited (government mostly).
- tptacek 12y agoBased on what capability? Symantec's PR machine aside: what do you think something like this would cost to develop? Based on the high-level summary we have here, it looks like a 6-figure project. Latvia could afford to build this thing. I probably didn't look at this any more carefully than you did, so if there's some specific capability you think narrows down the sources of this trojan, let me know; I probably missed it.
- AlyssaRowan 12y agoJust six figures? To build this and maintain it over multiple years, including a menu of payloads and exploits? When individual exclusive 0day exploits each rank at 5 figures upwards? Salaries? That seems unrealistically low for this. Sounds like much better value for money than any nation state would actually get in practice, and more in the ballpark of Malware-as-a-Service outlets like Hacking Team. (Why the love for .lv?)
- tptacek 12y agoI'm not counting payloads and exploits against the cost of the framework, because the framework is all we have to go on. Exploits cost a lot of if you (a) need zero-day, (b) need mass-infection, or (c) need to foil attribution. They're significantly cheaper if you relax those concerns. Similarly: I assume the payload that physically corrupts a centrifuge array is a bit pricier than the one that scans the hard drive for credit card numbers. Latvia's just the smallest EU economy that came into my head.
- higherpurpose 12y agoThe fact that it's an extremely sophisticated malware (much like Stuxnet was) points to US, as well.
- notastartup 12y agoI understand Russia, Pakistan, Afghanistan are targets. But Saudi Arabia? It strikes me as odd.
- pmorici 12y agoWhy? They probably fund as much militant extremism as anyone.
- waterlesscloud 12y agoMy very casually informed take was that it looked like a map of laundering money from oil producers to islamists.
- AlyssaRowan 12y agoAttribution is always thorny - but yes, targeting metadata does match those possible conclusions. Quite a bit of the other information in the 'technical report' (which isn't as technical as I would like) does seem eerily reminiscent of what we know about the CHIMNEYPOOL framework, and (to some extent) FOXACID. A little overengineered, and a little sloppy in places - and that's everything I'd expect from a pork barrel remote intrusion tool with serious dollars thrown at it. Go on, match it up and see what tallies! Assume "Stage 0" is the VALIDATOR egg (or a cousin), which is memory-resident, never touches disk, and fetches the rest, and work from there. In particular, I'd single out as particularly telling the 7a69-CRC ICMP filled with string-literal (and very English) shit, and… a 20-round variant of RC5? That has a strong smell of hamburger to it, although I'd wonder if the analysts perhaps mistook it for RC6, or if this is perhaps an earlier version? Yes, at first blush, this may indeed be NSA malware! Are the samples available for analysis, Symantec? Inquiring minds want to take a closer look at this creature, and you have piqued my interest. My email won't be hard to find. Deadlists are fine. https://keybase.io/akr https://keybase.io/akr
- tptacek 12y agoInteresting. Where do you see the overengineering? What parts seem sloppy? What else makes you think serious dollars were thrown at it? What evidence would you be looking for of that? We managed to throw 900MM at a health insurance portal. :) Is it really that unusual for trojans to be elaborately staged? I feel like I was on a CanSec stage with Jose Nazario about 12 years ago talking about malware staging. Staged malware, that is, is 2004 CanSec Jose Nazario levels of sophistication (due respect to Jose). The Wikipedia page for RC5 says to use 20 rounds, because RC5 sucks and fell to differential cryptanalysis, which NSA knew about in the 1970s.
- AlyssaRowan 12y agoThis is without having seen it, natch, so I can't speak to its quality except for what's in the "technical" paper: this is initial impressions and speculation, but I'd definitely love to see concrete deadlistings. The overengineering, and the serious dollars? I say that because it's a large, modular framework, with perhaps more stages than strictly necessary - which they cut down on later on. This isn't a small, precision piece of malware from one highly-skilled VXer. This is a project. Abstraction, modularity, plugins. Exploits (0days?) and payloads and C&C mechanisms, all as plugins. A big project, designed for lots of people to work on, probably of very different skill levels. Adapted over time. Hell, there's a linkfiler in there and their own RPC. So, kind of like any other big software project: it sounds a little sprawling. And big means expensive, as you know. I know GCHQ and NSA developed theirs via contractors. Seems reasonable this is the kind of thing they might put out. (Note CHIMNEYPOOL was specifically mentioned as a framework for malware.) Why did I call it sloppy in places? Because it's a (purported, and probable) nation-state espionage malware that touches disk, never mind the failure to clean up! Programmers of different skill levels; perhaps operators of different skill levels, too. I want to know more about the C&C. I would expect to see a C&C technique that transmits decryption keys for encrypted functions as selectors, but I think this is not quite that advanced. RC5 is indeed an odd cipher to use in the late 2000s (as is just bumping the rounds of it, rather than using a better one). I called that out, because at least one other piece of software which sounds very similar seems to use RC6 (the failed AES candidate), which is also a very unusual choice. It's not infeasible the two are linked, but I'm obviously lacking context here.
- tptacek 12y agoIt's funny to me that we posit attackers building malware of such sophistication that they can only be nation-state in stature, while at the same time supposing that they know so little about the AV industry that they could be revealed by a heat map of the countries their malware was spotted in. How about: it's Russia, Russia doesn't care about infecting hosts in its own country (in fact, they may prefer to do so; those might be their targets), and, while Russia surely does have an aggressive program of intrusions into the US [and China], they don't use this particular piece of malware to execute it? I have no reason to believe it's Russia. I just think: that story is as plausible as the others being tossed around this thread. If I have a bias about the origin being the US, hand to God, it's that I'd like to believe my tax dollars can pay for better malware than this. I have, for what it's worth to the thread, absolutely no doubt in my mind that the US has stuff like this in the field. I'd really like to believe it was Latvia.
- minimax 12y agoThe Saudi infections are obviously a decoy and the main target is clearly Russia. Latvia, as a former SSR and recent NATO addition, is nervous about Putin's next moves in the region. Wasn't there also recently a Russian sub spotted in the Baltic Sea? You'd have to be an idiot not to see Riga's fingerprints all over this thing.
- znowi 12y agoExpectedly, tptacek is all over the infosec thread, arrogantly dissuading the public from the notion of a possible involvement of the US intelligence community :)
- NickPollard 12y agoActually he's attempting to dissuade people from leaping to conclusions based on little-to-no data and their own biases. He doesn't say it's not the US, he just says that the data is not enough to support that conclusion. It might be time for another HN article on Bayes' Theorem.
- mobiuscog 12y agoOr it could be Google, Microsoft, Apple, Amazon... Any big tech company investing in industrial espionage. It's not as if they don't have the development staff.