Equation Group Cyber Weapons Auction
theshadowbrokers.tumblr.com
theshadowbrokers.tumblr.com
1. All bids are paid up front, and you never get your money back, even if you aren't the highest bidder. So if people bid $50, $70, and $100, they collect $220.
2. No one can verify what is actualy up for sale before the auction.
3. There is no way for the world to know that they actualy delivered the goods after the auction.
4. There is no way for the highest bidder to know that they will actually receive the goods.
5. There is nothing stopping the auctioneers from bidding. This not only raises the price, but they still get to keep every bidders money even if the high bid is their own.
Everything about this auction is lined up to incentivize a scam.
> Q: When does auction end? A: Unknown. When we feel is time to end. Keep bidding until we announce winner.
~~A silent penny auction :|~~
Yes, however the contents of the free sample seems very real. Without having dug into the binaries it's hard to tell, but it's hard to imagine someone wrote this to scam 1 million BTC out of the net.
Let's say you break into a server and steal 10 vulnerabilities, from an organization (e.g. the NSA) who are never going to acknowledge how many vulnerabilities they had or were stolen.
If you want to get the most in the auction, the best thing you could possibly do is to release all 10 of your vulnerabilities for free, claiming that it's just a teaser, and that you have many more. Then you take in bids and disappear. It makes no sense to only release 2 or 3 and hold back the remainder; the unreleased ones are essentially wasted because they didn't actually contribute to any bidding activity: nobody knew they existed when they were bidding. That they exist at all is a happy surprise to the winning bidder, but with no further sales, customer goodwill isn't worth anything.
There's really no incentive to actually follow through on the sale at all. The only purpose of the "goods" to the seller is to attract bids, but with nobody to verify what's actually for sale, the best strategy is to use everything for what amounts to advertising, in the hope of gaining more attention and attracting more bids.
I wouldn't dump it all at once, if I were them, though. I'd do an initial release, and them some more once the initial bids (if there are any) slow down, and keep doing that over and over until the market is entirely worn out and all the vulnerabilities have been disclosed. That's the profit-maximizing strategy, I think.
People do work for a lot less..
The block chain makes it worse because everyone can see the progress of the buyer and there's no market maker with anywhere near this level of liquidity.
Interesting to note: there has been no new Bitcoin block for the last 1 hour 23 minutes. This happens from time to time, but it is a little suspicious.
However, with that much money on the line (if that figure is correct), you could fake almost anything.
The only people who could verify if it's real are the Equation Group themself. For anyone else it's impossible to verify - it's just some names.
So: If it's real the Equation Group will bid - probably a lot. If it's fake no one will bid.
So it'll be easy to tell which it is.
Why? You have no guarantee what you're bidding for will remain private, and you don't want to give it legitimacy by bidding. Who's to say if it's real the Equation Group wouldn't bid, under the assumption that it's already out there and you have absolutely no guarantees that anyone you're dealing with would keep their word.
> So it'll be easy to tell which it is.
~~How can you tell how others have bid?~~
Some systems you can get into some you can't.
Actually if they could tie their identity to some positive reputation, the other points wouldn't be so bad (they could still attempt an exit scam).
The fact that they are so honest about the refunds actually makes me think it's not a scam, since scammers would probably lie and promise the opposite.
A government would handle this by trying to chase down the autioneers. If they wanted the data, they would buy it from Kaspersky, assuming it's real.
...The client gets infected with malware and sends the data home... to some server. The server side.
Or for the highest bidder to even know that they won.
- Split the leak into multiple chunks, each encrypted with a different key, and each readable/usable on its own
- Announce, ahead of time, that a random chunk will be revealed, based on the hash of block #N on the Bitcoin network
- On block #N, reveal chunk number block_N_hash % num_chunks.
Basically, reveal a provably random chunk in a way that cannot be controlled by the auctioneers, which would ensure that all the chunks are (most likely) real.
This, however, won't work with their penny auction style bids.
[0] https://en.bitcoin.it/wiki/Zero_Knowledge_Contingent_Payment
[1] https://bitcoincore.org/en/2016/02/26/zero-knowledge-conting...
Using hashes like you are suggesting you wouldn't even need ZK proofs. There is a simple trick you could do with the keys such that you post a single 128 value which is checkable with a tree of OP_HASH and OP_DUPs and would, with very high probability, reveal all the keys.
As pointed out below the problem with this scheme is that you could hash the same files with a little randomness added and make it look like you have more data to sell than you do. I think with some GC-based ZK proofs you could show this isn't true and each file is legitimately different (for example demonstrating randomly selected bit relationships or word frequencies).
I wonder if software already exists for this, like, purposely filling a text with random mistakes so that the identity of the writer is safe.
Yes, I acknowledged this but for a different reason.
You complained about bad grammar in your article, so I feel the need to point out this error in the last sentence.
set spell spelllang=en_us
https://www.linux.com/learn/using-spell-checking-vimWow. We really are f----d all the way down the stack.
The basic idea - flip bits a lot until things crash - wasn't totally shocking. But learning that Project Zero had put up working privilege escalation attacks off something so bizarre? That's just too far.
At least Van Eck phreaking is still hard to use in practice...
If you're stealing hardware, the only thing you're not capable of already is (necessarily) being able to decrypt it. So this would apply to any unencrypted SD card. Not terribly effective use of the hack.
A better one would be to do so with one of those WiFi SD cards[0] and transmit the data over the network. You could just read it directly from the card and place deleted files into your buffer when you overwrite them, and hope they don't delete more than your buffer's size of data before you can upload it.
[0]:https://en.wikipedia.org/wiki/Secure_Digital#Vendor_enhancem...
--EDIT-- From heartsuckers thread, the README text is also here: https://heartsucker.com/static/docs/shadow-broker-message.tx...
From:
bitmessage = BM-NBvAHfp5Y6wBykgbirVLndZtEFCYGht8 i2p-bote = o1uHOkOcMoFEa7O7dbEilzfMvWzo7bDu~td3x9gYz4b4t5OriJ7U6GUWr5GZoWxQ9f2TrIY5RzhpIMVP6hTLXZ
Equation Group Cyber Weapons Auction - Invitation - ------------------------------------------------
!!! Attention government sponsors of cyber warfare and those who profit from it !!!!
How much you pay for enemies cyber weapons? Not malware you find in networks. Both sides, RAT + LP, full state sponsor tool set? We find cyber weapons made by creators of stuxnet, duqu, flame. Kaspersky calls Equation Group. We follow Equation Group traffic. We find Equation Group source range. We hack Equation Group. We find many many Equation Group cyber weapons. You see pictures. We give you some Equation Group files free, you see. This is good proof no? You enjoy!!! You break many things. You find many intrusions. You write many words. But not all, we are auction the best files.
Picture Urls - ------------ http://imgur.com/a/sYpyn https://theshadowbrokers.tumblr.com/ https://github.com/theshadowbrokers/EQGRP-AUCTION
File Urls - ----------
magnet:?xt=urn:btih:40a5f1514514fb67943f137f7fde0a7b5e991f76&tr=http://diftracker.i2p/announce.php
https://mega.nz/#!zEAU1AQL!oWJ63n-D6lCuCQ4AY0Cv_405hX8kn7MEs... https://app.box.com/s/amgkpu1d9ttijyeyw2m4lso3egb4sola https://www.dropbox.com/s/g8kvfl4xtj2vr24/EQGRP-Auction-File... https://ln.sync.com/dl/5bd1916d0#eet5ufvg-tjijei4j-vtadjk6b-... https://yadi.sk/d/QY6smCgTtoNz6
Free Files (Proof) - ------------------ eqgrp-free-file.tar.xz.gpg
sha256sum = b5961eee7cb3eca209b92436ed7bdd74e025bf615b90c408829156d128c7a169
gpg --decrypt --output eqgrp-free-file.tar.xz eqgrp-free-file.tar.xz.gpg
Password = theequationgroup
Auction Files - ------------- eqgrp_auction_file.tar.xz.asc
sha256sum = af1dabd8eceec79409742cc9d9a20b9651058bbb8d2ce60a0edcfa568d91dbea
Password = ????
Auction Instructions - -------------------- We auction best files to highest bidder. Auction files better than stuxnet. Auction files better than free files we already give you. The party which sends most bitcoins to address: 19BY2XCgbDe6WtTVbTyzM9eR3LYr6VitWK before bidding stops is winner, we tell how to decrypt. Very important!!! When you send bitcoin you add additional output to transaction. You add OP_Return output. In Op_Return output you put your (bidder) contact info. We suggest use bitmessage or I2P-bote email address. No other information will be disclosed by us publicly. Do not believe unsigned messages. We will contact winner with decryption instructions. Winner can do with files as they please, we not release files to public.
FAQ - --- Q: Why I want auction files, why send bitcoin? A: If you like free files (proof), you send bitcoin. If you want know your networks hacked, you send bitcoin. If you want hack networks as like equation group, you send bitcoin. If you want reverse, write many words, make big name for self, get many customers, you send bitcoin. If want to know what we take, you send bitcoin.
Q: What is in auction files? A: Is secret. Equation Group not know what lost. We want Equation Group to bid so we keep secret. You bid against Equation Group, win and find out or bid pump price up, piss them off, everyone wins.
Q: What if bid and no win, get bitcoins back? A: Sorry lose bidding war lose bitcoin and files. Lose Lose. Bid to win! But maybe not total loss. Instead to losers we give consolation prize. If our auction raises 1,000,000 (million) btc total, then we dump more Equation Group files, same quality, unencrypted, for free, to everyone.
Q: When does auction end? A: Unknown. When we feel is time to end. Keep bidding until we announce winner.
Q: Why I trust you? A: No trust, risk. You like reward, you take risk, maybe win, maybe not, no guarantees. There could be hack, steal, jail, dead, or war tomorrow. You worry more, protect self from other bidders, trolls, and haters.
Closing Remarks - --------------------------------------------------
!!! Attention Wealthy Elites !!!
We have final message for "Wealthy Elites". We know what is wealthy but what is Elites? Elites is making laws protect self and friends, lie and fuck other peoples. Elites is breaking laws, regular peoples go to jail, life ruin, family ruin, but not Elites. Elites is breaking laws, many peoples know Elites guilty, Elites call top friends at law enforcement and government agencies, offer bribes, make promise future handjobs, (but no blowjobs). Elites top friends announce, no law broken, no crime commit. Reporters (not call journalist) make living say write only nice things about Elites, convince dumb cattle, is just politics, everything is awesome, check out our ads and our prostitutes. Then Elites runs for president. Why run for president when already control country like dictatorship? What this have do with fun Cyber Weapons Auction? We want make sure Wealthy Elite recognizes the danger cyber weapons, this message, our auction, poses to their wealth and control. Let us spell out for Elites. Your wealth and control depends on electronic data. You see what "Equation Group" can do. You see what cryptolockers and stuxnet can do. You see free files we give for free. You see attacks on banks and SWIFT in news. Maybe there is Equation Group version of cryptolocker+stuxnet for banks and financial systems? If Equation Group lose control of cyber weapons, who else lose or find cyber weapons? If electronic data go bye bye where leave Wealthy Elites? Maybe with dumb cattle? "Do you feel in charge?" Wealthy Elites, you send bitcoins, you bid in auction, maybe big advantage for you?
bitmessage = BM-NBvAHfp5Y6wBykgbirVLndZtEFCYGht8 i2p-bote = o1uHOkOcMoFEa7O7dbEilzfMvWzo7bDu~td3x9gYz4b4t5OriJ7U6GUWr5GZoWxQ9f2TrIY5RzhpIMVP6hTLXZ
END MESSAGE
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAEBCAAGBQJXrr2sAAoJEAQSTyzLXAwbVzwP/jR5sQcS8VzH2jmuRjbE6RLV P3RkY6RWyyTyCtTiyTXK4RtWQoz8CfEjnXdIaR3BIZG4u827iI2fbQMVlWu0jMn4 NYN1I/neBoDaagApRgGQqYXip3IdHsqJennOAxRqr0ZoOgJ3IVtiZK8/6vtEnXRK 03IJvKu0zOVROuP0a9OPX0jko2g3Rl2tvo1ljkU1bqLKHs6xb1VzmdoqlAOYR1Bv 4Kb/Gbr6uc5fG84sM8FzSdiyJgS3U21SqfUENyFLyyP05iCyKCybFMne1JckFre8 gI/nUhdRHJaETYorY49PTQvdBaD30aT1I7efyAAM9uxsF97Au/UEvk0hkzh0YfoR /m+htNKlaP/oclL5GhJEq2O4wWb1KJuyrHU3FZYdUWRA4SlELBb0oR64cw/8kDo+ 6WftSANdlolgQLMbng2/ORGTeXHQ033mX6Op93o2oZUuNNhHvR1PnhWPUA2vMcIs ndo6YuYV2TZR/4GVNiJYQhTcWVNZ7a10FuvWk7yyHkTKXRVHG43G5Rzzm9ZxMUcL DMAExiPnrehGYTcxrrOP28RB+Mw7Is5YwRpc/h0mwDYGijjUzXGLXPWKFLa8ksxR zdaUnAjJzhVwR4IVGmGlU687Ox0FayJz9LAhst5eiittciY0iooz8YLee8hrxD7C XqUIpr4n+QKMYs4AfWd+ =5yni -----END PGP SIGNATURE-----
Add on the fact that the author of the readme is clearly writing in an exaggerated Russian / East European accent, with such wild claims and mystery surrounding the terms of the auction...I would suspect joke or alternate reality game more quickly than a hack of Equation Group.
Without any spelling mistakes.
https://github.com/theshadowbrokers/EQGRP-AUCTION
They are apparently still ignorant of the Streisand Effect
(Nothing has happened yet, I expect small spam transactions to come in any minute)
I remember an config file regarding the XKeyscore tool, but nothing else.
So if you buy organic food, people will grow more organic food. If you buy oil, people will pump more oil. If you buy ivory, people will kill elephants for their tusks.
If you put money into this, people will do more of it.
Nobody could be both smart enough to hack Equation Group and dumb enough to think that they could just cash out through bitcoin and walk away.
If they're real, that's probably how these files got out there in the first place.
If you got your hands on something like this, you probably think you're pretty smart, and you'd probably try to come up with some smart way to make some money off this, and this is the plan you'd come up with...
See my first sentence...
Hence the open ended termination.
Then imply a state actor won (via a large self-bid) or disrupted the auction. Hence the penny-auction structure, where they can walk away and keep preliminary bids.
If it's a fake, it's a very good one – the code words match up to things we've seen in the Snowden leaks, e.g. Jetplow (https://www.schneier.com/blog/archives/2014/01/jetplow_nsa_e...). Matthieu Suiche has a good initial writeup here:
https://medium.com/@msuiche/shadow-brokers-nsa-exploits-of-t...
If nothing else, I found this compelling*
> In addition, timestamps in the malware seem to indicate that the programmers worked overwhelmingly Monday–Friday in what would correspond to a 08:00–17:00 workday in an Eastern United States timezone.
*assuming you trust the timestamps.
At that point it would look completely legit, but could be used to track back large amounts of Bitcoin. If the NSA knows through listening stations which adversary groups are sending how much BTC then they'll be able to follow the leads back significantly.
Combining technical knowledge of trades and BTC movement with CIA knowledge of on-the-ground information may net them some fantastic information.
With the addition of getting a large about of BTC for future funding. That would be a powerful move.
Also, here's link to free files github repo
"This repository has been disabled.
Access to this repository has been disabled by GitHub staff. Contact support to restore access to this repository. "
Not really. GitHub aren't liable for the initial upload due to safe harbor laws. If the dump is fake, then there's no problem for GitHub. Life goes on.
If the dump is real then potentially the owner could force GitHub to remove it, but in doing so would have proven the legitimacy of those files, which is something you don't usually want to do.
GitHub may, of course, choose to suspend the account for their own reasons (I don't know, for example, what their T&Cs are for running auctions via their site, but it's probably not allowed).
* Whomever is running this auction knows everything that has been mentioned in these threads already, and they're probably a few steps ahead of us all. There are multiple indicators that they know what they're doing from a technical standpoint and that it's very likely that these 'weapons' indeed do what they claim. * On the other hand, there's a lot of reason to believe that these could potentially be faked, since the whole auction is just designed to generate income.
Equation Group is a real group. They do exist, they get paid really well to operate, and a couple things jump out as obviously being bait.
If you were to place a bid, (I plan to bid a couple dozen BTC or so, but I want to see what other people do first) then they say they'd contact you with decrypt information and then you'd have the rest.
The real Equation Group is a group of intelligent individuals, rumored to be a group of several dozen people, and so they realize that they all have to operate under the same standards, and resist being correlated. These guys know that every so-called elite hacker that we know about, we know about them because they fucked up. We know that EG exists because their tradecraft WASNT good enough. The real question is whether or not they wanted us to find out. Bitmessage isnt perfect, i2p isnt perfect, none of these tools are perfect and the entire idea of a group that might not even exist contacting a bidder after they may or may not have bid the highest bid is just ridiculous.
There is reason to believe that if EG actually exists, that there might be subdivisions within whatever larger collective they belong to (NSA, CIA, etc) that seem to learn from approaches that can be correlated to work that EG either wanted us to find, or didn't.
Regardless, these guys know enough to not get in trouble over this. Even if they're NSA contractors, or permanent employees, or some sort of secret operatives from some crazy Intel firm, whatever the case is, they aren't going to make some stupid mistake and ruin this.
I'd give this like a 30% chance of being real. Doesn't seem likely.
I will really be surprised if anyone actually bids any significant amount. Come on, an open-ended auction where they keep all bids? The overly-russian phrasing? Just screams legitimacy.
You plan to bid $5,000 to $20,000 for this? Are you serious? Where do you work?!?
It's one of the things that puzzles and fascinates me about bitcoins in general - the early adapters have a disproportionate amount. Seems like a terrible investment because of the cap on growth - as soon as the currency reaches a certain threshold value, the select few cash out a few dozen or hundred. It drops again, they sit back and let demand build up again.