There are better ways to hide. From experience (I work in security), the ones I would use are (individually or combined):
- Have the VPN set up in my router using OpenWRT (the R7000 is great for that) and drop all connections when VPN disconnects (with a script).
- Rent a VPS on a botnet friendly host that accepts Bitcoins (i.e Hostsailor).
- Then do all my shady stuff from the VPS or even better, configure Tor and proxychains on the VPS then use proxychains when doing anything on a remote host.
I think the guy was just lazy and preferred convenience.
Having a separate browser that jumps through all the well-audited crypto hoops you want doesn't really help you if you have a native Safari window sitting next to it where you read your gmail.
Opsec is hard. Technology can only solve so much, the weak link will always be the wet spongy tissue.
This is not about being an 'idiot', this is perfectly normal behavior to happen once in a few years over hundreds or thousands of people.
And now I'm defending a Russian agent doing stuff I think sucks.
What you're asking for, fundamentally, is for people not to make mistakes. You probably don't hold that opinion in your professional life (yeah, I'm assuming you're a programmer). Why here?
For example, Rudolf Abel was caught because he paid with a fake nickel on accident.
Edit: you could even configure Little Snitch to ask for permission for every app and domain your Mac wants to connect to. That way you would even catch yourself accidentally surfing to the wrong URL or using the wrong browser.
Usually you don't have a choice, you use what your friends use.
That totally says "false trail" rather than "fuck up" to me. /sarcasm
Instead of phone number, think port on the phone company’s switch or a specific pair of wires. That’s hard to spoof.
It’s much easier to spoof a MAC address, which can identify specific hardware associated with the IP address, but that doesn’t make the IP any more difficult to identify.
Depends on the occasion, no? There's a difference between "the target account once used phrasing more typical of a Russian speaker than a Romanian speaker" and "the target connected to the server from inside GRU headquarters".
> it's also definitely easy to throw investigations off course
Connecting to a server from GRU headquarters isn't something I'd call "definitely easy". If the claim is true, Occam's Razor suggests that the GRU was involved in some fashion. What's the alternative? That the DNC compromised the network of a Russian intelligence agency?
(How much faith to put in an anonymously sourced claim about what was in the logs of an unnamed social network is a separate question, of course.)
> U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency’s headquarters on Grizodubovoy Street in Moscow.
Parent already addressed this. Unless you have evidence to the contrary the "what if" game does not take us very far.
As well as the whatabboutism game ("what about the other side pointing fingers? Who has done worse?").
I don't like thought stoppers.
In comparison why would you trust anybody who is a professional liar on any information? Just because you have no other more reliable information does not turn the liars lie into a truth.
Tell me; how did The Daily Beast, an org that has Chelsea Clinton on their board, get the external IP addresses of the Russian Intellegence headquarters?
It wasn't the DailyBeast conducting the investigation, they are just reporting on it
There are many, many cases where a journalist has tracked down specific wikipedia edits to a particular office or intranet in a government building all from their IP address
You can find a ton of stories with a quick google search: https://www.independent.co.uk/news/uk/home-news/government-w... https://www.smh.com.au/politics/federal/investigation-into-o...
It reminds me of this project https://github.com/edsu/anon which "lets you tweet about anonymous Wikipedia edits from particular IP address ranges"
You can see it working at Congress Edits - https://twitter.com/congressedits
Public IPs are NOT easy to monitor correctly when A. It's supposedly Russian Intelligence HQ B. They are claiming they can identify the specific office it came from
[0]: https://abcnews.go.com/Technology/story?id=119423&page=1
Right, the fact someone could compromise a random government agency in the 90s clearly means someone else could compromise Russian military intelligence in 2016, because NASA's IT security in the 90s is totally comparable to the GRU today, absolutely.
> possibly backed by a nation state
Which nation state, exactly?
There is no public video recording to substantiate their claim. You'd think this entire debate would be settled if on YouTube we could all just watch visual proof of Russians hacking the US.
They also claimed that the video feed came from a university building in Moscow's Red Square. I challenge you to find such a building on a map of the Red Square.
The story which made it to HN: https://arstechnica.com/information-technology/2018/01/dutch...
My analysis is below, but I encourage you to look at Suzie Dawson's epic takedown here: https://steemit.com/steemit/@suzi3d/10-reasons-the-dutch-rus...
So, just because the US intelligence community gets attribution details in 2014 doesn't mean they didn't fake the attribution for the 2016 DNC hack. That's like me registering an account with your username on some site and posting stuff with it - many digital "fingerprints" can be faked. Readers of HN should know this (lol).
Also, the author's claim that the US intelligence community attributed the DNC hack is dubious. James Clapper did, and he threw around a debunked "17 intelligence agencies" slogan[0], but the man's a retired partisan[1]. Recall that the DNC would not let the FBI do actual forensics on their hacked server[2] - well, there's one intelligence agency that didn't get a chance to make an official attribution. Recall too that the Crowdstrike's hack report claims were debunked by the Ukranian army[3] & authenticity of the C&C software was questioned by many in the cyber security community[4].
Like, who didn't know that Russia had hackers? We also know that the DNC/DeepState have a scapegoat.
[0] https://www.realclearpolitics.com/video/2017/07/06/clapper_c...
[1] https://www.usnews.com/news/articles/2016-11-17/lawmakers-re...
[2] http://www.slate.com/blogs/future_tense/2017/05/09/the_fbi_i...
[3] https://www.voanews.com/a/cyber-firm-rewrites-part-disputed-...
[4] http://www.zdnet.com/article/no-smoking-gun-for-russian-dnc-...
Because such hacks don't happen today?
>Which nation state, exactly?
Well, which nation state likes false flags and BS excuses like WMDs for their target du jour?
The most infamous (and heinous) oft sighted example...
https://en.wikipedia.org/wiki/Russian_apartment_bombings
And there are plenty of more recent allegations such as the framing of North Korea for the attempts to disrupt the Winter Olympics:
https://www.wired.com/story/russia-false-flag-hacks/
Parkland shootings etc etc
http://www.politifact.com/truth-o-meter/article/2018/feb/22/...
https://www.washingtonpost.com/opinions/after-the-parkland-s...
As words, phrases and fads spreads on the press, so they do on the internet.
I'm not going to change your mind on what you think is BS, but I do disagree with you. If you have the chance, I highly suggest talking to retired CIA operatives that were active during the Cold War -- the stuff they talk about (when allowed) can be pretty eye-opening.
It generally only takes one occasion of a videotape catching you stealing and an eyewitness corroboration for you to be believed the thief as well.
It's surprising that RT published those. I thought it was an entity controlled by the Russian government. Why would it be publishing the names of its own officers when supposedly the said officers went out of their way to appear Romanian and not Russian.
and please note the careful wording: "Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency’s headquarters on Grizodubovoy Street in Moscow. "
interpretation 1: The guy accessed the device from his GRU office
Interpretation 2: The IP belongs to a guy (maybe his residential connection), and he happens (from other sources) to work at the GRU office. Assuming the GRU device is relatively secure, is it possible that other devices on his home have malware on them? If the latter, all the devices would appear as coming from that same residential IP address.
I work in this field and false attribution happens all the time. Evidence is really easy to fake.
Don't confuse the ease of installing tools that let you maintain access once you have gained access with the ease of gaining access in the first place.
https://www.cyberscoop.com/winter-olympics-hack-attribution-...
https://krebsonsecurity.com/2017/08/blowing-the-whistle-on-b...
https://blog.trendmicro.com/trendlabs-security-intelligence/...
https://blog.talosintelligence.com/2018/02/who-wasnt-respons...
But that has nothing to do with a watering hole attack - are you claiming that successful watering hole attacks against GRU personnel are commonplace?
For example: the Chinese government has been waging war against the Free Tibet movement for years: https://www.google.com.sg/search?q=chinese+malware+free+tibe...
There's a bunch of articles there. One technique is they put up a pro-Free Tibet site, and put malware on it. The visitors get infected and they have an insight into who is interested in that topic and their IP addresses for basic geo location, and maybe remote control of their machines.
If we pick a topic that's super interesting for government intelligence people (like the Guccifer blog site itself), and put some awesome non-detectable malware on there, you could potentially infect multiple intelligence officers from multiple countries.
When the bots phone home, they will report username, domain name, email addresses, visited URLs, security certificates (or basically anything you want). So you now have a rolodex of machines you can manipulate. Mossad did it...nope....North Korea....nope CIA...nope FBI etc etc
Now this is super hard to do in practice. But you only have to be lucky once.
OK - show us. Doesn't need to be GRU - I'd settle for an NSA or Mossad ip address instead. Go on, install a RAT and make a connection...
What is being disputed is that making it look like it came from a Russian intelligence officer specifically, as opposed to from some random infected machine somewhere, is easy. I see that you're claiming that if you set up a botnet and start infecting people and wait, you'll eventually get someone who works for a bank or someone who works for the military, sure. But what are the changes that you'll find someone who happens to work for the specific intelligence agency that is widely suspected as being the actual perpetrator?
Are you claiming that lots of botnet operators happen to have infected so many machines that their chance of being able to get to the machine of an employee of any government agency in the world is high? That the average GRU officer has hundreds of RATs in their home from hundreds of bored teenagers around the world?
I believe that intelligence agencies are targeted all the time, and keeping machines clean is not that easy. Certain governments (like Singapore) adopted an air-gap approach, so the machines you use for work don't touch the internet.
But even then, it would be a lot easier to infect that persons's home machine.....Many of the people visiting Guccifers site were normal people, some were from intelligence agencies (proportionally probably a lot more than visit a normal site).
Assuming you had AWESOME undetectable malware, you'd have to infect the lot, get them to report in, and ferret out the interesting ones. Not exactly a weekend project, but if this was your passion in life, very achievable.
Spear phishing these guys is hard, watering hole may be easier.
I still think we're talking at cross purposes though - I'm not disputing Zeus works, I'm disputing that it's "super easy" to identify and then infect a machine attributable to "an intelligence official in another country".
I mean - if all I need to do is make a tcp connection - all I need is an <img> tag in a web page - the big problem is getting that webpage and/or RAT onto a GRU officer's work computer.
(And if you _do_ cover how to do that in the remaining bit of the talk, I'd love to know...)
"bigian" (an alias) taunted kenbaylor on an internet message board call Hacker News to attack the NSA or Mossad"...
That means that if it it wasn't Russia then it must be some "deep state" conspiracy. Which so far hasn't been backed up by any decent evidence.
Lets see what Jonathan Haidt has to say on the matter:
"“With UMBRAGE and related projects the CIA cannot only increase its total number of attack types, but also misdirect attribution by leaving behind the ‘fingerprints’ of the groups that the attack techniques were stolen from,” Wikileaks said in a statement."
https://www.usatoday.com/story/news/2017/03/07/wikileaks-cia...
and for remote control:
"In April this year, WikiLeaks disclosed a brief information about Project Hive, revealing that the project is an advanced command-and-control server (malware control system) that communicates with malware to send commands to execute specific tasks on the targets and receive exfiltrated information from the target machines. Hive is a multi-user all-in-one system that can be used by multiple CIA operators to remotely control multiple malware implants used in different operations."
https://thehackernews.com/2017/11/cia-hive-malware-code.html
How would either be relevant?
Except the Russians haven't worked very hard to try to deny it.
And - more importantly - everything else they do aligns with this same goal.
It's like during WW2 finding a person spying in London, finding they were passing information on English plans to attack German air defenses to someone in Berlin and saying "Well.. they might have been American, because the US and the UK were rivals during the Washington Naval treaty process during the 1920s". Yes.. they might. But there's a lot of evidence pointing the other way, and German actions indicate it was the kind of thing they would like.
Same here.
Doing something shady from a regular workstation is either a mark of noobiness, or it's someone trying to disguise as someone else. Relying on manually launching a commercial VPN each time when you want anonymity? It's not really opsec per se.