Dark Basin: Uncovering a Hack-for-Hire Operation
citizenlab.ca
citizenlab.ca
Activity like this makes everyone poorer in terms of the actual damage done by the breach as well as all the extra security work that has to be done by Gmail, Dropbox, etc to prevent further abuses like this. It's exactly the type of activity the government needs to protect us from.
Key takeaways:
- Phishing continues to be highly successful (not a shocker)
- Phishing as a Service has significant demand
- The researchers enumerated the targets via poor operational security of the attackers, including one who apparently used their CV as a test document.
stuxnet is attributed to the US and Israel and is regarded as one of the most advanced pieces of malware documented.
furthermore, there is lots of evidence of china absolutely ravaging the intellectual property from other countries, presumed by cyber intrusions. no need to invest decades in people, culture, and research equipment when you can just steal the result from others.
This isn't really a new phenomena. The USSR had spies in the Manhattan project and was able to create a nuclear bomb a few short years after the USA. Or the classic story of the British cracking the German radio communications in WW2 (with the help of the Poles, certainly).
I wonder if we're going to get interesting stories about what's happening right now in the future if it ever becomes declassified. Also, I'd imagine there's just as much cyber intrusions by the American government / American companies as there are by Chinese companies although I will admit I have seen no evidence to point to this. I just think we wouldn't hear about it.