Highly Evasive Attacker Leverages SolarWinds Supply Chain
fireeye.com
fireeye.com
Dang, that's pretty sneaky. This is one heck of a hack.
In this case, it's likely that they somehow found the backdoor in SolarWinds' network and realized what was happening that way.
It doesn't take a great deal of sophistication to come up with some of these things, just a bit of cleverness and exposure to the possibility of cleverness.
Then someone realized it was also a good early warning system for new viruses, as many viruses would crash their host process in novel ways that were unlike the usual software-induced errors.
WER reports also could do other things. Sometimes bizarre, impossible crashes would happen. Microsoft would investigate some of these by showing a popup to the user inviting them to participate in analysis. If the user consented, they were put in contact with a Microsoft engineer. Turned out a lot of people were running unstable, overclocked hardware sold to them by vendors who had fraudulently misrepresented the hardware.
The telemetry that is out there is amazing, but not as amazing as the secrets it can reveal.
The original devblog from 2005 is (https://devblogs.microsoft.com/oldnewthing/20050412-47/?p=35...). Aside: Upon pulling that up, I recognized the author as the one who wrote my favorite article about undefined behavior (https://devblogs.microsoft.com/oldnewthing/20140627-00/?p=63...).
[0]: https://www.goodreads.com/book/show/18465875-countdown-to-ze...
But it could go unnoticed and disregarded as completely normal, benign network traffic for years, or perhaps forever.
I frankly don't know how anyone finds any of these sort of burried attacks anymore. When software systems were simpler, it was already difficult to know enough about a system to detect or observe abnormal behavior and that was with simple systems with a fairly deep understanding of how things should be.
Anymore, so many systems are some tower of SaaS APIs mixed with commercial on prem software, then mixed with internal developed software spread across multiple teams, developers with high turnover rates, focus on functional software over specification/documentation for anyone to compare to, etc. that it seems like running over these issues are flukes discovered either by dedicated teams looking only for these issues (security auditing teams) or developers maintaining systems than happen to run across an abnormal behavior in the process of normal maintenance.
Unless the outer layer is a legitimate service that's actually in use, this kind of thing only fools people who'd dismiss this traffic as "something I don't know about, but which is probably benign". Then there's the whole figuring out what IPs this is going to part, which would raise more alarm bells.
Cute, but I think you could do better. Hiding from someone looking at your traffic is very hard. The more important part is how well you hide from dumb automated tools that people rely on for initial detection.
Then again, a huge portion of the auditing/"infosec" market nowadays are untrained random people running automated scanners who actually have zero reverse engineering or proper security research experience, so I'm sure it'd work well against those.
This isn't accurate. If you look at the Snort rules used to block it[1], it is masquerading as traffic to .solarwinds.com (ie, the vendor) to URLs looking like: swip/upd/SolarWinds.CortexPlugin.Components.xml
Unless you knew the software isn't supposed to do that, it isn't suspicious at all.
[1] https://github.com/fireeye/sunburst_countermeasures/blob/mai...
If this were HTTPS then it wouldn't need the obfuscation to pass by undetected. And then there isn't much you could do at that point to find it via traffic analysis, assuming the uncompromised app makes similar HTTPS connections, other than perhaps going deeper into traffic pattern analysis if you're lucky.
Once the threat is identified some other way, it might be possible to develop blocking rules that work at the ciphertext layer (e.g. from packet size patterns exhibited only by the backdoor requests).
It's unclear from that one rule but the majority of the Snort rules for this exploit stop HTTPS. Note the "port 443" in the rules.
A proper analyst working in a well-funded clean environment with carefully defined legitimate traffic patterns. That is not a majority of organizations and it would be very easy to miss something like this in the other 99% where they’re understaffed, dealing with the noise of routine malware, and what appears to be a poorly written vendor application doesn’t stand out as much when you have hundreds of them.
Human ingenuity is really impressive sometimes.
Even a fresh Windows install these days has so much regular network activity for telemetry and other services, it's trivial to hide bad behavior.
NXDOMAIN is watched because known malware has been observed to use it.
But I tell you: malware can just as easily utilize a valid DNS response.
The downside is that all the bots will generate a lot of DNS traffic checking for those domains. That's what's being detected here -- the NXDOMAIN responses don't carry any desired data, but the malware can't avoid generating them while it's looking for its owner.
For those following at home, these are caused by Domain Generation Algorithms that try a ton of (deterministically generated) top level domains. The attacker need only register one of them, and if the domain gets frozen they can often just register another -- until the generator algorithm is integrated into the registrars' blocking system, which takes time and work.
Personally I'm surprised we don't see more malware using the various DNS replacements that sit on top of Ethereum. They were using Namecoin for a while.
Deeper heuristics on the deviations in that telemetry from normal could also have provided a signal that something was off -- like the temporary file replacement activity.
Without telemetry that kind of activity could likely continue undetected for longer.
Had you left your VM running a little while longer, you might've noticed something else in your Netflow data: yet another service calling home to Canonical twice a day.
I wish I were joking about this but... the (likely) "primary" reason for this is so that they can show ads to users when they log in -- ads for things like TV shows or software for other operating systems or, sometimes, just a "fun fact".
I can't really say it's the only reason, however. With all of the system information they're getting off of each host, there's now several different things they can use it for and, of course, that provides them with even more motivation to keep doing it!
This isn't a new thing, though. In fact, people have been expressing their "unhappiness" about it to Canonical for a few years now [0,1,2].
Unfortunately:
- it's still installed by default
- it's still enabled by default
- they've actually increased the amount of system info that they're collecting [3]
- it's installed as part of the "base-files" package -- an "essential" package which cannot be removed!
- "it's a 'feature', not a bug" (so we absolutely should not expect it to get removed)
- apparently, a 42 line MOTD [4] is perfectly acceptable
I suppose there's one "positive" thing I can say about it: at least they're using TLS to encrypt the data over the wire. :/
--
If you want to disable this spyware on your Ubuntu hosts, change "ENABLED" to "0" in /etc/default/motd-news:
$ sudo sed -i -e '/^ENABLED=1$/s/1/0/' /etc/default/motd-news
When executed, /etc/update-motd.d/50-motd-news checks if "ENABLED" is set to "1". If not, it exits without calling home.50-motd-news gets launched by motd-news.service which itself is activated -- twice per day -- by motd-news.timer. Since I like to be thorough, I recommend running a few more commands (as it's impossible to know that Canonical won't change any of this in the future!):
$ sudo systemctl mask --now motd-news.service
$ sudo systemctl mask --now motd-news.timer
$ sudo systemctl clean --what=state motd-news.timer
$ sudo rm -f /var/cache/motd-news
That should do it. If you're rather not have to worry about something like this in the future, you may want to consider replacing Ubuntu Linux with Debian GNU/Linux.--
[0]: https://news.ycombinator.com/item?id=14662088
[1]: https://old.reddit.com/r/linux/comments/98ctgu/ubuntu_server...
[2]: https://dev.to/fivnex/open-letter-to-canonical-ltd-a1k
[3]: https://bugs.launchpad.net/ubuntu/+source/base-files/+bug/18...
https://blogs.microsoft.com/on-the-issues/2020/12/13/custome...
> An intruder using administrative permissions acquired through an on-premises compromise to gain access to an organization’s trusted SAML token- signing certificate. This enables them to forge SAML tokens that impersonate any of the organization’s existing users and accounts, including highly privileged accounts.
See detailed version: https://msrc-blog.microsoft.com/2020/12/13/customer-guidance...
> In actions observed at the Microsoft cloud, attackers have either gained administrative access using compromised privileged account credentials (e.g. stolen passwords) or by forging SAML tokens using compromised SAML token signing certificates.
> Although we do not know how the backdoor code made it into the library, from the recent campaigns, research indicates that the attackers might have compromised internal build or distribution systems of SolarWinds, embedding backdoor code into a legitimate SolarWinds library with the file name SolarWinds.Orion.Core.BusinessLayer.dll.
It should probably become a requirement (for both open and closed source software) that any updates be not just signed but have their hashes available in a Binary Transparency log[0].
When you first install a piece of software, you might need to calculate the hash locally and manually search for it in a log's web interface, but after that, its software-update routine should check that the new version it is downloading has had its hash published in a known place. That way, software publishers can check an append-only independently-run log to see what has been signed with their keys.
I suppose there is a risk that an attacker could prevent users from receiving security updates by DoS'ing the transparency logs, but that should be harder than just DoS'ing the servers that host the software updates themselves. Large organisations could also maintain mirrors of these logs on their internal networks, which would help with privacy/latency/availability, and the logs should ideally be available as Tor hidden services too.
For non-critical updates, the log checking routine should require that the update's hash had been in the log for a certain period of time, long enough for the software publisher to notice and raise the alarm to their users. Updates marked as critical should default to stopping the software from running until the necessary period had elapsed, for which the workaround would be a fresh install of the newer version by whomever has the admin privileges to do that.
I’m not in favour of having public client lists, especially when you’re a critical software vendor — but this list is just terrifying. There are a lot of big there, and I won’t be surprised to hear of more incidents in the coming days.
What’s the opposite of security through obscurity?
Marketing
Security.
I mean that company list has "smith barney" which doesn't exist anymore.
If you look at operation model of threat actors, even with current hack, they have their targets and no one is going to say "hey they have solar winds let's hack them". Threat actors have their budget, limited time and goals. They could also find this information by other osint means. Even if they have it on that page, they still need to make their research.
Even if SolarWinds would not have a list on their page they are so big that you can count them as interesting target anyway. It is the same with Google and MSFT you can safely assume if you hack them, some of your targets will use some tools from those companies.
I mean security by obscurity is fine, but I don't see what kind of value it would bring in this scenario.
Generally, you have to get a company's permission to use it's name or logo as an endorsement. That agreement has stipulations, such as being revoked if the association could bring disrepute or reputational harm to the endorser.
I'm sure none of the companies on that list want their investors calling the IR to ask about whether this event is a material issue for the company.
Had the same with Citrix hack that was going around, we never had any Citrix but at we got at least ten calls.
Here it is from earlier today:
https://web.archive.org/web/20201214065921/https://www.solar...
SolarWinds’ comprehensive products and services are used by more than 300,000 customers worldwide, including military, Fortune 500 companies, government agencies, and education institutions. Our customer list includes:
- More than 425 of the US Fortune 500
- All ten of the top ten US telecommunications companies
- All five branches of the US Military
- The US Pentagon, State Department, NASA, NSA, Postal Service, NOAA, Department of Justice, and the Office of the President of the United States
- All five of the top five US accounting firms
- Hundreds of universities and colleges worldwide
Partial customer listing:
Acxiom
Ameritrade
AT&T;
Bellsouth Telecommunications
Best Western Intl.
Blue Cross Blue Shield
Booz Allen Hamilton
Boston Consulting
Cable & Wireless
Cablecom Media AG
Cablevision
CBS
Charter Communications
Cisco
CitiFinancial
City of Nashville
City of Tampa
Clemson University
Comcast Cable
Credit Suisse
Dow Chemical
EMC Corporation
Ericsson
Ernst and Young
Faurecia
Federal Express
Federal Reserve Bank
Fibercloud
Fiserv
Ford Motor Company
Foundstone
Gartner
Gates Foundation
General Dynamics
Gillette Deutschland GmbH
GTE
H&R; Block
Harvard University
Hertz Corporation
ING Direct
IntelSat
J.D. Byrider
Johns Hopkins University
Kennedy Space Center
Kodak
Korea Telecom
Leggett and Platt
Level 3 Communications
Liz Claiborne
Lockheed Martin
Lucent
MasterCard
McDonald’s Restaurants
Microsoft
National Park Service
NCR
NEC
Nestle
New York Power Authority
New York Times
Nielsen Media Research
Nortel
Perot Systems Japan
Phillips Petroleum
Pricewaterhouse Coopers
Procter & Gamble
Sabre
Saks
San Francisco Intl. Airport
Siemens
Smart City Networks
Smith Barney
Smithsonian Institute
Sparkasse Hagen
Sprint
St. John’s University
Staples
Subaru
Supervalu
Swisscom AG
Symantec
Telecom Italia
Telenor
Texaco
The CDC
The Economist
Time Warner Cable
U.S. Air Force
University of Alaska
University of Kansas
University of Oklahoma
US Dept. Of Defense
US Postal Service
US Secret Service
Visa USA
Volvo
Williams Communications
YahooGeneral reminder that your funny 404 page becomes instantly unfunny the second your tech department both publicly and catastrophically shits the bed: https://i.imgur.com/kNbScVH.png
* https://web.archive.org/web/20201213230906/https://www.solar...
What is SolarWinds, and why are all these organizations using it?
Clearly, it’s a giant single point of failure, but other than that, I’ve never heard of them.
Their marketing says they do network monitoring, etc. Do they have a legitimate product, or is this just another case of enterprise checkbox security theater gone awry?
The thing it does for many orgs is become a "one stop shop" for the array of products a "modern" IT stack needs... and if you thought splunk was expensive...
I have definitely found some deficiencies in SolarWinds products I've used that feel like they should've fixed long ago. But their products are also leaps and bounds better than tools I worked with prior.
Not the best, but very far from being the worst.
If your antivirus product is any good, it will work fine with legitimate software. But that is entered solely as a support disclaimer for "I can't guarantee anything if anything else is running on your system".
It's used to set alarms that will go off if "process XYZ is not running on server 123" or "CPU Utilization is over 95% for 15 minutes on server 456" that kind of thing, as well as dashboards.
The special thing about Solarwinds is that it's agentless, meaning you don't have to install an agent on the boxes you want to monitor, I think it uses ICMP to ping the instances you're monitoring.
It's terrible software (compared to say, Datadog) and I've been saying I want to short it for a year. Obviously I should have put my money where my mouth was.
I'm sure 100% of small ISPs use them as well as anyone that runs a decent size Network ex. Schools, Universities.
I wonder what the cost of an attack like this is. It doesn't feel impossible for a small group (< 10) of very smart and motivated people to maybe achieve this in 12-18 months of work?
Of course they could be working on behalf of some nation state, but compared to let's say an ICBM attack, this is probably not out of the realm of non-nation-state actors to pull of.
An entrepreneurial crime syndicate would probably have the resources to do this (or outsource to some mercenary attackers).
They used a an on-premises compromise to gain access to an organization’s trusted SAML token- signing certificate. This enables them to forge SAML tokens that impersonate any of the organization’s existing users and accounts, including highly privileged accounts
Note the on-premises compromise (!!)
Microsoft credits it to a nation state.
So then the question becomes was it really a nation state, or just incompetence being covered by claims of "nation state" hacking
https://savebreach.com/solarwinds-exposed-ftp-credentials-ba...
Most of the SolarWinds tools run on Windows only. Some of the obfuscation they use reminds me of how complicated PSD is to parse.
Finding that you've been infected with this malware should trigger a critical response. I wouldn't even feel safe until I've nuked all the servers and rolled as many credentials as I could. And even then who knows how much data the attacker could have already exfiltrated. Frankly this level of sophistication is terrifying because you really never know for sure how deep they managed to get in.
The word you're looking for is probably "prosaic".
A large chunk of people making iPhone apps is basically tied into the feature set given to you by Apple that you leverage to make a product on top of. Same with Android.
What's a "vertical" in this context? The article uses it as well, but also doesn't explain. This is the first time I've heard the word used this way, and it's a tough one to search for.
But here it's actually overspecified. Parent probably wanted to simply say that Microsoft has a gigantic market share in basically every industry sector.
Despite what one might think, Windows is still ruling the desktop and in a typical enterprise environment often also the server landscape.
Basically any company that isn't a software-first company is using Windows. It's clearly not a hard rule, but it's definitely a trend.
Healthcare, Insurance, Automotive/general manufacturing, Professional services, logistics, etc, etc are Windows primary orgs. For many of these companies, internal software development is a relatively recent trend (compared to their company history) so they have IT departments that hold everybody on Windows.
Instead there's clearly a large market for them to be comfortable with being Windows only.
It be would interesting to know how it was originally detected/discovered.
The knowledge of how it works and the level detailed shared in this particular case is also interesting. It’s almost like they are burning this one on purpose.
Gonna be a busy week for a lot of teams.
If somebody can backdoor one of their products it would stand to reason they can backdoor others too.
IME needs to go away.
If this hadn't been spotted sooner I wonder if the affected component would have ended up being bundled into n-Able and being shipped that way too.
Ensure you have a reproducible build, then randomly build on a different machine and compare file signatures of the results. Do it every so often with a “clean room” machine. Probably no need to run parallel infra that’s just as likely to be hacked.
Code signing hardly means much. All you have to do is compromise CI to make an organisation sign a binary that isn't based on reviewed code.
How hard is that? I think for the vast majority of us we have to admit our CI would be very easy to compromise. Especially if you can get administrator credentials as easily as these guys apparently can. But even without that, CI executes and runs arbitrary code that's intended to only come from trusted individuals.
Step 1. Find a third party package or library that is being downloaded by a package manager onto a CI box.
Step 2. Compromise the open source dev's laptop by phishing them or something else really basic.
Step 3. Put a back door into that package.
Step 4. Wait for it to be downloaded to and executed on SolarWinds CI.
Step 5. Insert a rootkit into CI.
Now that rootkit can just systematically insert the final back door into any build of that file it sees using link time editing. Every build will have the back door and the owners will eventually sign the binary and push it out to production.
In many orgs CI can actually request signing of any binary it wants, so you don't even have to do that. You can just hack the CI machine, grab the credential used to authenticate to the HSM, sign your preferred binary and then ensure users are downloading it.
What if this exploit came through a compromised third-party dependency (eg npm or pypy or deb or rpm or docker image) that made its way into SolarWinds CI system?
Is that something the rest of us now face?
That means we're not finding them, not that they don't exist.
Considering how easy it is to create plausible external attack vectors from the inside, I would be surprised if it didn't exist.
As you said, intelligence agencies have had people on the inside of important organisations since forever. That's what they do. It's not like everyone decided inside access is useless, it's more likely it has become easier to not burn insiders by them having to work hands on.
Step 2 can also be: Buy the open source package from the maintaining dev.
It has its place, but it has become massively overused.
The “Delivery and Installation” section covers this. It’s a very short section, the subtext of which is that there’s basically no defense for malware delivered with a valid signature from a trusted vendor.
It’ll be pretty interesting to find out what happened at SolarWinds in the coming days: whether this malware was smuggled into the update via employee collusion with attackers or a hack of SolarWinds itself.
Was someone being blackmailed? Or a malicious actor managed to gain employment?
That Jenkins plugin you haven't updated in years. Or that maven package no one knows about.
Third party risk management is unfortunately not well funded cyber security vertical.
You think you are supplying software to all the armed forces branches and "forgot" to update a Jenkins plugin?
As a security professional, getting people to upgrade simple software is difficult enough, upgrading critical infrastructure used 24/7 by the development team... forget about it.
yeah. Just now I am reading that their FTP servers had such a weak password that it allowed the pentester to upload/replace any binary back in 2019
If you think about it for even a moment you'll see that for code signing to be meaningful requires a completely locked down software supply chain, including controls that trace through developer laptops and third party open source code that's pulled in to your application. The typical app developer combines components from a huge number of sources of unknown reputability and security strength, which are then all executed on laptops that have permission to push arbitrary jobs to CI clusters.
https://www.kxan.com/news/local/austin/austin-based-solarwin...
I understand that Solarwinds is a reputable company with all the right security auditing and compliance credentials. That's why they are used by US federal and state government agencies.
Perhaps the criteria (MBA/Audit/Management driven security) that governments use to judge vendors is useless against real world attacks? If I wanted or needed to be compliant, I would buy that software (like all the other gov agencies), but if I wanted to be secure, I would not.
If you think about it, the modern cloud-native approaches are logically aiming for the same. You have a centralised management system (the cloud provider's engine), with programmatic configuration (infrastructure-as-code and indeed everything-as-code). We even call these modern best practices. Just instead of a webgui management console, we have git repos, and in place of two-person change protocol we have mandatory code reviews enforced by tooling.
A single point of failure is one side of the coin. The side you're not looking at is single point of control.
No, You're right. It's not.
But I mean, it's totally different that a hack to Solarwinds and FireEye that was before the election and just assume a correlation knowing that all these counties and election systems suppliers use SolarWinds but only might be contributed to Russia should be considered the same as the Russian disinformation campaign carried out on Facebook ads in 2016.
I mean, one would be election shattering but there is no proof, and the other we are pretty sure happened even though nothing came of it at all.
Your threat model just got....complicated..
As for the write-up itself, I honestly can’t believe they published this much detail. The feds and FireEye must be very concerned that folks are exposed to this right now and those folks don’t know it.
I've noticed this since the NK hacks in 2014 and it's bothered me. Why is this the reaction even in technologically savvy quarters?
Tech nerds like to describe things as boring, obvious, and easy to do, it makes them feel smart.
Certain politics lead people to assume that government is incompetent and therefore obviously it was an unsophisticated attack that breached them.
A lot of IT workers think every instance of a hack is an example of underfunding the IT department, or the IT department wastes the budget they do have.
I would say history leads people to assume that government is incompetent. We have plenty of evidence on which to form this conclusion
>A lot of IT workers think every instance of a hack is an example of underfunding the IT department,
Again this is also drawn from a place of experience, many of us have seen first hand organization refusing to put in the money needed to properly secure systems until AFTER their is a compromise, and then the money is only allocate for a few months to resolve the exact compromise that impacted the organization never really changing the security posture of the company / organization.
This pattern is repeated over and over and over again
Security has a certain cachet which makes people want to sound like experts and one way to do that is to minimize others’ accomplishments, implicitly saying that they aren’t challenging to you.
Dunning Kruger doesn’t cover the entirety of what’s happening, but there’s some pathology at work here.
Example: "Continents move around", "time slows if you're fast", and "turtles, all the way down" are all similarly ridiculous unless you've studied these subjects. People see the first two receiving lots of applause[1] and start making claims that to them are just as believable.
[1]: Or they see footnotes being correlated with "serious science" and start adding footnotes.]2]
[2]: For details on how references make people appear smart, see Feynman, 1968: Cargo-Culting. Also scientism
[3]: A heuristic that in our experiments succeeded in identifying 0.65 of the lower 20-quantile of wannabe basement-warriors is to count the occurrences of the terms /threat (model|actor)/, /sigint/, /retcon/, /psyops/, /opsec/, and the phrase /everyone does it/. Exclude any >= 1.
One of many examples:
https://firstmonday.org/ojs/index.php/fm/article/view/528/44...
Also, it’s standard practice to write these things up in full detail.
This annoys me.
1) I'm equally breached whether the hacker used a sophisticated attack or not.
2) A "nation-state" attacker is more than willing to use "unsophisticated" attacks to accomplish their goals.
In fact, a "nation-state" attacker is probably less likely to use "sophisticated" attacks as they will want to save those for the cases where they really need to get through security.
This could be a stuxnet type attack looking for a particular facility, or something far worse at a time when the US is most vulnerable.
Just from the target I'd suspect it is not someone doing it for the lulz, but I didn't see anything in OPs quote that indicates that it must be a nation state.
Edit: a quick counterfactual here. If this is so easy and so valuable, why is it so rare?
Designed, as in back-of-the-envelope chicken scratching? Sure. You can reduce almost any exploit to "compromise system or org, leverage compromise to go after another system or org" and any stealth measures reduce to something like "hide your own efforts among legitimate signals, and use cutouts to make them harder to trace back".
I'm not sure what you think counts as "sophistication", but thinking up the specifics of multiple stages, and executing each stage without errors that would expose the other stages to detection isn't easy, and takes time and patience by many people with diverse skills working in concert.
Sure, each specific link in the chain may not look difficult, but those were just the solutions that worked in isolation when tried in whatever testing environment(s) the threat-actor operates (not to mention funding the "blue team" that operates it, because you don't want your unsuccessful attempts to tip your hand), and then deployed in sequence.
Or were you under the impression that this whole effort was created de-novo and worked (correctly, might I add) without being detected the very first time each component was tried?
The old school concept of a script kiddie was someone who had a limited skill set that consisted of downloading exploits and trying everything to see what worked. Traditionally, a script kiddie didn't develop any of their own exploits.
Nowadays these people are known as Network Security Consultants and they are paid very well.
[0] https://www.computerworld.com/article/2483923/poison-ivy--us...
Targeted, sophisticated, nation-state threats are real and have been documented in the FLAME, DUQU, DARKHOTELs of the world. Supply-chain attacks are not new either, Juniper was compromised 4 years ago and backdoored into their firmware, NOTPETYA compromised a legitimate accounting software company, and ransomware has been delivering through MSPs for quite some time.
Professionals look at indicators posted and techniques leveraged and come to their own conclusions.
This is not standard malware. This was not a script kiddie.
> The IP address was linked to the GRU HQ itself. https://www.techradar.com/news/defending-against-nation-stat...
> one website that helped to coordinate them, StopGeorgia.ru, was hosted at an IP address that belonged to a company headquartered next to a GRU-connected military research institute https://www.wired.com/story/us-blames-russia-gru-sweeping-cy...
> Dragos researcher Joe Slowik noticed that one IP address identifying a server in Hungary used in that APT28 campaign matched an IP address listed in the CISA advisory https://www.wired.com/story/russias-fancy-bear-hack-us-feder...
> They used an Ip address that has been previously seen in other russian attributed attacks https://abcnews.go.com/WNT/video/ip-address-linked-russia-dn...
List would go on and on, and this is only for Russia. And yes I'm aware those sources are easily discarded as "non serious enough", as expected from the top results of a search engine I guess. Do your part and provide us with better sources.
Unfortunately, evidence is never provided beyond hearsay.
> umanghere 1 minute ago [dead] [–]
> Here’s a list of SolarWinds’s customers:
> https://www.solarwinds.com/company/customers
> I’m not in favour of having public client lists, especially when you’re a critical software vendor — but this list is just terrified. There are a lot of big there, and I won’t be surprised to hear of more incidents in the coming days.
That's exactly what vouching is for: https://news.ycombinator.com/newsfaq.html#cvouch.
coryrc already pointed this out but I want to hammer the point :)
(Users have already vouched for the comment so it's no longer dead.)
To flag a comment your account needs a minimum score, I'm not sure, but I think it is 50 (or 100 or something).
To flag something you click on the timestamp on top of the comment (typically something like: <x> hours ago). This opens a view of only that comment and replies to it. If you have enough reputation/points/karma, you can now see a flag link on top of the comment. If you click flag it ends up in a moderation queue. If multiple users click flag it might bypass the moderation queue and become flagged immediately without further intervention from mods.
(No one flagged it.)
It is that simple.