Which in weak cases can be an artifact observed throughout the attacks though not necessary for the behaviour to occur (e.g. compiler timestamp), and in strong cases the artifact is tied directly to the malicious behaviour (e.g. explicit registry key or anti-infection marker)
Even if US intellegence is pinning it on Russia or it was someone else, there's no way we're going to know about it right now.
Releasing attribution evidence right now will not happen as that would intrude on the response. Instead you will get signatures for specific pieces of malware or generalized yara rules to look for indicators of compromise. The specific indicator that allowed for attribution may never be released as then this particular adversary could work around it.
FireEye is a reputable security organization that is publicly traded. If they were lying and it was discovered as a company their business would go away rapidly and some of their executives might even go to prison. If you have legitimate evidence that casts doubt on their statements please share it. Finding something that significant would shake up the industry.
Attribution is most likely a combination of evidence and forensic data collected both from the initial breach (SolarWinds) and other breached entities. Things like how data was exfiltrated and to where to who purchased and setup the domain names, any other malware that was loaded (was it signed, compiled, contain a certificate, etc).
While Snowden did reveal interesting things, there is zero basis to support anything other than a Russian state actor at this time.
I think a more likely outcome would be their stock price would drop for a few weeks, maybe executives would resign, and then it would be forgotten.
So was RSA when they accepted $10 million from NSA to backdoor their crypto library. As long as FireEye keeps the customers who pay the bills happy they'll be fine, just like RSA was.
We _knew_ at the time that Dual EC_DRBG was bad - there is an entire openssl mailing list archive from the moment it was announced/proposed talking about it being bad
FireEye / Mandiant are _the_ team within infosec who are experts in the field of attributing state threat actors - you won't find many experts who openly disagree with them
SANS isn't some secret government group - I have a colleague who is an instructor there. Those recordings aren't some top secret briefings. I and a lot of other industry professionals attended them
> " It's FireEye spewing out stuff as "facts" with very little evidence."
An APT has certain TTPs that allow you to start to figure out who is behind attacks. FireEye has tracked the attacker as UNC2452, which means it is "uncategorized" in their view. Others have come forward pointing fingers at the SVR.
Finally, just a tip: if you want to sound like you know what you're talking about, it's not a "CNC" it's a "C2".
> SANS isn't some secret government group
I understand that, but the video/livestream they released at the time was Unlisted on YouTube and had a watermark saying it wasn't for general release. I realize they didn't intend to have it up permanently and am familiar with the roles SANS has in the security industry. I was just commenting on the video and things I think they got wrong.
> Finally, just a tip: if you want to sound like you know what you're talking about
No need to be insulting. I've heard them called Command and Control servers before. I don't currently work in security; haven't in years. I'm just speaking as as developer/sysadmin.
If you genuinely don't know how companies like FireEye do attribution then one has doubt the level of insights you have.
Notably in this case FireEye said they COULD NOT attribute the attack to any group initially:
"FireEye wouldn't confirm the APT29 attribution and gave the group a neutral codename of UNC2452, although several sources in the cyber-security community told ZDNet the APT29 attribution, done by the US government, is most likely correct, based on current evidence"
https://www.zdnet.com/article/microsoft-fireeye-confirm-sola...
seems very very far fetched. i guess if i got caught breaking a ton of laws against my own government I might want to misdirect too
this seems like the same trolling type comment farm crap we see anytime these countries come up