Microsoft has detected nation-state activity associated with NOBELIUM
microsoft.com
microsoft.com
Just tell us which country.. It's probably one of two options.
Other classic examples of non-nation-states are the UK and the US.
It's like saying 'I saw a 2019 Ford Focus in blue' and then when someone points out it was actually a green Dodge saying 'well I just meant any car why are you splitting hairs'.
From this map, you can clearly see that Microsoft uses nation-state and country interchangeably
Nation-state has at least two specific uses in its field of origin (political science), which are closely linked conceptually though very different. It can mean either a state that is approximately one-to-one with a nation as became something of a European norm after after the Peace of Westphalia, or it can be the structural kind of sovereign that became the norm in the same space after the peace of Westphalia (a synonym for the latter sense is “Westphalian sovereign”).
When the context is more legal/structural the latter use dominates, when it leans more to the social the former use does.
The cybersecurity use matches the latter use.
You may be right in poli-sci class, but that's just how it is in cybersecurity. To use your framework, it would be like me colloquially asking "do you have a car?" and someone responding "yeah, a Jeep Wrangler". Car = automobile. But I wouldn't be that casual when filling out my auto's title information.
I would be incredibly surprised if Israel's intelligence didn't make use of NSO tech, especially since their founders came right out of Unit 8200, their military intelligence cyber warfare division.
IDK, maybe using the same type of reasoning which helps convict criminals in cases where there are no witnesses.
Microsoft is not making their own determination of who the state actor is and is just letting the three letter agencies' finger pointing fly with no evidence. There is however significant evidence indicating a country other than Russia in the FBI's Solarwinds report that contradicts the headlines if you read the body of the report.
Such as?
The narrative US = good, Russia = bad is true but only if you are in the US. In Russia you see the complete opposite.
Both US and Russian intelligence have lied in the past, it's part of their job.
For example, the intelligence agencies don't have the right to spy or attack their own population (as far as I know), but there is nothing that forbids them to ask an ally to do it and put the blame on someone else.
Russia denies doing it, and both US and Russia have interest into collecting this data, so starting from there, it's important to keep an open mind that the interactions between countries are not black & white.
The best place to draw the line is Texas. More national identity than Texas and you're a nation-state, less and you're a state. The nationality of Texas is undefined in this scheme, which is just as they would have it.
P.S. people call extremely well-funded cybersecurity adversaries "nation-state adversaries" because those three words start with the letters NSA. It's a joke about US national security being the greatest threat to US private security.
When used in the politico-social sense that invokes national identity, nation-state still takes as a minimum requirement the functional sense of Westphalian sovereignty, which Texas lacks. Texas would probably be considered a nation-state in both senses if it was a nation-state in the functional sense; but as a subordinate unit of a Westphalian sovereignty it is not a nation-state in the functional sense, much less the narrower social sense.
Yes, it does, it distinguishes Westphalian sovereigns (like thr U.S.) from federated states (like Rhode Island).
This introduces the much more serious meta-problem of distinguishing commenters who merely happen to use 'Westphalian' from Lyndon LaRouche fans.
It is directly applicable, and not at all a used; the broader functional (Westphalian sovereign) and social (the functional definition + two-way close mapping to a nationality) definitions of “nation-state” are both technical definitions widely used (and distinguished by context) in the field from which the term originates. (Just like “consistency” has different meanings in a CAP context vs. an ACID one, except with less ambiguity for “nation-state”, because compared to the functional and social definitions of “nation-state”, the CAP and ACID definitions of “consistency” are far more likely to both be plausibly relevant in the same context.)
The common use in cybersecurity is exactly the functional definition, not an abuse of terminology.
Its a nation-state in the functional sense (a Westphalian sovereignty) but arguably not in the politico-social sense (a nation-state in the functional sense that is also aligned with a single national identity and vice versa), though like most Westphalian sovereigns where that is true, works very hard to align national identity with the state, and the former sense is mostly a clear, concrete distinction [0] while the latter sense is a platonic ideal which is, at best, approximated, so binary inclusion/exclusion is always something of an arbitrary line-drawing exercise.
[0] And mostly corresponds to status in international law, but there are exceptions
Instead, we are rarely given any evidence at all. In the article cited, we're just supposed to trust that Microsoft knows it's Russian government and can prove it. When we _are_ given some explanation, it's usually pretty weak: IP addresses are from XYZ country, metadata in a word doc is ABC language, etc. Add to that you have criminal elements that may or may not be controlled by their government.
...and then when you do question, you're downvoted, accused of being a shill, etc. I understand this sort of thing can rarely be proven 100%, and there is a need to protect intelligence sources and methods, but given that we should stop speaking and behaving as though things are 100% certain. Personally I'd like to see articles present more evidence and/or summarize into a percentage. "We rate the likelihood this is XYZ branch of Russian government at 60% due to the following factors: ...."
We can debate whether the Kremlin controls Russia's criminal elements. What is apparent is it's unwilling to pursue them. So much so that they practically live in the open.
It creates a bureaucratic situation where a company might have a great deal of data points to base an attribution on, but is prevented from disclosing 95% of them... not necessarily out of concern about source protection, but simply by contract with the data source(s).
There's a long-running controversy within the industry about whether or not this situation is productive. The confidentiality agreements make corporations more willing to disclose data due to reduced risk of reputational damage and liability. But it also tends to make research and open communication more difficult and vague. The federal government has been through basically the exact same controversy over the last two decades regarding intelligence sharing, and to further complicate things it's common for there to be government elements (e.g. DHS) involved in these circles that mean there are also confidentiality agreements between government agencies and private industry that enforce many of the same rules.
At its core, this comes out of a fundamental tension of liability and the law: is it better to do research that will produce damning material in lawsuit discovery, or to avoid doing the research and remain ignorant to the problem? Various industries have various half-solutions to this problem (e.g. Patient Safety Organizations in healthcare that are exempt from discovery), but the dominant one in information security reflects the roots of the industry in the intelligence community: anonymity of sources and confidentiality of information.
Microsoft has been quite lax lately with a lot of things, you only need to see the stuff Kevin Beaumont is posting (ex-MSFT employee - senior cyber) about them knowingly hosting malware in OneDrive (standout as a OneDrive user), and knowing about a lot of issues and potentially being rather passive about fixing them.
I love MSFT products, but lately from what I’ve been reading, their attitude to a lot of things security lately is a bit worrisome to me, I could be completely wrong as i don’t know what’s happening internally, but it’s also slightly worrying from one of essentially, the most powerful cyber security firms around.
its their "Marble" program, that was leaked in Vault 7
"Marble is used to hamper forensic investigators and anti-virus companies from attributing viruses, trojans and hacking attacks to the CIA,"
so how can anyone really say who did what when it comes to cyber crimes? unless you have a camera watching the person doing it?
Could be Russia, could be domestic agencies. I think it is safer to deduct responsibility by the reaction.
This sort of results in an impression that there is a capability asymmetry between the two. Is that true? Or do we just not hear about it.
NATO does not want this fight, and they do not have the hierarchy of plausible deniability, which the Russian security services have perfected to a form of art.
"Independent" hacking groups do jobs for the government, in exchange to freely conduct mercenary for-profit attacks without fear of being jailed.
NATO countries don't have this system. If they do something, they do it without proxies.
https://arstechnica.com/information-technology/2018/01/dutch...
Or asymmetry in the desire to report it. Any country reports threats against them wide and far, and they downplay or ignore any threatening actions they make.
> NATO countries don't have this system. If they do something, they do it without proxies.
Colour me skeptical. "Open and transparent" is just not how intelligence services operate.
The Chinese media would label such an attack as a US hack on China, while the US media would report it as a Korean hack on China (meaning you probably never hear about it at all unless you’re in the business).
I’m only aware of this happening the other way round (.ru crime actors doing things Moscow needs done, ddos on Estonia etc etc)
I’d love to read more on this.
https://en.wikipedia.org/wiki/Cozy_Bear for the sources for each name
[1]https://news.ycombinator.com/item?id=28980382
[2]https://www.destinypedia.com/Grimoire:Allies/Rasputin#Ghost_...
They really do though, some RASPUTIN level AI just naming things.
It's very interesting to see how humans naturally tend to craft identities for faceless, nameless adversaries, which I think is very interesting from a social standpoint. Also the artwork in the website above is just plain cool IMO :)
Although the vendors share information quite freely, I think there's hesitation on a vendor mutually adopting another vendor's threat actor name because it implies more substantive research on the latter's part, which is usually a no-no in a field like this. Ofc, I'm sure there are exceptions.
edit: I also wanted to give Thai CERT a shout out and add a link to https://www.thaicert.or.th/downloads/files/Threat_Group_Card... which is less flashy than the CrowdStrike compendium, but well-detailed
It's quite simple: you need a name (preferably unique) in order to refer to it in communication.
The authorities are so incompetent in generating consequences that they have go with the idea that Putin signed off on the action himself, just to deflect
“A dozen intelligence agencies” are all going to have the same evidence: a non-VPN IP address
People are really gullible, remember when even just that turned into a partisan thing a few years ago? lulz. idiots.
The names were classified (Secret perhaps?), but at some point the US Government realized everyone was kinda using these names in conversations, probably not all at the secret level. These names had leaked out too much, they needed new names.
So they decided to rename them with new Secret names, and just kinda let the old names become utilized. They tried to hide the old <-> new name mapping because the new name mapping was classified.
Crowdstrike started as mostly former FBI / NSA employees. They liked using all these names to identify actors. But they realized they didn't want to use classified names. So they came up with their own very boring names (APT1, APT2 ,etc.). While others had always done this internally (Microsoft had names, Google had internal names, etc. etc.), Crowd strike utilized these names very publicly and it just kinda took off.
I think the US Government at some point realized they could just use Crowdstrike names and avoid all of the Classified name mess, so they just utilized crowd strike names as well. So now Crowdstrike names are mostly the go-to. Unless you are micrososft, then you keep using your names....
My guess is Somewhere at Ft Meade an analyst has produced a massive, beautiful chart mapping all this shit together, and her sole job is to keep it updated.
...or this is my best guess anyway.
For Microsoft specifically, we leverage the periodic table of elements when naming nation states.
Notice how everyone in this thread is scared of "nation-state" and Russia - this is the exact emotion and reaction Microsoft wants. After fear of some "god-level Russian state hacker superpower" is seeded, the next logical step is to SELL some crappy cloud subscriptions for $$$ and keep milking your fear and making money.
Claiming that the notice is false simply because some aspect of it it may also align with some profit sounds like an entry-level fallacy spouted by Qanoners, or an actual RUS twitter troll posting their daily dezinformatsiya, or just the everyday paranoia of those who flock under those banners.
Do you have any actual evidence that the notice is false?