Most of it was just malware analysis and people creating pubstro servers for fun with different communities.
Not everything is Reds under the bed.
I've heard of someone who completely reverse engineered the iTunes DRM just because he wanted to download 4K to watch the series that he had "bought" from Apple offline on his TV. It's more of a myth because that person refuses to release source code or details, but then again that is probably a sane decision. Still, I would be willing to believe that someone would do that just because they themselves feel irritated by the DRM.
Add a bit of youthful rakishness and someone might then upload the result to bittorrent, just because they can and don't care, i.e. "for the lulz".
I don't side with them. In the grand scheme of things they did open my eyes to the terrible IR processes of a much hyped company (okta), and they exposed how poor their product is/was. Security companies should be held to a higher standard when discussing breaches and IR. okta very much deserved it (and so does microsoft a 1000x). I don't endorse it but I can't hide my Schadenfreude either.
Tillie had TERRIBLE opsec from day one tho. Everyone knew her real name and face. I once mentioned this in the group chat and she promptly tweeted a selfie saying "don't have opsec like me".
Considering this, it lastes pretty long actually.
Disclaimer: I was in no way involved and publicly stated my disapproval in the deletescape Chats. It was however a thrill to see these things go down. Although it is equally as sad how this young lady threw away a lot of future potential for her ideals, without making any significant changes imo
They seem to be someone who is clearly inexperienced and support "hacker ethos" and don't really know what they want. They started talking about "demanding" code under open source licenses and stuff like that....
I think they are just some young hackers that started punching above their weight, and something will happen to them sooner or later. But let's see
Which is not a judgment on whether LAPSUS$ is doing genuinely bad stuff—I don’t know—only to say that, when computers are involved, “criminal” not only doesn’t make a good consensus point on avoiding a slippery slope into overall badness, it doesn’t even seem to make a good heuristic on whether something is bad or not.
[1] https://jvns.ca/blog/2022/03/10/how-to-use-undocumented-web-...
More specifically hacking under US law is;
Californian law for example:
1. Knowingly accesses and without permission alters, damages, deletes, destroys, or otherwise uses any data or computer system to:
2. Execute a scheme to defraud or extort a victim.
3. Wrongfully control or obtain money, property or data.
4. Knowingly accesses and without permission takes, copies, or makes use of any data from a computer or takes or copies supporting documentation.
5. Knowingly introduces any contaminant or virus into any computer system.
6. Knowingly and without permission uses the Internet domain name or profile of another individual, corporation, or entity in connection with the sending of electronic messages that damage a computer system.
7. Knowingly and without permission disrupts or causes the denial of governmental computer services.
8. Knowingly and without permission disrupts or causes the denial of public safety infrastructure computer services.
US Federal Law:
Knowingly accessing a computer without authorization to obtain:
Financial information
Information from a governmental department or agency
Information from any protected computer with the intent to defraud
Knowingly causing the transmission of a program, information, or code from a protected computer
Knowingly accessing a protected computer and causing damage and loss to that computer
Source: https://www.ncsl.org/research/telecommunications-and-informa...
I don’t know whether or not these folks are inexperienced, but it’s hard to overstate how truly bad software is, these days. Many software developers are inexperienced, and the entire industry is built like a house of cards.
The bar is very, very low, and over reliance on dependencies seems to be something that programmers actually boast about. Another point of pride seems to be deliberately ignoring experience and a careful approach (“Move fast and break things”).
But there’s certainly good money in being a security consultant. Lots of low-hanging fruit. That industry is growing like a weed.
Despite that, I feel like Web designers are a bit more disciplined, these days, than the days of yore. It may be because the industry has matured, and there's now a prevalence of knowledge on the matter (as well as a lot of tools and frameworks that are actually pretty good).
The actual software behind them, that said tools and frameworks connect to, on the other hand...
I think things kinda balance out.
Correct me if I’m wrong but do their attacks actually involve significant skill?
Their offer of buying credentials/access from employees suggests their bank account might ultimately be bigger than their skills and they’re leveraging that approach.
Of course, the question is, where is that money coming from and whether anyone is bankrolling them, and if so, what their motives are.
Wild speculation here, but if they are located in a country that is recently a lot less friendly with the west, maybe they decided that being overt isn't a real problem given what they are doing is de facto legal where they live. Being a Belarusian or Russian cybercriminal targeting the west is probably less risky now than ever before (and it wasn't especially problematic before.)
find a group of enthusiasts that are not quite there yet, such as an enclave of SKitties. give them superpowers, feed the hunger for recognition, silently run support operations, grease things up with cash so it feeds the illusion, in short troll them into thinking they are leet. let them be noticed, and create a fog of war.
step two
now that the show is on start actually infiltrating your hacks in position for a major attack. let your SKitties be the fall guys.
when its done cooking,it smells like state sponsored espionage.
LAPSUS$ grabs the headlines, sows chaos, keeps security teams fighting fires. Meanwhile the truly important attacks proceed with great stealth.
That doesn't leave very many actors capable or willing to do this.
They also use Brazilian slang, which granted could just be disinfo to throw people off.
There might well be something that, say, some US interests want and Brazilian entities are not willing to share. Enter a bit of XXI century spycraft, and everyone is happy.
This said, it seems a bit too exposed to be an intelligence op, even as diversion. Even if misdirecting, it is raising alarms and improving the security posture of the affected organisations afterwards, which you typically wouldn't want as a spook. You want to put down invisible roots, to let everyone sleep soundly while you go about your business undetected.
To me this looks like an average gang with slightly above-average tech skills, drunk on their own success - with a mindset to "get rich, or die trying".
Even in the late 1990s, the public learned the FVEY countries had explicit agreements to not spy on each others' governments. Anyone paying attention knew that meant that the US probably considered all non-FVEY governments fair game. Germany might feign surprise, but German counterintelligence knew there was a club, and they weren't in it.
In the early 2000s, I was contracted out to write (unclassified) network simulations for a US defense contractor. I was using a library written by a colleague contracted out to a French defense contractor. I found an apparent bug in poorly commented code (treating unexpected error codes as successes). My client instructed me that I could talk to my French colleague over the phone and verify that it really was a bug, but if the colleague asked, I couldn't tell him what the code was being used for (apart from general network simulation). Furthermore, if my colleague asked a second time what the library was being used for, I was to (1) assume he was working for French intelligence,(2) hang up immediately, and (3) report the incident to my client. My French colleague was experienced and smart enough not ask the forbidden question. I was smart enough not to ask him about the purpose for which he originally wrote the library. We both knew the rules. Nobody paying attention is surprised that even close allies routinely spy on each other.
Ask yourself the solve rate on most serious crime on the US.
While the SEC has “algorithms” to look for insider trading, it’s most relying on folks with bad OPSEC bragging and getting turned in by bitter third-parties.
Source: worked for Thesys / Thesys CAT group before our fucktard brass lost us the contract.
"58 members of Congress have violated a law designed to stop insider trading and prevent conflicts-of-interest"
https://www.businessinsider.com/congress-stock-act-violation...
"Threat Landscape and Good Practice Guide for Internet Infrastructure"
[PDF]: https://www.enisa.europa.eu/topics/threat-risk-management/th...
"How Google Stops Sharks From Eating Undersea Cables":
https://www.forbes.com/sites/amitchowdhry/2014/08/15/how-goo...