Hackers claim vast access to Western Digital systems
techcrunch.com
techcrunch.com
What mystifies me about ransomware attacks is how many targets don't notice that vast quantities of data are being systematically exfiltrated. I can see how it might be particularly difficult for a cloud provider (assuming the hackers didn't pull it all through a single set of credentials), but for many targets, any sort of unfamiliar outgoing data stream larger than a gigabyte ought to be suspicious.
It is really not, though. Unless they take it very slowly and to locations that are not suspicious. Even something like GuardDuty on AWS will flag 'interesting' traffic to new locations.
They are not necessarily so. Plenty of times the hackers just pretend they have a copy when in fact they don't. Also encryption 'in place' or overwriting data with noise doesn't do much other than a bunch of IO without any network traffic besides the initial commands.
Here's the site, although there's nothing relevant to this stuff on there yet:
Guidepointsecurity.com/blog
how many people do you know that is constantly monitoring their outbound traffic? hell, how many people do you know that even know what that means?
edit: do you mean corporate targets? if so, yeah, i'd expect a competent IT department to be monitoring that kind of activity. i was coming from the home user suffering the malware
I will push it even one step further. I knew in an abstract and it was still not until I saw pihole visualizations that I changed my mind about a lot of things. It is one thing to know, but it is quite another to see it with your own peepers. It is a shame, because it means I might be not processing things fully when I consider them in an abstract.
I think up-thread is talking about known-internal IP doing loads of traffic to new-untrusted IP which would indicate exfiltration.
Network-layer security devices are pretty useless in 2023. Everything is encrypted and everything talks to everything else as part of “normal” operations.
What is your understanding of ransomware? The point isn't to exfiltrate every byte of data, it's to encrypt it in-place (sabotage, not theft).
Is some data exfiltrated in some cases? Sure. I'd argue those are espionage cases masquerading as ransomware, and your question holds. But by design ransomware is supposed to fly under the radar.
What evidence do you have for this? Not being snarky, as I have a whole bunch of WD drives.
Please do tell. Thanks!
That's a strong statement, unsupported by, well, anything.
Not saying it isn't true -- and if it is, I want to know about it -- as it puts my systems at risk.
2017 https://www.bleepingcomputer.com/news/security/owners-of-wdt...
2017 https://blog.exploitee.rs/2017/hacking_wd_mycloud/
2018 https://www.theregister.co.uk/2018/01/08/wd_mycloud_nas_back... https://www.bitdefender.com/blog/hotforsecurity/researcher-f... https://www.techpowerup.com/240306/western-digital-ships-som...
"However, since more than 6 months have passed with no patch or solution having been deployed, the researchers disclosed and published the vulnerability, which should (should) finally prompt WD to action on fixing the issue."
That's not very flattering, and if I used any of those products/software features (I have only bare, internal SAS drives, both spinning rust and SSD) I'd be really concerned.
Since I only use bare internal drives, I imagine I'm not at risk (although, I've had one or more of these drives for at least 7 or 8 years -- so if I was at risk, you'd think that would have happened already) from the vulnerabilities noted in the links you provided.
But I'll do some research (although I do try to keep track of such things and never heard anything about actual drive firmware -- rather than the NAS/cloud products -- being compromised.) anyway.
Thanks again for compiling these links and sharing them. Much appreciated!
I only know of this "My Cloud" service which appears to be somehow linked to some NAS-like HDD offerings they have. I never really read about it because it is irrelevant to me, so I don't know if they also mirror the data in the cloud, or if the cloud gives the attacker remote access to these NAS disks and that they exfiltrated data this way, or something else.
Probably a lot based on the 10 terabyte number... and the SAP Backoffice... and that it took 5 days for them to come back up
Ah, the SAP Backoffice, the magical land where businesses store their most treasured data, and where hackers drool over the potential loot. The SAP Backoffice system is a complex beast, made up of several components, such as:
ERP (Enterprise Resource Planning) - The backbone of the operation, keeping track of everything from finances to supply chain management. CRM (Customer Relationship Management) - The digital black book of customer interactions, preferences, and sales opportunities. SRM (Supplier Relationship Management) - The hub that orchestrates the delicate dance between a business and its suppliers. HCM (Human Capital Management) - The watchful eye over the company's most valuable asset: its people. PLM (Product Lifecycle Management) - The puppet master pulling the strings of a product's journey from inception to obsolescence. SCM (Supply Chain Management) - The maestro conducting the symphony of goods flowing from supplier to customer. BI (Business Intelligence) - The all-knowing oracle that uncovers hidden insights from the vast sea of data.
The data is not "in the cloud" per se, but the credentials and login portal are.
That Bing CMS bug was only exploited by the researchers who disclosed it to MS.
Given that in many cases they are more skilled than the actual cybersec folks in those companies, they should charge a fee to monitor their systems.
There's prior art for that business model. I'm told it was popular in Italy many years ago.
I would assume that 10TB of hacked data will not fit a 10TB Western Digital hard drive.
This weirdly hilarious. Though I wonder how could you even handle such a negotiation, from WD's side?
Still highly likely that they'd be able to talk this rate down to something well below the 8 figures they're demanding.
Edit: Seems like the downvotes made me hit my rate limit of HN comments. Can't reply to any more comments; sorry. :(
Let the $mostly_defunct_state die off with the rest of them without succumbing to their playbook.
Do you think that worked with China?
Fearmongering and doomer attitudes drive clicks for news publishers. Clicks drive money. Money drives their growth and influence. Which, in turn, drives more clicks.
And guess who is thrashing around in their desperate attempts to stop bleeding influence and money in the internet age? Traditional news media.
Not that difficult to see some clear examples of that either, like the recent bills in some countries trying to extort FB and Google to pay money for every news article shared on their platforms (for google it was in the form of the preview snippets, for fb it was in the form of users sharing links iirc).
Russia doesn't have anything remotely like the global propaganda apparatus based in Washington. They do a lot of propaganda, sure, but they are small fries in comparison. They are investing in changing that, however.
To be fair, most outlets never quite took the time to go back and admit they were spewing political oppo-fiction for years.
Also, not to get into a debate on the stale issue, but hypertargetted ad buys (Cambridge Analytica) in key districts can swing elections when they are decided by tens of thousands of votes in those districts. I find it endlessly fascinating that Putin et al understood our election system better than us. I guess he didn't have the luxury of motivated reasoning and reality distortion fields.
I think you’ve been brainwashed on this one. Local campaigns spend orders of magnitude more money and are run by extremely capable social media strategists. The IRA struggled with proper English grammar and mis-targeted their ads to staunch Republicans.
It was by all actual evidence an extremely shoddy effort run on a shoestring budget that made no difference at all.
Which when you look at the general competency level of Russia these days, I guess it’s par for the course.
For me the big takeaway isn’t arguing about political bygones. It’s that by and large, these boogeymen are entirely incompetent at what they purport to do, and don’t deserve a fraction of the hand-wringing that they seem to elicit.
They are hyped up boogeymen for political purposes. The reality is that they are poorly trained, underfunded, and entirely corrupt, and so the results of their efforts are predictably lame.
That’s exactly the BS that was peddled back in the day that people like the NYT happily took home Pulitzers for, but where it turned out they spun it nearly out of whole cloth.
Actual research [1a] into the effect of such a meager ad buy showed not only were staunchly Republican voters the ones who predominantly saw the ads, but unsurprisingly it had no effect on their voting.
Looking back, it’s fair to say that on the order of 0-100 votes may have been changed by this “meddling”, for which the nation was subjected to years of breathless left-wing coverage.
It was, in short, a sham story and it’s well past time to be still be carrying water for such thoroughly debunked propaganda.
[1] - https://www.scribd.com/document/618991728/Nature-Article-on-...
And when it comes to propaganda, it's good to remember that the US didn't win the cold war because it had a better propaganda machine. It won, because it had more substance behind the propaganda. As a kid in the 80s, I was exposed to blatant propaganda from both sides. The USSR fell, and I was left with an instinctive dislike to anything that suggests that America is somehow special. But I've never had any doubt of which side I would choose if I had to, because substance is ultimately more important than propaganda.
How can you be so sure? Western propaganda was and is extremely potent since the Cold War. The West had Solzhenitsyn, rock stars and Hollywood, NYT to BBC, the cultural amplitude was unstoppable.
Meanwhile, USA was abandoning the gold standard and had leaders getting assassinated and embarking on insanely murderous wars of choice in Vietnam, Cambodia and Laos. What substance? Propaganda effectiveness is the main differentiator.
I'm from Finland, which was the USSR's favorite capitalist country. I went to the only school where everyone took Russian as the first foreign language. The Soviets had plenty of reasons to show us their best side, and they sure did try. We did school trips to the USSR before it fell, but as middle class kids, we could also travel around the West.
The thing is, no matter what imperialistic BS the Soviets and the Americans did, the Americans at least had the reality on their side. It was the little things that revealed it. Little things such as which countries had very favorable black market exchange rates for the currencies of the other side. Or where you could make money by smuggling everyday goods.
Putin is just the Russian leader who happens to be around when the fruits of those labours are paying off.
---
Various actors in the west have been manipulating narratives for decades. There are literally companies that provide astroturfing services to fossil fuel intetests and others.
But suddently people discover Russia is getting in on the action too, now its cause for panic?
Yes, an adversary working against American and democratic interests is a cause for concern over and above the typical American and western profit-seekers.
And someone had an expectation that adversaries will not take advantage of it?
Is it that impossible for you to imagine that someone could be extremely apalled by the invasion of Ukraine and be fully in support of their side (i.e., being fully opposed to the Russian side), while at the same time standing for the principles of open internet and not believing in wholesale disconnecting entire countries?
Because that's my personal stance. I am fully on the side of Ukraine here, with no "ifs" or "buts", and I simultaneously don't believe in blackholing tens of millions of people like that being a good idea.
If MEGA is used repeatedly and almost exclusively by threat actors as an exfiltration point, and is unwilling to address legitimate concerns about their use across the web, why shouldn't every who isn't interested in using MEGA just block any connections to or from the service?
I was able to get around this is by changing the login POST to use nvidia.com and everything worked just fine, and the ping to .com was obviously faster.
It is lightyears beyond dumb that this is even legal in the USA.
Would love to be talked down from this with a rational explanation.
NOTE: This happened in 2021
When it failed I opened devtools and saw the .cn attempt.
Portscans and SSH bruteforcing are not necessarily the problem, but they can be preludes to a problem.
In another application I got rid of 90% of the flash wear on an IoT device by blocking a single country from a port.
A determined, targeted attack will go around a geoblock, but I have to reluctantly admit that it can be useful for the high volume attacks.
It's not $country's fault that you don't use vpn or port knocking.
2) proxies exist, many of which are your "first world residential ip address" thanks to IoT in every toaster.
No, it is not okay that many US websites decided to block access from EU instead of adopting a normal privacy policy, it is equally not okay to block access from whole regions of the world based on your prejudice, there are much better solutions.
[1] https://dutchreview.com/news/tindependent-russian-news-chann...
I'm going to take this opportunity to shill gost, an amazing tool (https://github.com/go-gost/gost). Can someone tell me why Go is so popular in Chinese dev circles?
Obvious hyperbole and all, but just how much data is transmitted to accomplish a sophisticated nation-state level attack?
I’d believe a regular laptop is sufficient but not a lightbulb. Then again, if it’s only a matter of 100KB, then maybe a lightbulb makes sense.
Here is the english readme:
https://github.com/go-gost/gost/blob/master/README_en.md
... and here is a better page:
It seems to have a rich feature set ... can you elaborate on why you like this tool so much ?
information is and must continue to be a fundamental human right, and the internet is information. you basically doom an entire nation (or nations) to try to stop a small group of actors. this is the same thought process that has gotten the US into pointless wars and allowed awful law to be created all in the name of good.
making efforts to block the payment systems they use arguably is a more effective approach (which i am not recommending by any means, but if we want to be serious about this and lowering the reward for ransomware, crypto would be a far better target)