December 30, 2016

INFORMATION WANTS TO BE FREE:

'Grizzly Steppe': How Russia Hacked This Year's Presidential Election (Chris Strohm, December 30, 2016, Heat Street)

The initial hackers sent e-mails that appeared to come from legitimate websites and other Internet domains tied to U.S. organizations and educational institutions, according to the report. Those who were fooled into clicking on the "spearphishing" e-mails provided a foothold into the Democratic National Committee -- although the party organization wasn't identified by name in the report -- and key e-mail accounts for material that would later be leaked to damage Hillary Clinton in her losing campaign against Trump.

"This activity by Russian intelligence services is part of a decade-long campaign of cyber-enabled operations directed at the U.S. government and its citizens," according to a joint statement from the Federal Bureau of Investigation, DHS and the Office of the Director of National Intelligence. "The U.S. government seeks to arm network defenders with the tools they need to identify, detect and disrupt Russian malicious cyber activity that is targeting our country's and our allies' networks." [...]

In addition to providing evidence, the report was intended to embarrass and stymie the Russian government by making public its tactics, techniques and procedures, according to a U.S. official who asked not to be identified discussing internal deliberations.

Along with the report, the Homeland Security Department released an extensive list of Internet Protocol addresses, computer files, malware code and other "signatures" that it said the Russian hackers have used.

"These actors set up operational infrastructure to obfuscate their source infrastructure, host domains and malware for targeting organizations, establish command and control nodes, and harvest credentials and other valuable information from their targets," the report said.

The initial hackers worked for Russia's FSB, the successor to the Soviet Union's KGB. Once inside the DNC, the group dubbed "Advanced Persistent Threat 29" or "APT 29," used stolen credentials to expand its access to directories and other data, and made off with e-mail from several accounts through encrypted communication channels, according to the report.

Then, a second wave came in the spring of 2016. Hackers working for Russia's military intelligence service, the GRU, and dubbed "Advanced Persistent Threat 28" or APT 28, infiltrated the DNC's networks through more spearphishing e-mails, the report said.

"This time, the spearphishing e-mail tricked recipients into changing their passwords through a fake webmail domain hosted on APT 28 operational infrastructure," according to the report. "Using the harvested credentials, APT 28 was able to gain access and steal content, likely leading to the exfiltration of information from multiple senior party members. The U.S. government assesses that information was leaked to the press and publicly disclosed."

While the report doesn't name the DNC, U.S. officials and cybersecurity researchers have confirmed that it was a prime target of the Russian hackers.

"A great deal of analysis and forensic information related to Russian government activity has been published by a wide range of security companies," according to the statement from the FBI, DHS and DNI. "The U.S. government can confirm that the Russian government, including Russia's civilian and military intelligence services, conducted many of the activities generally described by a number of these security companies."

The singular lesson of the email and hacking kerfuffles is that Hillary and the DNC should have just publicly released everything.  None of the actual content did any harm.

Posted by at December 30, 2016 8:25 AM

  

« THERE'S NO SUCH THING AS UNEMPLOYMENT...: | Main | ...AND CHEAPER...: »