News: 1608508332

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Trump administration says Russia behind SolarWinds hack. Trump himself begs to differ

(2020/12/21)


United States secretary of state Mike Pompeo has laid the blame for the SolarWinds hack on Russia, but his boss begs to differ.

Pompeo on Friday gave an interview with pro-Trump conservative talk radio host Mark Levin, the [1]transcript of which was posted by the State Department.

During the interview Levin asked about the SolarWinds incident. Pompeo responded by saying: “I think it’s the case that now we can say pretty clearly that it was the Russians that engaged in this activity.”

President Donald Trump responded with the following Tweets that were his only substantial public commentary on an enemy nation’s likely penetration of many government agencies in the nation he leads.

....discussing the possibility that it may be China (it may!). There could also have been a hit on our ridiculous voting machines during the election, which is now obvious that I won big, making it an even more corrupted embarrassment for the USA. [2]@DNI_Ratcliffe [3]@SecPompeo — Donald J. Trump (@realDonaldTrump) [4]December 19, 2020

The Associated Press [5]reports that the White House was set to issue a Friday afternoon statement describing Russia as “the main actor” behind the incident, but that staff were told to stand down instead.

At the time of writing the State Department, National Security Agency, White House, Cybersecurity and Infrastructure Security Agency, and president Trump all appear not to have attempted to reconcile the administration’s conflicting view on the incident.

Russia [6]denies any involvement.

One new source of information is Microsoft, which has published a [7]post that says the poisoned SolarWinds downloads were digitally signed.

That factoid “suggests the attackers were able to access the company’s software development or distribution pipeline” and once they’d done so targeted a single .dll file called “SolarWinds.Orion.Core.BusinessLayer.dll”

“The attackers had to find a suitable place in this DLL component to insert their code,” wrote analysts from Microsoft’s 365 Defender Research Team and Threat Intelligence Center (MSTIC). “Ideally, they would choose a place in a method that gets invoked periodically, ensuring both execution and persistence, so that the malicious code is guaranteed to be always up and running. Such a suitable location turns out to be a method named RefreshInternal .

Trump says '400 pound hacker', not Russia, could be behind email hack [8]READ MORE

“The modification to this function is very lightweight and could be easily overlooked—all it does is to execute the method OrionImprovementBusinessLayer.Initialize within a parallel thread, so that the normal execution flow of RefreshInternal is not altered.

Among the jobs that RefreshInternal does as part of its legitimate business is accessing a class called CoreBusinessLayerPlugin initializes various other components and schedules the execution of several tasks. Among those tasks is loading a method named Start that loads the malicious code.

Once that code is up and running it runs a bunch of tests to make sure it is in an environment free of certain security software and is configured to communicate with certain expected IP addresses.

If a single hoped-for condition is not present, the backdoor bails “to avoid exposing the malicious functionality to unwanted environments, such as test networks or machines belonging to SolarWinds.” Otherwise, it gets to work giving its masters the ability to run, stop, and enumerate processes; read, write, and enumerate files and registry keys; collect and upload information about the device; and restart the device, wait, or exit.”

Microsoft says the hack allows attackers to “follow the standard playbook of privilege escalation exploration, credential theft, and lateral movement hunting for high-value accounts and assets.”

Cyber-security super-brain Rudy Giuliani forgets password, bricks iPhone, begs Apple Store staff for help [9]READ MORE

And as we [10]know , attackers have gained access to the US government departments of State, Treasury, Homeland Security, and Commerce – among 18,000 known victims. There’s plenty of high-value targets in that lot.

But we don’t know which were compromised, and secretary of state Pompeo suggested the US government may never reveal the extent of the hack.

“I can’t say much more as we’re still unpacking precisely what it is, and I’m sure some of it will remain classified,” he said in his interview with Levin. ®

Get our [11]Tech Resources



[1] https://www.state.gov/secretary-michael-r-pompeo-with-mark-levin-of-the-mark-levin-show/

[2] https://twitter.com/DNI_Ratcliffe?ref_src=twsrc%5Etfw

[3] https://twitter.com/SecPompeo?ref_src=twsrc%5Etfw

[4] https://twitter.com/realDonaldTrump/status/1340333619299147781?ref_src=twsrc%5Etfw

[5] https://apnews.com/article/donald-trump-politics-mark-levin-coronavirus-pandemic-hacking-6080f156125a4a46edef2a6dcf826611

[6] https://washington.mid.ru/en/press-centre/news/embassy_comment_/

[7] https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/

[8] https://www.theregister.com/2016/09/27/technology_in_first_presidential_debate/

[9] https://www.theregister.com/2019/10/31/giuliani_iphone_password/

[10] https://www.theregister.com/2020/12/18/solarwinds_nnsa_microsoft_cisa/

[11] https://whitepapers.theregister.com/

That tweet is real?

Peter Prof Fox

Not a parody? Not an impressionist? I've done my best to avoid the splutterings of Duck Turd so I seem to have missed a great thread of couldn'tmakeituptertainment.

ACL

Yes Me

Once that code is up and running it runs a bunch of tests to make sure it is in an environment free of certain security software and is configured to communicate with certain expected IP addresses. So there's an obvious way to defeat it, if you haven't already been backdoored, assuming you know those addresses. Just update the ACL in your border router.

I assume those addresses are known to be under Russian control.

P.S. There's a list of suspect addresses at https://raw.githubusercontent.com/ExtraHop/code-examples/main/sunburst/threats.json

P.P.S But maybe not so useful, since it includes e.g. Amazon Inc and Nokia address blocks.

Re:Domain killswitch

Palpy

FireEye identified a domain name which serves as a killswitch for the malware. I am unclear whether this is in fact checked by the initializing dll or whether this kills the malware in another stage of execution.

This from Krebs ( [1]https://krebsonsecurity.com/2020/12/malicious-domain-in-solarwinds-hack-turned-into-killswitch/ ):

"'SUNBURST is the malware that was distributed through SolarWinds software,' FireEye said in a statement shared with KrebsOnSecurity. 'As part of FireEye’s analysis of SUNBURST, we identified a killswitch that would prevent SUNBURST from continuing to operate.'”

[1] https://krebsonsecurity.com/2020/12/malicious-domain-in-solarwinds-hack-turned-into-killswitch/

Re: Re:Domain killswitch

Yes Me

That would be avsvmcloud dot com according to [1]this post , which also says that MS has seized it.

[1] https://www.sdxcentral.com/articles/news/solarwinds-attack-fallout-18k-customers-at-risk-extrahop-ids-550-suspicious-ip-addresses/2020/12/

Re: Re:Domain killswitch

Anonymous Coward

Unlikely to end with Sunburst though..... they'll have used that to install additional malware.

https://threatpost.com/sunburst-c2-secrets-rsolarwinds-victims/162426/

"Further exploitation by the unknown advanced persistent threat (APT) group, dubbed UNC2452 or DarkHalo by researchers, involves installing more malware, installing persistence mechanisms and exfiltrating data, according to Kaspersky."

I find it funny that they're quoting Kaspersky in that article. Have they forgotten Ruslan Stoyanov?, the Kaspersky FBI informant that was arrested 6 days after Trump got into power. Somehow the Russians got the names of informants 6 days after Trump got access to the unredacted Christopher Steele memos with all the informants names.

https://en.wikipedia.org/wiki/Ruslan_Stoyanov

https://www.dailykos.com/stories/2019/5/19/1857878/-Just-how-much-is-confirmed-from-the-Christopher-Steele-dossier

Mr Irrelevant Tweets what?

Winkypop

“An empty vessel makes the loudest sound, so they that have the least wit are the greatest babblers.”

― Plato

PS: And what does Vlad have on him?

six_tymes

all democrats always blame Russia for all hacking. they are blind as dirt.

Trump is alone

Anonymous Coward

No, even his Republican CIA chief, Mike Pompeo, says it's Russia (below). Everyone, even Bill Barr is ass covering right now, resigning early to duck blame or doing their jobs professionally, even Pompeo.

Trump calls for martial law and the Pentagon to run elections, but not the machines with the verifiable paper trail that Georgia uses, no sir, he wants to use the Texas ones without the audit trail! All the martial law scenarios have been run and mitigated. The army will not obey Michael Flynn and the courts will not obey Sidney Powell.

Bunker boy screams at his generals. 30 days left and he's desperate as fuck. It's a bit pathetic.

https://www.npr.org/2020/12/19/948318197/pompeo-russia-pretty-clearly-behind-massive-solarwinds-cyberattack

"On Friday, Secretary of State Mike Pompeo broke that silence, becoming the most prominent administration official to blame Russia for the attack. This was a very significant effort," Pompeo told the The Mark Levin Show, "and I think it's the case that now we can say pretty clearly that it was the Russians that engaged in this activity."

"I see little divinity about them or you. You talk to me of Christianity
when you are in the act of hanging your enemies. Was there ever such
blasphemous nonsense!"
-- Shaw, "The Devil's Disciple"