News: 1610434568

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Kaspersky Lab autopsies evidence on SolarWinds hack

(2021/01/12)


Kaspersky Lab reckons the SolarWinds hackers may have hailed from the Turla malware group, itself linked to Russia’s FSB security service.

Referring to the hidden backdoor secretly implanted in SolarWinds' Orion product, Kaspersky’s Georgy Kucherin wrote in a [1]blog post on Monday: “While looking at the Sunburst backdoor, we discovered several features that overlap with a previously identified backdoor known as Kazuar.”

[2]

Kaspersky, itself a Russian company, linked that Kazuar remote-access hole (a .NET nasty) with previous research by Palo Alto Networks which attributed it to the Russian state-sponsored Turla crew, who were last spotted [3]targeting the Armenian government and [4]Austria ’s Foreign Office.

“While Kazuar and Sunburst may be related, the nature of this relation is still not clear,” summarised Kaspersky. "Through further analysis, it is possible that evidence confirming one or several of these points might arise. At the same time, it is also possible that the Sunburst developers were really good at their opsec and didn’t make any mistakes, with this link being an elaborate false flag."

Ah, right on time: Hacker-slammed SolarWinds sued by angry shareholders [5]READ MORE

Palo Alto’s Unit 42 research division published its findings on Turla [6]last summer , stating: “We suspect the Kazuar tool may be linked to the Turla threat actor group (also known as Uroburos and Snake), who have been reported to have compromised embassies, defense contractors, educational institutions, and research organizations across the globe.”

Taking these two snippets together, they suggest an even stronger link between the Russian state and the hackers who successfully compromised SolarWinds. The firm has taken the problem seriously, [7]hiring a consultancy run by US infosec veterans Chris Krebs (former chief of the Cybersecurity and Infrastructure Agency) and Alex Stamos, whose CV includes stints at Yahoo ! and Facebook.

“This has been a multiyear effort by one of the very best, the most sophisticated intelligence operations in the world," Krebs told the Financial Times.

The SolarWinds compromise [8]came to public attention in December 2020 after infosec behemoth FireEye, a SolarWinds customer, admitted its systems were unlawfully accessed in “a state-sponsored attack.” ®

[9]

Meanwhile... CrowdStrike has [10]detailed how it reckons Orion was infected with a hidden backdoor: a source file was automatically swapped at the right moment when the software was being built on a build server compromised by highly customized malware.

Get our [11]Tech Resources



[1] https://securelist.com/sunburst-backdoor-kazuar/99981/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x250%7C300x252%7C300x600&tile=3&c=33X-2BRprlo3FFki61MKiSigAAAIE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2020/03/12/eset_spots_turla_hackers/

[4] https://www.theregister.com/2020/02/14/austria_foreign_ministry_hack_turla_group_allegs/

[5] https://www.theregister.com/2021/01/05/solarwinds_sued/

[6] https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/

[7] https://www.theregister.com/2021/01/11/security_in_brief/

[8] https://www.theregister.com/2020/12/09/fireeye_tools_hacked/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x100%7C300x250%7C300x251&tile=4&c=44X-2BRprlo3FFki61MKiSigAAAIE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.crowdstrike.com/blog/sunspot-malware-technical-analysis/

[11] https://whitepapers.theregister.com/

That's poking the bear in the eye

chivo243

That's a gutsy thing to do. Was it smart jump on the bandwagon and toot the horn? Maybe a middle of the road tactic would have to been say when asked, "It was most likely them, but don't quote us on it."

Re: That's poking the bear in the eye

Anonymous Coward

The Blogpost does say....

"TLDR; just tell us who’s behind the SolarWinds supply chain attack?

Honestly, we don’t know. What we found so far is a couple of code similarities between Sunburst and a malware discovered in 2017, called Kazuar. "

So that should avoid falling from a 5th story balcony or dying from tea poisoning.

(On a serious note, its a pretty interesting piece of technical analysis!)

Re: That's poking the bear in the eye

Anonymous Coward

Kaspersky has been moving itself away (operationally, etc.) from under the shadow of the home country. (to Schweiz?) Consider that they might be now feeling confident they could survive as a company despite backlash. Consider also they might be trying to provoke a backlash, in order to demonstrate effective independence. After all, only a demonstrated autonomy will allow them to continue to sell their products.

Full disclosure: I use their anti-virus product as it is the only one that hasn't betrayed me. Your opinion on my possible futures may be wildly different than mine. But consider we're all test cases and pause your smiling...

Re: That's poking the bear in the eye

osakajin

Interesting if they are building trust in this way like an undercover cop doing dirty business to integrate to the gang...

Mind games?

Invisibles

jgarbo

Cracking 101: Successful penetration must be invisible. No log changes, all timestamps correct(ed), clean as a ghost's whistle. If these "hackers" left traces they weren't Russian state actors. Let's instead look for underpaid CIA interns or drunk NSA contractors.

Re: Let's instead look for underpaid CIA interns or drunk NSA contractors.

Anonymous Coward

I couldn't agree more. Russian are *never* underpaid or drunk :-)

Re: Let's instead look for underpaid CIA interns or drunk NSA contractors.

seven of five

I am unconvinced about them being able to get drunk. They (unfair generalisation, I know) do stop drinking, usually when they are dead.

Otoh, sometime one falls over and sleeps a bit, but resumes drinking as soon as he wakes up.

I'm not sure either counts as "getting dunk".

Re: Let's instead look for underpaid CIA interns or drunk NSA contractors.

slimshady76

I'm not sure either counts as "getting dunk".

I think this act equals "stop being breastfeed" in the Motherland.

What is going on

GordonD

First possibility: Just what it looks like, FSB hacking the world, Kaspersky calling them on it. Plausible ( and gutsy by Kaspersky).

Second Possibility: FSB hacking the world, Kaspersky arm of Russian state, Tramp administration correctly points finger at Kaspersky, Russian state, knowing the FSB operation will be identified shortly, uses Kaspersky to out itself, making Kaspersky look good, and Tramp administration bad. Plausible until you consider the Tramp administration doing something right.

Third Possibility: FSB hacks world; knowing that it won't stay secret forever, Russia lines up Kaspersky to out themselves. They then tell their komprimised lackey (who they know will soon be no longer a useful idiot, just an idiot) to accuse Kaspersky of working for Russia, so that they can later discredit the NSA et al.

I think it is one, but three would make a better spy novel, and also fits the facts.

If I knew what brand [of whiskey] he drinks, I would send a barrel or
so to my other generals.
-- Abraham Lincoln, on General Grant