The perils of non-disclosure? China 'cloned and used' NSA zero-day exploit for years before it was made public
- Reference: 1614041423
- News link: https://www.theregister.co.uk/2021/02/23/microsoft_chinese_nsa/
- Source link:
Check Point put out a [1]report on Monday digging into Chinese malware it calls Jian, and argues persuasively this particular software nasty was spawned sometime around 2014 from NSA exploit code that eventually [2]leaked online in 2017.
[3]
The timeline basically seems to be, according to Check Point:
2013: NSA's Equation Group developed a set of exploits including one called EpMe that elevates one's privileges on a vulnerable Windows system to system-administrator level, granting full control. This allows someone with a foothold on a machine to commandeer the whole box.
2014-2015: China's hacking team code-named APT31, aka Zirconium, developed Jian by, one way or another, cloning EpMe.
Early 2017: The Equation Group's tools were teased and then leaked online by a team calling itself the Shadow Brokers. Around that time, Microsoft [4]cancelled its February Patch Tuesday, identified the vulnerability exploited by EpMe (CVE-2017-0005), and [5]fixed it in a bumper March update. Interestingly enough, Lockheed Martin was credited as alerting Microsoft to the flaw, suggesting it was perhaps used against an American target.
Mid 2017: Microsoft quietly fixed the vulnerability exploited by the leaked EpMo exploit.
[6]
It could be that Beijing obtained a copy of Equation Group's EpMe, or observed it being used and recreated it, and used it while the hole in Microsoft's Windows remained unfixed. Or the Chinese could have found the same bug within the OS. Check Point reckons the code was lifted rather than a coincidence:
Our research started by analyzing “Jian”, the Chinese (APT31 / Zirconium) exploit for CVE-2017-0005, which was reported by Lockheed Martin’s Computer Incident Response Team. To our surprise, we found out that this APT31 exploit was in fact a reconstructed version of an Equation Group exploit, dubbed “EpMe”. This means that a Chinese-affiliated group used an Equation Group exploit possibly against American targets.
The case of “EpMe” / “Jian” is unique, as we have evidence that “Jian” was constructed from the actual sample of the Equation Group exploit. Having dated the APT31’s samples to 3 years prior to the Shadow Broker’s leak, our hypothesis is that these Equation Group exploit samples could have been acquired by the Chinese APT in one of the following ways: Captured during an Equation Group network operation on a Chinese target; Captured during an Equation Group operation on a 3rd-party network which was also monitored by the Chinese APT; Captured by the Chinese APT during an attack on Equation Group infrastructure.
The full sleuthing is outlined in an [7]extensive technical report , and again raises the question over whether it is in the US intelligence community’s best interests to share the details of any exploitable vulnerabilities they find – rather than try to keep them a secret and use them themselves – because, ultimately the tools will leak (or the bugs be discovered by others) and expose US businesses and institutions to hacking attempts.
More damage
The Shadow Brokers were also responsible for leaking [8]the Eternal series of exploits that were later used to spread software nasties, such as the Wannacry ransomware and NotPetya malware.
The Zirconium hacking crew, meanwhile, was accused of [9]menacing candidates in America's 2020 elections. It also opens the possibility that the nightmare hack of US government departments and Fortune 500 companies [10]through SolarWinds networking software was the result of US-government developed exploits that had been directed back at the US.
The security researchers note that society still has an illogical perspective on cybersecurity. “What would you say if we told you that a foreign group managed to steal an American nuclear submarine? That would definitely be a bad thing, and would quickly reach every headline,” they note. “However, for cyber weapons – although their impact could be just as devastating – it’s usually a different story.”
[11]
They go on: “Cyber weapons are digital and volatile by nature. Stealing them and transferring from one continent to another, can be as simple as sending an email. They are also very obscure, and their mere existence is a closely guarded secret. That is exactly why, as opposed to a nuclear submarine, stealing a cyber-weapon can easily go under the radar and become a fact known only to a selected few.” ®
Get our [12]Tech Resources
[1] https://blog.checkpoint.com/2021/02/22/jian-the-chinese-double-edged-cyber-sword/
[2] https://www.theregister.com/2017/04/14/latest_shadow_brokers_data_dump/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDSL7KErvEW6mhDpfr8@xgAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2017/02/14/microsoft_patch_tuesday_delayed/
[5] https://www.theregister.com/2017/03/15/microsoft_massive_patch_tuesday_bundle/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDSL7KErvEW6mhDpfr8@xgAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://research.checkpoint.com/2021/the-story-of-jian/
[8] https://www.theregister.com/2017/04/14/latest_shadow_brokers_data_dump/
[9] https://www.theregister.com/2020/09/11/microsoft_us_election_security_assessment/
[10] https://www.theregister.com/2021/01/19/fireeye_solarwinds_code/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDSL7KErvEW6mhDpfr8@xgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: Stealing?
Nobody really "steals third base" either, but that's what it is called in competitive baseball.
"I have no doubt that the NSA knew of the Chinese use of their exploit long before ..." --- congratulations on your supernatural powers. It takes a man to understand his own feelings.
"Meanwhile, companies and organizations were put in peril because of the lack of disclosure." --- Spot on! You finally connected and scored a century!!.
failure to take long view
Another symptom of the intellectual decline of the ruins of Western culture. A near total inability in the manglement level to consider longer term consequences of anything. Even more astonishing because of the ephemeral nature ( by historical standards) of software. One wonders how much Britain lost by keeping its WW2 computing skills secret so they could read other countries private communications. Not sure they gained much from it. If computing had been encouraged they might have kept a lead in something a little longer.
Re: failure to take long view
> Not sure they gained much from it
Depends on the "they", if you mean politicians/generals who became heroes because of their brilliant strategies over the hun, rather than being able to read their mail = quite a lot
Stealing?
The ending comments are wrong and disingenuous.
It's not stealing. If the Chinese Navy stole a US submarine, then the US Navy could no longer use it and they would be upset.
It's copying. I have no doubt that the NSA knew of the Chinese use of their exploit long before the the Shadow Brokers' leak. They didn't say anything because they were still using the exploit themselves.
Meanwhile, companies and organizations were put in peril because of the lack of disclosure.