Russian cyber-spies changed tactics after the UK and US outed their techniques – so here's a list of those changes
- Reference: 1620413350
- News link: https://www.theregister.co.uk/2021/05/07/ncsc_russia_vulns_smart_cities_china_warning/
- Source link:
Now, the UK's National Cyber Security Centre (NCSC) and the US warn, the SVR is busy exploiting a dozen critical-rated vulns (including RCEs) in equipment ranging from Cisco routers through to VMware virtualization kit – and the well-known Pulse Secure VPN flaw, among others.
"In one example identified by the NCSC, the actor had searched for authentication credentials in mailboxes, including passwords and PKI keys," warned the GCHQ offshoot today.
[1]
[2]
[3]
Roughly equivalent to MI6 mixed with GCHQ, the SVR is Russia's foreign intelligence service and is known to infosec pros as APT29. A couple of weeks ago, Britain and the US [4]joined forces to out the SVR's Tactics, Techniques and Procedures (TTPs) , giving the world's infosec defenders a chance to look out for the state-backed hackers' fingerprints on their networked infrastructure.
"SVR cyber operators appear to have reacted to this report by changing their TTPs in an attempt to avoid further detection and remediation efforts by network defenders," said the poker-faced NCSC today, in an advisory detailing precisely what those changed TTPs are.
They include:
[5]A severe hole in Pulse Secure's Zero Trust Remote Access VPN software ;
An [6]arbitrary code execution vuln in F5 BIG-IP app delivery controllers ;
[7]An exploitable flaw in the Cisco RV320 WAN router (live code for the exploit exists in the wild);
A critical vuln in [8]Citrix (Netscaler) ADC load-balancers (publicly disclosed, ironically, by [9]now-US-sanctioned Positive Technologies );
A [10]critical RCE vuln in VMware's HTML5 client for its vSphere hybrid cloud suite ; and
An [11]exploitable hole in Oracle's WebLogic Server permitting remote code execution
On top of all that the SVR is also posing as legitimate red-team pentesters: looking for easy camouflage, the spies hopped onto GitHub and downloaded the free open-source Sliver red-teaming platform, in what the NCSC described as "an attempt to maintain their accesses."
There are more vulns being abused by the Russians and the full NCSC advisory on what these are can be [12]read on the NCSC website . The advisory includes YARA and Snort rules.
The self-preservation society
Separately, the NCSC issued a blog post this morning warning public sector operators of [13]smart city infrastructure to be wary of unnamed hostile foreign countries using these installations to steal data and more.
Comparing the risks to The Italian Job , NCSC chief techie Ian Levy wrote: "As part of an elaborate heist, a dodgy computer professor (played by Benny Hill) switches magnetic storage tapes for the Turin traffic control to create a gridlock."
[14]
Drawing on this, the NCSC has published a set of " [15]connected places cyber security principles " for operators of public spaces with connectivity kit and sensors in them.
Why the sudden focus on smart streetlights and all the rest of it? Though the NCSC wouldn't be drawn, a clue lies in El Reg 's inbox. For the past few years Huawei has been one of the most aggressively marketed smart city vendors. The Chinese company's [16]website boasts of its "smart city solution service", which consists of covering your dumb pavements and stupid trees in sensors that may or may not be remotely accessible by Beijing.
More prosaically, the risk in smart cities is the direct control of operational technology; industrial equipment such as CCTV, streetlights and access control systems. We understand at least one UK council is removing some smart city gear after having had a think about the wisdom of installing it. ®
Get our [17]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJW4eCvgY4lOY3CpjTbpZgAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJW4eCvgY4lOY3CpjTbpZgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJW4eCvgY4lOY3CpjTbpZgAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/04/27/apt29_russia_svr_tactics_cisa/
[5] https://www.theregister.com/2020/01/07/pulse_secure_attacks/
[6] https://www.theregister.com/2020/07/03/f5_critical_flaws_big_ip/
[7] https://www.theregister.com/2019/01/26/security_roundup_250119/
[8] https://www.theregister.com/2019/12/23/patch_now_published_citrix_applications_leave_network_vulnerable_to_unauthorised_access/
[9] https://www.theregister.com/2021/04/16/positive_technologies_us_sanctions_groundless/
[10] https://www.theregister.com/2021/02/23/vmware_vsphere_critical_bugs/
[11] https://www.theregister.com/2020/11/03/oracle_weblogic_server_rce_patch/
[12] https://www.ncsc.gov.uk/news/joint-advisory-further-ttps-associated-with-svr-cyber-actors
[13] https://www.theregister.com/2017/09/07/smart_cities_are_surveillance_cities/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJW4eCvgY4lOY3CpjTbpZgAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://www.ncsc.gov.uk/collection/connected-places-security-principles
[16] https://e.huawei.com/uk/services/industry-consulting-and-application-integration/smart-city
[17] https://whitepapers.theregister.com/
Covert pen testers
"... the SVR is also posing as legitimate red-team pentesters ..."
On one bid, the HMG Agency client insisted (and I mean insisted) that their IT people should have the right to conduct unannounced technical security testing on the supplier's network management system (which was used to support other clients) including DoS attacks.
I refused point blank. I pointed out that this would provide an attack vector for a subverted IT person in their team to probe defences. If caught (s)he would claim it was an unannounced pen test, and still gain valuable information. I further pointed out that if while monitoring their network, it appeared to be under attack from something like, Melissa, or 'The Love Bug', the appropriate action to protect the network might just be to turn it all off, without notice. And whilst the sales team really wanted to comply with the client's repeated insistence on this (they were motivated by a 'win bonus', I think), they were somewhat unwilling to insert a contract clause that the client would indemnify us, the supplier, against any adverse effects the client's 'unannounced technical security testing' had on their own and other clients' networks supported from the same service desk. The sales team were similarly unwilling to inform other existing clients that their service desk would suddenly be contractually attackable by a new client (probably without compensation).
Other issues, of course, include whether we could have obtained relief from SLAs had there been an attack by them, and the service had fallen below required levels, if we couldn't prove it was the client, rather than a failing on our part. And of course, selling a service one client has the contractual right to attack without notice to other clients would be an 'interesting' legal challenge.
Eventually, after much effort, I did get my way (the clause giving them unannounced pen testing rights was deleted). But of all the BONE-HEADED, IDIOTIC and DOWNRIGHT STUPID things to ask for, this one has got to take the biscuit, in my experience. I don't think any of them worked for the SVR, or whatever they were calling themselves then, but it would have made sense.
Anyone beat that?
"D'oh" icon for idiocy, I wanted to include the explosion and the FAIL icons too, but you're only allowed one per post, it seems :o(
I've said this for three decades now - connecting any utility or related infrastructure to the general publicly accessible internet is always a (very stupid) mistake and should be regulated against.
Russia was probing connected oil refineries and traffic systems in the 1980's and I can imagine since then so have plenty of bored teenagers.