Attacks/Breaches
12/30/2014
01:15 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
100%
0%

Sony Hacked By N. Korea, Hacktivists, Ex-Employee, Or All Of The Above?

FBI gets briefed on ex-Sony employee's possible role in hack as questions remain about who did what and when in epic breach of the entertainment company.

Researchers at Norse Corp. who say an ex-Sony employee may have had a hand in the epic breach of the entertainment company shared their intelligence on the finding with the FBI yesterday. But the FBI today still maintained its stance that North Korea is behind the massive cyber attack.

Norse found no link whatsoever with North Korea in the intelligence it gathered independently on the attacks, which evolved out of its interest prior to the breach in landing Sony as a security customer. But an FBI spokesperson -- who declined to comment on the Norse research and briefing -- today reiterated the agency's unwavering position that North Korea was behind the attack: "Nothing has changed" in that assessment, the spokesperson told Dark Reading.

"There is no credible information to indicate that any other individual is responsible for this cyber incident," according to a statement provided today by the FBI spokesperson.

Interestingly, however, the FBI's statement specifically calls out North Korea for "theft and destruction" of data. Missing from that attribution is the initial intrusion into Sony's network and servers -- the phase researchers from Norse think may have occurred with the assistance of a former Sony employee with an axe to grind.

"The FBI has concluded the Government of North Korea is responsible for the theft and destruction of data on the network of Sony Pictures Entertainment," the FBI's latest statement says.

The agency on December 19 provided an update on the breach investigation, confirming that North Korea was responsible for the attack, pointing to the data-wiping malware used that had ties to North Korean hackers; the command and control infrastructure containing IP addresses tied to known North Korean systems; and attack tools with similarities to the attacks waged by North Korea against South Korean banks and media outlets in March of 2013.

Meanwhile, Reuters reported last night that North Korea likely hired hacking help from outside its borders to hit Sony. According to the sources, North Korea alone would have been unable to wage some phases of the attack, and officials are investigating whether Pyongyang subcontracted some of the technical know-how to perpetrate the breach.

Kurt Stammberger, senior vice president at Norse, says the common interest between "Lena," the former Sony employee identified and traced by his firm, and the Guardians of Peace is likely their mutual anger toward Sony: Lena, for getting laid off, and the Guardians for Sony's legal moves in the anti-piracy space. Norse believes Lena, based on her communications and movements, may have teamed up with hacktivists to help carry out the attacks.

He says none of the people Norse has identified are North or South Korean -- they are Americans and Canadians, and a Singapore national as well as individuals from other countries. "None of these people had any kind of obvious tie to the North Korean government that we can see," he says.

But security experts say the breach could well have been the handiwork of a combination of actors and attacks, resulting in a possible "pile-on" effect.

Mark Weatherford, the former undersecretary for cyber security at the Department of Homeland Security, says he initially questioned how the FBI could have drawn its conclusion about North Korea's involvement so quickly. "It's just mindboggling. But on the other hand, the FBI are not dummies, and they know that these statements are going to have great gravity. There must be some smoking gun or some irrefutable evidence they can point to but can't release" publicly, says Weatherford, who is a principal with The Chertoff Group.

"Norse is not going to put themselves out there, either… unless they have something irrefutable themselves," he says.

Richard Bejtlich, chief security strategist for FireEye, a firm that is investigating the Sony breach, says "responsibility" is a nuanced term, especially in the Sony breach. "The attribution debate may depend on how observers define responsibility," he says, noting that the FBI doesn't appear to be differentiating the specific level of involvement North Korea may have had. He points to an FBI statement to The Daily Beast today that adds a twist to the debate over additional actors being involved: "We're not making the distinction that you're making about the responsible party and others being involved."

Bejtlich, who recently blogged about the different levels of attribution for nation-states, says the FBI may have a broader definition of North Korea's actual role in the multi-faceted attack. "They don't think in terms of differentiating state-integrated, state-executed, state-ordered, or state-coordinated activity. If a state has any of those roles, the FBI may consider the state 'responsible,' " he says.

Norse's Stammberger doesn't dismiss the possibility of multiple attacks on Sony by different groups, either: "It may come out in the wash that the big exfiltration attack is actually a series of two or three different attacks or two or three different groups who came together and shared a common cause."

Lena, the disgruntled ex-Sony employee
At the center of Norse's findings is Lena, a woman who had worked for Sony for 10 years in a senior technical position until she was laid off in May during a corporate restructuring. "Lena had the technical knowledge to facilitate the type of attack Sony had, which is why… she remains a person of interest," Norse's Stammberger says. "There are other individuals as well. There's a pretty short list of specific individuals, and we know their names, addresses, and nationalities. They seem to have some connection to this incident."

Norse researchers examined the malware used in the attack and found it was pre-compiled with the addresses for Exchange and Active Directory servers and other specific machines inside Sony's network where "specific" files resided, says Stammberger. Usernames, passwords, and digital certificates also were found. "So this malware was precompiled with some of the keys to the kingdom," he says, adding that the malware was first compiled in July, long before the breach was revealed.

"This was more of a cruise missile than carpet-bombing, which is the typical way malware operates. This was much more targeted."

So if Lena was no longer with Sony, how did she still have access to the network and servers there?

"Perhaps her credentials were not properly retired. Or a very technical person could have easily placed backdoors in servers if they had enough notice before they had to leave… If they were sufficiently pissed off, that would be straightforward to do."

Stammberger notes that the Christmas Day distributed denial-of-service attacks on Sony's PlayStation and Microsoft's Xbox network by the Lizard Squad hacker group were not connected. "They had completely different motives," he says of the attackers.

Meanwhile, the FBI's statement today cited the DHS as one of its sources of intelligence in the investigation. "Attribution to North Korea is based on intelligence from the FBI, the US intelligence community, DHS, foreign partners, and the private sector," the FBI said. "The FBI is committed to identifying and pursuing those responsible for this act and bringing them to justice. While it remains an ongoing investigation, no further information can be provided at this time."

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 3   >   >>
ODA155
50%
50%
ODA155,
User Rank: Ninja
1/6/2015 | 2:36:35 PM
Re: So confuised
@Kelly Jackson Higgins...

After this new revaluation about an "ex-Sony employee(s)" came out I started thinking about a few things, first of all my initial feelings that regardless who was responsible, Sony still bears the blame and we should not lose sight of their (Sony's) responsibility to protect their resources.

That said, I started thinking about the company that I work for... so I'm comfortable that our SIEM is collecting the information, but are we looking in the right places? What if WE lose someone with specific admim privileges to a lay-off or if that person is fired or even if they leave on good terms, are we revieiwing everything they do/did (administratively) and are we making sure that it's all within his\her job?

The first thing I pulled out was a report that I generate quarterly (maybe I should force it to monthly)... that does not come from the SIEM, "WHO ARE THE PEOPLE WITH ADMIN\ROOT\SCHEMA ACCESS"? I use PowerGui Administrative Console to get this information for our Windows systems, unfortunately I have to rely on the UNIX\Linux Manager to get this information from those systems (but I'm working on that) too.

Then I reviewed the list of reports that I get and from the SIEM:

 - Account Creation
 - Privilege Escalation
 - Admin UserID Usage
 - Admin Database Access, Usage and Queries
 - Admin Access to Servers, DB's and Applications that are compliance applicable
 - Admin via Remote Access
 - Login Source
 - Admin Accounts with Failed Login Attempts & Locked Accounts
 - Admin Accounts with non-Expiring Passwords

This list started to get very long when I compared what I was looking at to what I wasn't. Then I started going through our security policies and I stopped at our policy that specified how "Terminations" should be handled. I recommended that we make the following changes:
  • Prior to any planned termination a review of administrative activity for a period of at least 120 days be performed.
  • Upon receipt of resignation a review of administrative activity for a period of at least 120 days be performed.
  • Manager of employee and security must review\compare all work conducted by employee to a valid Change Management Request (CMR)
  • HR\Legal notification to former employee that this internal investigation is being conducted and that employee will be held liable (legally) for any discrepancies created using their admin UserID.
  • Notify ALL administrators and managers this is the policy going forward.

I know this sounds like I'm paranoid, but I am and I don't mind because it's what they pay me for and if I don't do it nobody will... besides my boss will be the first person raked over the coals if we get hit by CRYPTOLOCKER, so if we were hacked, they'd come looking for us both with pitchforks and torches, so why not put the onus on "them" and give someone else the opportunity to say NO?
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
1/5/2015 | 4:17:59 PM
Re: So confused
@Kelly  Yeah, I feel like there were multiple groups involved, possibly working together, possibly not. If the N.K. government was at the root of it, it seems like they must have hired independent attackers to carry the thing out. Maybe one of those attackers was a disgruntled insider. Who knows?!
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
1/5/2015 | 4:14:41 PM
Re: So confuised
I hear ya, @Sara!

I still think this was not just one attack, but multiple attacks/layers by different actors that everyone is trying to understand as one big breach, which is why it's hard to wrap your head around it as a classic insider attack, hacktivist attack, or nation/state attack. It's not just one of those, really.
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
1/5/2015 | 4:10:28 PM
So confuised
I wonder if this will be one of these things that the government will classify and we'll learn the truth 50 years from now. The people I've spoken to have said everything from "an insider MUST be involved" to "no insider would be needed at all, and probably wasn't."

The whole thing just seemed too snarky to me to not include an insider somewhere in the process. Also, the North Korea connection was not acknowledged by Lena -- at least not at the beginning. In November Lena was quoted saying that NK was NOT involved. It's all very perplexing.

 
SamsonY579
50%
50%
SamsonY579,
User Rank: Apprentice
1/5/2015 | 3:54:47 PM
Petition the Whitehouse to allow an independent review of the evidence.
On November 24th, 2014 Sony Pictures Entertainment, was the victim of a cyber-attack, and on January 2nd, 2015, the Treasury imposed sanctions against the Democratic People's Republic of Korea, more commonly known as North Korea.

The premise of the sanctions is the assertion by the FBI that the cyber-attack was committed by North Korea, an assertion that has been publicly refuted by computer security experts based on information available to them.

To avoid a repeat of the "WMDs in Iraq" debacle, the President could allow a well-respected, non-partisan, independent audit by a cyber-security firm, of the evidence linking North Korea to the cyber-attack as the FBI's "just trust us" stance is insufficent, especially in the face of North Korea's denial of their involvement.

If you agree with this, please sign my petition at whitehouse.gov.

Since URLs are blocked the URL is: wh dot gov slash iggO4

wh.gov/iggO4
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
1/5/2015 | 8:11:52 AM
Re: Ongoing
Thank you, @fpdesignco. You are spot on: the bottom line is we really don't know what the FBI knows. 
Eric Kruse
50%
50%
Eric Kruse,
User Rank: Apprentice
1/4/2015 | 1:17:00 PM
Ongoing
Kelly.

 

First off way to be the first person who I have seen that actually wrote a decent article on this.  Going to take a piece of the writing out and write a opinion.

      "differentiating state-integrated, state-executed, state-ordered, or state-coordinated activity. If a state has any of those roles, the FBI may consider the state 'responsible,' " he says."

 

This is exactly what most poeple dont understand.  I love reading the articles by every major media outlet that talks to some cyber-security research firm who all have conflicting opinions about attribution.  The thing it, you do not know how the FBI (Intelligence Community in general) came to that conclusion.  For a company to say that makes me very weary of adding a talking point to selling their product with respective customers.  

 

I'd place a little bit of faith in the intelligence community on this one as no one is really looking for another black eye and congressional inquiry on a topic like this.  
Some Guy
50%
50%
Some Guy,
User Rank: Strategist
12/31/2014 | 4:49:31 PM
Re: N Korea .. Much better movie
Yeah, but only to us.

Not going to make $1M the first day of release, either.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
12/31/2014 | 12:47:51 PM
Re: Title of movie about all this
:-) #epic
BertrandW414
50%
50%
BertrandW414,
User Rank: Strategist
12/31/2014 | 12:10:09 PM
Title of movie about all this
@kelly - I think the title of the movie should be "EPIC BREACH". ;-)
Page 1 / 3   >   >>
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.