Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/20/2016
02:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Report: ShadowBrokers Obtained Stolen NSA Info Via Rogue Insider

Flashpoint researchers have 'medium confidence' that rogue insider, not just outside hacker, was involved in ShadowBrokers' August and December data dumps.

A new report from threat intelligence firm Flashpoint suggests attackers from ShadowBrokers did not hack into the NSA to obtain details about internal exploit tools. Flashpoint researchers now believe ShadowBrokers received stolen information from a rogue NSA insider. This is the first evidence indicating stolen details came from someone within the NSA and not a third-party hack.

In August 2016, the ShadowBrokers claimed to possess - and offered to sell - stolen information from the "Equation Group." Security experts widely believe "the Equation Group" to be the NSA - although Kaspersky Lab, which originally exposed the Equation Group in 2015, never confirmed this, because it doesn't verify attribution. Researchers discovered a code similarity in August that led them to believe tools leaked by ShadowBrokers were related to Equation Group malware.

Experts theorized ShadowBrokers hacked into the NSA, pulled information, and shared it, says Ronnie Tokazowski, senior malware analyst at Flashpoint. Some people thought there might have been a rogue contractor, but there was little to no evidence supporting the idea.

Now, it seems Shadow Brokers has resurfaced after a quiet period following the August incident. Last week, it leaked more information and a newly uncovered website indicates it's attempting to sell hacking tools to individual buyers online.

The group may have also inadvertently shared the level of access it has.

Based on the most recent data dump, "it looks like it was an insider who did it," says Tokazowski. 

While the company is unsure how the documents were exfiltrated, it seems documents were copied from an internal system or code repository. They weren't directly accessed via external remote hacking or discovered on an external staging server.

"Based off the file structure and how it's written, instead of the ShadowBrokers hacking in, it looks like an internal code repository the author or ShadowBrokers had access to," Tokazowski continues. "We're looking at how the files were written and how stuff is laid out."

Tokazowski says he believes an insider was involved in both this latest data dump and the earlier one this summer. 

There are several questions surrounding the latest leak, namely the motivation behind it.

"If it is an insider, the timing is strange," Tokazowski notes. The tools offered for sale in this latest dump include documentation scripts from 2005 through 2013, focused on Linux and Unix-based Computer Network Exploitation (CNE) operations.

While ShadowBrokers changed the data and timestamps to prevent expert analysts, Flashpoint estimates the information was obtained in July 2013. If that's the case, why wait until 2016 to sell? If the group wanted to generate a profit, they would have sold the exploits in 2013, when the data was most valuable.

This incident could still be financially motivated. The insider is currently selling the entire batch of data for 1,000 Bitcoin (about $800,000 USD); individual tools are going for 10-100 Bitcoin (about $8,000-$80,000 USD). However, if the sale is successful, "everyone and their brother will want to see where the money goes," says Tokazowski.

Tokazowski notes the NSA insider may have been inspired by Edward Snowden, who leaked data in 2013. The individual may have "chickened out" on selling the information and held onto it until now.

Who does he think is behind the December leak? "I think it was an insider, someone who had access to those systems," he emphasizes. "It really looks like this ties back to an insider, as opposed to someone who hacked the NSA."

Insider employees with access to sensitive data can be tremendously dangerous to an organization, as Snowden demonstrated. Tokazowski says businesses will have to be on the lookout for these individuals: people who operate independently, who may carry USB sticks or CDs loaded with sensitive information.

There are different rules organizations can employ to disable USB access or prevent CDs from being written, making it more difficult for malicious insiders to share sensitive data. However, it's difficult to entirely prevent this type of crime.

"If you put in protection, someone who is passionate enough will attempt to bypass those," he cautions.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
Average Cost of a Data Breach: $3.86 Million
Jai Vijayan, Contributing Writer,  7/29/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-18112
PUBLISHED: 2020-08-05
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
CVE-2020-15109
PUBLISHED: 2020-08-04
In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order without changing the shipm...
CVE-2020-16847
PUBLISHED: 2020-08-04
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
CVE-2020-15135
PUBLISHED: 2020-08-04
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF...
CVE-2020-13522
PUBLISHED: 2020-08-04
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this vulnerability.