https://krebsonsecurity.com/2021/04/did-someone-at-the-commerce-dept-find-a-solarwinds-backdoor-in-aug-2020/ Advertisement [13] Advertisement [107] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020? April 16, 2021 16 Comments On Aug. 13, 2020, someone uploaded a suspected malicious file to VirusTotal, a service that scans submitted files against more than five dozen antivirus and security products. Last month, Microsoft and FireEye identified that file as a newly-discovered fourth malware backdoor used in the sprawling SolarWinds supply chain hack. An analysis of the malicious file and other submissions by the same VirusTotal user suggest the account that initially flagged the backdoor as suspicious belongs to IT personnel at the National Telecommunications and Information Administration (NTIA), a division of the U.S. Commerce Department that handles telecommunications and Internet policy. [ntia] Both Microsoft and FireEye published blog posts on Mar. 4 concerning a new backdoor found on high-value targets that were compromised by the SolarWinds attackers. FireEye refers to the backdoor as " Sunshuttle," whereas Microsoft calls it "GoldMax." FireEye says the Sunshuttle backdoor was named "Lexicon.exe," and had the unique file signatures or "hashes" of "9466c865f7498a35e4e1a8f48ef1dffd" (MD5) and b9a2c986b6ad1eb4cfb0303baede906936fe96396f3cf490b0984a4798d741d8 (SHA-1). "In August 2020, a U.S.-based entity uploaded a new backdoor that we have named SUNSHUTTLE to a public malware repository," FireEye wrote. [sunshuttle-vt] The "Sunshuttle" or "GoldMax" backdoor, as identified by FireEye and Microsoft, respectively. Image: VirusTotal.com. A search in VirusTotal's malware repository shows that on Aug. 13, 2020 someone uploaded a file with that same name and file hashes. It's often not hard to look through VirusTotal and find files submitted by specific users over time, and several of those submitted by the same user over nearly two years include messages and files sent to email addresses for people currently working in NTIA's information technology department. [vtntiared] An apparently internal email that got uploaded to VirusTotal in Feb. 2020 by the same account that uploaded the Sunshuttle backdoor malware to VirusTotal in August 2020. The NTIA did not respond to requests for comment. But in December 2020, The Wall Street Journal reported the NTIA was among multiple federal agencies that had email and files plundered by the SolarWinds attackers. "The hackers broke into about three dozen email accounts since June at the NTIA, including accounts belonging to the agency's senior leadership, according to a U.S. official familiar with the matter," The Journal wrote. It's unclear what, if anything, NTIA's IT staff did in response to scanning the backdoor file back in Aug. 2020. But the world would not find out about the SolarWinds debacle until early December 2020, when FireEye first disclosed the extent of its own compromise from the SolarWinds malware and published details about the tools and techniques used by the perpetrators. The SolarWinds attack involved malicious code being surreptitiously inserted into updates shipped by SolarWinds for some 18,000 users of its Orion network management software. Beginning in March 2020, the attackers then used the access afforded by the compromised SolarWinds software to push additional backdoors and tools to targets when they wanted deeper access to email and network communications. U.S. intelligence agencies have attributed the SolarWinds hack to an arm of the Russian state intelligence known as the SVR, which also was determined to have been involved in the hacking of the Democratic National Committee six years ago. On Thursday, the White House issued long-expected sanctions against Russia in response to the SolarWinds attack and other malicious cyber activity, leveling economic sanctions against 32 entities and individuals for disinformation efforts and for carrying out the Russian government's interference in the 2020 presidential election. The U.S. Treasury Department (which also was hit with second-stage malware that let the SolarWinds attackers read Treasury email communications) has posted a full list of those targeted, including six Russian companies for providing support to the cyber activities of the Russian intelligence service. Also on Thursday, the FBI, National Security Agency (NSA), and the Cybersecurity Infrastructure Security Administration (CISA) issued a joint advisory on several vulnerabilities in widely-used software products that the same Russian intelligence units have been attacking to further their exploits in the SolarWinds hack. Among those is CVE-2020-4006, a security hole in VMWare Workspace One Access that VMware patched in December 2020 after hearing about it from the NSA. On December 18, VMWare saw its stock price dip 5.5 percent after KrebsOnSecurity published a report linking the flaw to NSA reports about the Russian cyberspies behind the SolarWinds attack. At the time, VMWare was saying it had received "no notification or indication that CVE-2020-4006 was used in conjunction with the SolarWinds supply chain compromise." As a result, a number of readers responded that making this connection was tenuous, circumstantial and speculative. But the joint advisory makes clear the VMWare flaw was in fact used by SolarWinds attackers to further their exploits. "Recent Russian SVR activities include compromising SolarWinds Orion software updates, targeting COVID-19 research facilities through deploying WellMess malware, and leveraging a VMware vulnerability that was a zero-day at the time for follow-on Security Assertion Markup Language (SAML) authentication abuse," the NSA's advisory (PDF) reads. "SVR cyber actors also used authentication abuse tactics following SolarWinds-based breaches." Officials within the Biden administration have told media outlets that a portion of the United States' response to the SolarWinds hack would not be discussed publicly. But some security experts are concerned that Russian intelligence officials may still have access to networks that ran the backdoored SolarWinds software, and that the Russians could use that access to affect a destructive or disruptive network response of their own, The New York Times reports. "Inside American intelligence agencies, there have been warnings that the SolarWinds attack -- which enabled the SVR to place 'back doors' in the computer networks -- could give Russia a pathway for malicious activity against government agencies and corporations," The Times observed. This entry was posted on Friday 16th of April 2021 08:57 AM A Little Sunshine CVE-2020-4006 Cybersecurity Infrastructure Security Administration Democratic National Committee fbi FireEye GoldMax Lexicon.exe microsoft national security agency National Telecommunications and Information Administration NTIA SolarWinds hack Sunshuttle The Wall Street Journal U.S. Commerce Department U.S. Treasury Department virustotal VMware [109] Post navigation - Microsoft Patch Tuesday, April 2021 Edition 16 thoughts on "Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020?" 1. Sugar Ray April 16, 2021 It mentioned that the NTIA emails were hacked in June. Perhaps the attackers obtained VirusTotal credentials as well and uploaded it via those hacked credentials. That way, it cannot be traced to them Reply - 1. 1 April 16, 2021 Why would they upload their own virus to VirusTotal to be scanned? Reply - 1. Gannon (J) Dick April 16, 2021 The Six Dumbest Ideas in Computer Security #2) Enumerating Badness http://www.ranum.com/security/computer_security/ editorials/dumb/ Reply - 2. Grumpy Old Guy April 16, 2021 A long time ago, around 1970, I read a book called "Up The Organization" The only part I still remember is "You will rise to your level of incompetence." Sounds like that happens at most of these departments of government Reply - 1. Gannon (J) Dick April 16, 2021 Love that book. My favorite quote is about the strategy of data over-collection. (Exxon was the largest Corporation in the world at the time) The comment was: "Exxon didn't get to be Exxon doing things the way Exxon does them now." Reply - 2. security vet April 16, 2021 ..."rise to your level of incompetence" has been known since the 1969 book The Peter Principal by Peter Drucker... ...the vast majority of supervisors / managers exhibit that... Reply - 3. A Grumpier and probably even older guy April 16, 2021 Up the Organization is a good book, and it does mention that as a 'viable theory" (if I recall correctly--my copy got so well used it fell apart and I tossed it), but the originator of the theory was Dr. Peter, a B-school prof. and published in his books and writing. https://en.wikipedia.org/wiki/ Peter_principle Reply - 1. security vet April 16, 2021 ...possibly older and grumpier, that's me... Reply - 2. AJ North April 16, 2021 Indeed, one can trace this concept's thread back [at least] to Shepherd Mead's 1952 book, "How to Succeed in Business Without Really Trying: The Dastard's Guide to Fame and Fortune" -- which was was the basis for the highly successful 1961 Broadway musical "How to Succeed in Business Without Really Trying" (with music by Frank Loesser and book by Abe Burrows, Jack Weinstock, and Willie Gilbert), followed by a 1967 film. The original stage production won seven Tony Awards, the New York Drama Critics' Circle award, and the 1962 Pulitzer Prize for Drama. (Today, one either becomes president or goes to prison -- which are not necessarily mutually exclusive...) Kudos -- again -- Brian! Reply - 4. Steve Bushman April 16, 2021 The same goes for private industry too. Reply - 1. Steven Swinkels April 16, 2021 Based on my years in corporate management, I developed my own corollary to the Peter Principle: "You rise to one level above your level of incompetence, and then you stay THERE." Reply - 3. Fabian Soler April 16, 2021 Great analysis and writing as usual Brian. The joint advisory is also a clear-cut vindication of your reporter's instincts as to the potential link between the VMWare flaw and the NSA report about Russia/SolarWinds. The readers who called your writing "tenuous", "circumstantial" or "speculative" back in December were way off the mark. Seems they didn't bother to consider the depth of research and careful consideration that you apply to your writing, before they posted their opinions. Personally, I appreciate your no-nonsense reports. Looking forward to your virtual event on April 22nd. Regards Fabian Reply - 4. Bart April 16, 2021 I am confused by your second sentence in the first paragraph above; that begins with "An analysis..." Does it mean to say someone at the NTIA uploaded malware? Reply - 1. randomSecDude April 16, 2021 VirusTotal is a place where you can upload suspect files and see whether they have been identified as malware by well-known security vendors. So, yes, it appears someone at NITA found the backdoor, found it suspicious, and uploaded it to VirusTotal to see if it was a known malicious file. The NITA employee did the right thing. You're supposed to upload malware to VirusTotal. They didn't upload the malware any place that would have furthered any infections. Reply - 5. Gary April 16, 2021 This is a good reminder that whatever you submit to virus total will not be private. The way I use virus total is I feed it links in spam. If there is a suspicious attachment, I just delete the email. I don't even chance doing the download. Often the link isn't deemed malware. However it is possible the file isn't known to be malware yet. If it is detected as malware, only two or three out of the hundred of service will deem it malware in my experience. My point here, after that long wind up, is submitting something to virus total doesn't mean you had a clue it was malware at all. Reply - 6. Grumpy Old Guy April 16, 2021 Thanks, I actually read both books. Mainly just remember the phrase. I had a concrete construction co. in S. Cal. & several of my employees reached that level. I gave them a choice go back to being what they were before the promotion or get laid off. Most chose to go back. Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] Advertisement [111] Advertisement [110] Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020? * Microsoft Patch Tuesday, April 2021 Edition * ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users * Are You One of the 533M People Who Got Facebooked? * Ransom Gangs Emailing Victim Customers for Leverage Spam Nation Spam Nation A New York Times Bestseller! All About Skimmers All About Skimmers Click image for my skimmer series. Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * How to Break Into Security * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 The Value of a Hacked PC valuehackedpc Badguy uses for your PC Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. Donate to Krebs On Security Most Popular Posts * Sextortion Scam Uses Recipient's Hacked Passwords (1076) * Online Cheating Site AshleyMadison Hacked (798) * Sources: Target Investigating Data Breach (620) * Trump Fires Security Chief Christopher Krebs (534) * Cards Stolen in Target Breach Flood Underground Markets (445) * Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) * Was the Ashley Madison Database Leaked? (376) * DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) * True Goodbye: 'Using TrueCrypt Is Not Secure' (363) * Who Hacked Ashley Madison? (361) Why So Many Top Hackers Hail from Russia [computered-580x389] Category: Web Fraud 2.0 Criminnovations Innovations from the Underground [shreddedID-copy-285x189] ID Protection Services Examined Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can Inside a Carding Shop Inside a Carding Shop A crash course in carding. Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. (c) Krebs on Security