[HN Gopher] An inside look at NSA tactics, techniques and proced...
___________________________________________________________________
An inside look at NSA tactics, techniques and procedures from
China's lens
Author : davikr
Score : 145 points
Date : 2025-02-19 18:16 UTC (4 hours ago)
(HTM) web link (www.inversecos.com)
(TXT) w3m dump (www.inversecos.com)
| themark wrote:
| It seems like the lack of operations during US holidays would be
| a big oversight.
| vednig wrote:
| can I comment freely here
| rdtsc wrote:
| > can I comment freely here
|
| Sure, we all have the freedom of speech here. Will you have
| freedom after speech though, I don't know? It depends on your
| particular situation ;-)
| vednig wrote:
| nothing it's just two biggest intelligence agencies fighting,
| I think keeping quiet is the safest bet
| inetknght wrote:
| Sometimes keeping quiet isn't the best form of defense
| though.
|
| So it really does depend on your situation.
| rdtsc wrote:
| > No attacks occurred during Memorial Day and Independence Day
| holidays which were unique American holidays.
|
| Simple but effective. A good non-NSA agency should also learn
| from this to be able to effectively false-flag as NSA, as long as
| they are flexible enough to allow off-hours and overtime pay and
| remember to respect the US federal holidays.
|
| > Two zero-days were used to breach any company with SunOS-
| exposed systems in neighbouring countries to China
|
| SunOS? Wonder if it's because it's genuinely used still quite a
| bit or they simply had zero-days for it since many of those are
| old and unpatched?
| formerly_proven wrote:
| Assuming they mean Solaris, it's still technically maintained,
| at least in the Oracle sense (of both "technically" and
| "maintained").
| rdtsc wrote:
| I assumed that much, SunOS is pretty ancient, last version
| was what, in early 1990s? Though, Solaris still would report
| a SunOS 5.$solarisver version or something like that. So I
| guess we can say it is a "SunOS" box if we wanted to.
| jjtheblunt wrote:
| SunOS 4.x is the BSD lineage and SunOS 5.x the Solaris
| lineage, or at least was when i worked at Sun.
| zdragnar wrote:
| The same strategy is used to attribute attacks against US based
| targets by Russian, N.Korean and Iranian and other state or
| state sponsored actors. Time of day, holidays, etc. are (in
| tandem with other evidence) considered to be surprisingly
| reliable.
|
| If I were in charge of things I'd like to think that this sort
| of thing would be the first step I'd take to cover my tracks,
| but I still hear cyber security firms using it in their
| attributions.
| kokx wrote:
| The type of work the people working at an APT do, is mainly
| office work, while it still is very much "hands-on-keyboard"
| work (so you cannot set an action to automatically occur when
| nobody is checking the results in the middle of the night).
| You might want to try shuffling this up when you are in
| charge, but your (usually highly skilled and expensive)
| employees probably don't want to be working weird shifts all
| the time. Especially when they have families.
|
| It also may not be worth it. Generally APT's want to stay
| under the radar while they are executing. But after the goals
| have been reached, most of the time it doesn't matter much if
| they get attributed. We have yet to see real consequences
| against any APT's. So paying your employees more to work
| night shifts, likely doesn't stack up against the
| consequences of attribution.
| vlovich123 wrote:
| I have a hard time imagining these APT attacks are manual
| at the keyboard typing. That seems like an invention for
| entertainment whereas I'd expect reality to be "run script
| & establish an ongoing backdoor" or "run script & perform
| attack". You might need on-call to flag if anything has
| gone wrong, but I'd have a hard time imagining the entire
| team is involved for that so the cost of paying extra for
| an on-call is quite trivial vs the overall cost of the
| team. In industry that's not even compensated since
| salaried employees don't get overtime although I imagine
| that for government work the unions have negotiated this
| better.
|
| EDIT: Huh, I guess sometimes it is like the movies: > One
| of the frameworks used by TAO that was forensically
| uncovered during the incident named "NOPEN" requires human
| operation. As such, a lot of the attack required hands-on-
| keyboard and data analysis of the incident timeline showed
| 98% of all the attacks occurred during 9am - 16pm EST (US
| working hours).
| luckylion wrote:
| On-Call for mission of this size sounds fairly unlikely,
| doesn't it?
|
| You wouldn't spend hundreds of thousands of dollars on
| large scale attacks with lots of (temporary)
| infrastructure and planning to then yolo it at the last
| minute and hope that everything goes well and you have
| the results back when you come back on Monday.
| EvanAnderson wrote:
| > I have a hard time imagining these APT attacks are
| manual at the keyboard typing.
|
| (My perspective on this comes from doing security
| assessments and pentests 10+ years ago. Take that for
| what it's worth.)
|
| I think of it a little bit like robotic vs. human space
| missions.
|
| A robot can gather a ton of data without human
| intervention. It can perform repeated mindless
| activities. A certain amount of contingency against
| unforeseen issues can be engineered-in. Beyond the point
| of expected anomalies, though, the robot is going to fail
| (and perhaps expose your operation).
|
| When it comes to reacting to rapidly changing mission
| conditions nothing beats a human in the loop. It's really
| hard to plan for all the peculiarities of any given
| environment. Intuition and experience play an immense
| role. Most of all, though, you may only get one shot
| before you're detected and stopped.
| viccis wrote:
| >A good non-NSA agency should also learn from this to be able
| to effectively false-flag as NSA
|
| It seems like such a lapse in tradecraft that, absent other
| indicators, I would just assume it's a crude false flag
| attempt.
| rdtsc wrote:
| It's a Schrodinger's false-flag! Just incompetent enough to
| look like a false flag. But at the same time, it's coming
| from the heart of US bureaucracy, which finds cash to build
| multi-billion dollar hidden data centers, but is also
| inflexible enough properly pay for overtime and off-schedule
| work.
| plagiarist wrote:
| I don't find the money inexplicable at all. Building multi-
| billion dollar data centers increases wealth for
| billionaires but paying overtime would benefit a middle-
| class pleb.
| actionfromafar wrote:
| Well how convenient those plebs are down-sized right now.
| nonrandomstring wrote:
| Wasn't one of the curiosities in Snowden vault7 an
| "attribution engineering toolkit"? That sounds quite
| flexible.
| runjake wrote:
| *> A good non-NSA agency should also learn from this to be able
| to effectively false-flag as NSA*
|
| For what it's worth, this is already a TTP used domestically,
| as well as by our adversaries (and allies, eg GCHQ and 8200).
| markus_zhang wrote:
| This is really interesting. I wonder how red-teams in State
| sponsored teams operate in real life. I guess every one has an
| NDA, but would love to get a general idea.
|
| I assume it's a jungle out there, so teams need to protect
| themselves 24/7/365 and I'm surprised to find no activities in
| holidays.
| breppp wrote:
| It seems like the most efficient way of detecting NSA tools is a
| regular expression of two all caps dictionary words
| contingencies wrote:
| BadJoke LoveIt.
|
| Similarly, 0day ABNF to identify probable NSA front companies:
|
| _[optional-firstname] <surname> [optional-adjective]
| <"systems">_
| lazide wrote:
| BRILLANT SPECTRE finds your joke in bad taste (/s)
| motohagiography wrote:
| glad to see the same basic tradecraft from 90s hacking, only very
| refined and industrialized. it's a durable skill. the focus on
| switches and routers is very pro, as they are the most opaque
| infra with the fewest forensic capabilities. iot is less reliable
| as RE'ing cheap devices and firmware for IoCs is accessible,
| where almost nobody outside the IC did core gear (word to
| phenolit from back in the day tho).
|
| the traffic redirection is interesting in that i would be curious
| if they rate limited it or used on device selectors in their
| implant to redirect traffic. the trade off between memory caching
| packets to sort on selectors vs.stealthy throughput would have
| been a fun design meeting.
|
| hunting these kinds of actors would be supremely fun. the main
| thing that protects them is few outside massive bureaucracies
| really care enough or find it economical, as the rewards are more
| in finding new zero day and not hunting state level threat
| actors. the exceptions who do (p0, citizenlab etc) are attached
| to massive orgs and dont really led themselves to privateering.
| amazing write up anyway.
| thaumasiotes wrote:
| > These insights stem from extensive research I did on Weixin
|
| Someone doing extensive research on Weixin might ordinarily
| realize that it's called "Wechat" in English.
| boston_clone wrote:
| Wechat is the internationalized version; Weixin is for mainland
| China.
|
| https://duckduckgo.com/?q=weixin+vs+wechat
| thaumasiotes wrote:
| I guess if ChatGPT told you to glue the cheese onto your
| pizza, you'd eat it that way.
|
| Wechat is also the mainland version. It's always been Wechat,
| and in particular it was Wechat years before they kicked me
| off of the mainland Chinese version+ for registering an
| American phone number. The reality is exactly what I already
| told you: the app's name is Wei Xin in Chinese and Wechat in
| English. This is why coverage of Wechat's extensive market
| penetration in China always calls it "Wechat".
|
| Don't believe everything you read in the results of the
| stupidest web search you know how to run. If you try facts,
| you might like them!
|
| + By the way, "version" is _really_ stretching things. There
| is no difference in the app. They don 't keep your data
| within China, you go into a different advertising segment,
| and by default you connect to a different in-app sticker
| shop.
| boston_clone wrote:
| That would have been great to include with your initial
| comment instead of seemingly picking at nits and then
| making inflammatory comments.
|
| Always love the use of a dagger though, I don't see them
| too often online!
| kridsdale1 wrote:
| I love the Windows 98 clip art.
| alphalite wrote:
| I originally came here to comment how crazy it seems that DoD
| employees at NSA cannot be bothered to cover their tracks by
| working nonstandard hours/holidays (obviously Mil & Intel folks
| do this, they even get deployed!). But the thought occurred to me
| that attribution to NSA was likely a desired outcome here ("We
| can hack you too") and there are probably many people at NSA
| working nonstandard hours/days to prevent attribution.
|
| I think the English language aspect is much more interesting and
| difficult/impossible to prevent.
| quanto wrote:
| I agree, but I would go further and say (written) English
| language is as easy to emulate. There are technical people with
| great written English skills who will give away their non-
| Anglophone identities at the first sentence they speak.
| maxglute wrote:
| Technical talent with transferable skills for higher paying
| work aren't incentivized to work on deployment schedule. But
| really, why assume NSA capable of obfuscating against PRC also
| stacked with talent. The parsimonious answer is then why
| bother, everyone knows they're deep in each others networks for
| decades and will continue to be. So let the hackers have their
| weekends.
| quanto wrote:
| > Chinese cyber organizations openly acknowledge and publicize
| their partnerships. This openness was particularly interesting to
| observe and may be influenced by cultural factors, such as the
| Confucian emphasis on shared knowledge and a political framework
| that encourages collective efforts.
|
| I or anyone outside obviously cannot verify the technical
| details. However, the above statement struck as particularly
| uninformed. As any engineer in East Asia can tell you, there is
| nothing especially collaborative about tech in Confucian culture;
| if anything, the engineers in that region admire the free speech
| and discussion traditionally prized in the Western culture.
| Calling Chinese political framework, especially in the context of
| national security, conducive to open public discussion was quite
| ironic to see.
|
| Edit: the punchline is this. If a friend who is always secretive
| and deceptive about his personal life is suddenly openly
| discussing his life, what does that say about the details he just
| disclosed and/or the situation he is currently in?
|
| source: I regularly work with engineers from that culture and
| studied relevant geopolitics.
| dmix wrote:
| > In total, 54 jump servers and 5 proxy servers were used to
| perform the attack coming from 17 different countries including
| Japan, South Korea, Sweden, Poland and Ukraine with 70% of the
| attacks coming from China's neighbouring countries.
|
| I'm guessing this is so when they do data exfiltration (and
| hosted MITM) it's not sending a ton of data to a single server,
| but spreads them out.
|
| > SECONDDATE: This tool was allegedly used by TAO (NSA) to hack
| into the office intranet of the University. Attribution of
| SECONDDATE was discovered through collaboration with other
| industry partners. They found thousands of network devices
| running this spyware - where the communications went back to NSA
| servers located in Germany, Japan, South Korea and Taiwan. This
| tool was used to redirect user traffic to the FOXACID platform.
|
| > SECONDDATE - Backdoor installed on network edge devices such as
| gateways and border routers to filter, and hijack mass amounts of
| data in a MiTM. This was placed on the border routers of the
| University to hijack traffic to redirect to NSA's FOXACID
| platform.
| ThinkBeat wrote:
| Given how US is attacking their enemies and at times their
| allies, 24/7 it is amazing how little we ever hear about it.
| Mountain_Skies wrote:
| If we were in Russia or China, we'd likely hear about US
| actions in this area quite a bit more. With allies, well,
| there's a lot of mutual back scrubbing going on.
| WarOnPrivacy wrote:
| Regarding unwarranted surveillance of Americans not suspected
| of a crime (and by extension, our allies):
|
| Throughout my longish life, these things have not changed.
|
| ~All federal politicians support/expand it and then obfuscate
| their part.
|
| News orgs don't/won't cover it (most of the time). The reason
| is every possible reason. Stated differently: Reluctance is a
| forgone conclusion; every editor/journalist has their own why.
|
| There is an excess of voters who compulsively give Gov the
| benefit of the doubt. At least where Gov favors it's interests
| over ours. (modern version: Where Gov acts in good faith and
| places our interest first, wound-up voters endlessly crap all
| over that [because agendas].)
| markus_zhang wrote:
| China did publish some information once for a while. But the
| information is usually in Chinese and lacking details.
___________________________________________________________________
(page generated 2025-02-19 23:00 UTC)