[HN Gopher] An inside look at NSA tactics, techniques and proced...
       ___________________________________________________________________
        
       An inside look at NSA tactics, techniques and procedures from
       China's lens
        
       Author : davikr
       Score  : 145 points
       Date   : 2025-02-19 18:16 UTC (4 hours ago)
        
 (HTM) web link (www.inversecos.com)
 (TXT) w3m dump (www.inversecos.com)
        
       | themark wrote:
       | It seems like the lack of operations during US holidays would be
       | a big oversight.
        
       | vednig wrote:
       | can I comment freely here
        
         | rdtsc wrote:
         | > can I comment freely here
         | 
         | Sure, we all have the freedom of speech here. Will you have
         | freedom after speech though, I don't know? It depends on your
         | particular situation ;-)
        
           | vednig wrote:
           | nothing it's just two biggest intelligence agencies fighting,
           | I think keeping quiet is the safest bet
        
             | inetknght wrote:
             | Sometimes keeping quiet isn't the best form of defense
             | though.
             | 
             | So it really does depend on your situation.
        
       | rdtsc wrote:
       | > No attacks occurred during Memorial Day and Independence Day
       | holidays which were unique American holidays.
       | 
       | Simple but effective. A good non-NSA agency should also learn
       | from this to be able to effectively false-flag as NSA, as long as
       | they are flexible enough to allow off-hours and overtime pay and
       | remember to respect the US federal holidays.
       | 
       | > Two zero-days were used to breach any company with SunOS-
       | exposed systems in neighbouring countries to China
       | 
       | SunOS? Wonder if it's because it's genuinely used still quite a
       | bit or they simply had zero-days for it since many of those are
       | old and unpatched?
        
         | formerly_proven wrote:
         | Assuming they mean Solaris, it's still technically maintained,
         | at least in the Oracle sense (of both "technically" and
         | "maintained").
        
           | rdtsc wrote:
           | I assumed that much, SunOS is pretty ancient, last version
           | was what, in early 1990s? Though, Solaris still would report
           | a SunOS 5.$solarisver version or something like that. So I
           | guess we can say it is a "SunOS" box if we wanted to.
        
             | jjtheblunt wrote:
             | SunOS 4.x is the BSD lineage and SunOS 5.x the Solaris
             | lineage, or at least was when i worked at Sun.
        
         | zdragnar wrote:
         | The same strategy is used to attribute attacks against US based
         | targets by Russian, N.Korean and Iranian and other state or
         | state sponsored actors. Time of day, holidays, etc. are (in
         | tandem with other evidence) considered to be surprisingly
         | reliable.
         | 
         | If I were in charge of things I'd like to think that this sort
         | of thing would be the first step I'd take to cover my tracks,
         | but I still hear cyber security firms using it in their
         | attributions.
        
           | kokx wrote:
           | The type of work the people working at an APT do, is mainly
           | office work, while it still is very much "hands-on-keyboard"
           | work (so you cannot set an action to automatically occur when
           | nobody is checking the results in the middle of the night).
           | You might want to try shuffling this up when you are in
           | charge, but your (usually highly skilled and expensive)
           | employees probably don't want to be working weird shifts all
           | the time. Especially when they have families.
           | 
           | It also may not be worth it. Generally APT's want to stay
           | under the radar while they are executing. But after the goals
           | have been reached, most of the time it doesn't matter much if
           | they get attributed. We have yet to see real consequences
           | against any APT's. So paying your employees more to work
           | night shifts, likely doesn't stack up against the
           | consequences of attribution.
        
             | vlovich123 wrote:
             | I have a hard time imagining these APT attacks are manual
             | at the keyboard typing. That seems like an invention for
             | entertainment whereas I'd expect reality to be "run script
             | & establish an ongoing backdoor" or "run script & perform
             | attack". You might need on-call to flag if anything has
             | gone wrong, but I'd have a hard time imagining the entire
             | team is involved for that so the cost of paying extra for
             | an on-call is quite trivial vs the overall cost of the
             | team. In industry that's not even compensated since
             | salaried employees don't get overtime although I imagine
             | that for government work the unions have negotiated this
             | better.
             | 
             | EDIT: Huh, I guess sometimes it is like the movies: > One
             | of the frameworks used by TAO that was forensically
             | uncovered during the incident named "NOPEN" requires human
             | operation. As such, a lot of the attack required hands-on-
             | keyboard and data analysis of the incident timeline showed
             | 98% of all the attacks occurred during 9am - 16pm EST (US
             | working hours).
        
               | luckylion wrote:
               | On-Call for mission of this size sounds fairly unlikely,
               | doesn't it?
               | 
               | You wouldn't spend hundreds of thousands of dollars on
               | large scale attacks with lots of (temporary)
               | infrastructure and planning to then yolo it at the last
               | minute and hope that everything goes well and you have
               | the results back when you come back on Monday.
        
               | EvanAnderson wrote:
               | > I have a hard time imagining these APT attacks are
               | manual at the keyboard typing.
               | 
               | (My perspective on this comes from doing security
               | assessments and pentests 10+ years ago. Take that for
               | what it's worth.)
               | 
               | I think of it a little bit like robotic vs. human space
               | missions.
               | 
               | A robot can gather a ton of data without human
               | intervention. It can perform repeated mindless
               | activities. A certain amount of contingency against
               | unforeseen issues can be engineered-in. Beyond the point
               | of expected anomalies, though, the robot is going to fail
               | (and perhaps expose your operation).
               | 
               | When it comes to reacting to rapidly changing mission
               | conditions nothing beats a human in the loop. It's really
               | hard to plan for all the peculiarities of any given
               | environment. Intuition and experience play an immense
               | role. Most of all, though, you may only get one shot
               | before you're detected and stopped.
        
         | viccis wrote:
         | >A good non-NSA agency should also learn from this to be able
         | to effectively false-flag as NSA
         | 
         | It seems like such a lapse in tradecraft that, absent other
         | indicators, I would just assume it's a crude false flag
         | attempt.
        
           | rdtsc wrote:
           | It's a Schrodinger's false-flag! Just incompetent enough to
           | look like a false flag. But at the same time, it's coming
           | from the heart of US bureaucracy, which finds cash to build
           | multi-billion dollar hidden data centers, but is also
           | inflexible enough properly pay for overtime and off-schedule
           | work.
        
             | plagiarist wrote:
             | I don't find the money inexplicable at all. Building multi-
             | billion dollar data centers increases wealth for
             | billionaires but paying overtime would benefit a middle-
             | class pleb.
        
               | actionfromafar wrote:
               | Well how convenient those plebs are down-sized right now.
        
           | nonrandomstring wrote:
           | Wasn't one of the curiosities in Snowden vault7 an
           | "attribution engineering toolkit"? That sounds quite
           | flexible.
        
         | runjake wrote:
         | *> A good non-NSA agency should also learn from this to be able
         | to effectively false-flag as NSA*
         | 
         | For what it's worth, this is already a TTP used domestically,
         | as well as by our adversaries (and allies, eg GCHQ and 8200).
        
       | markus_zhang wrote:
       | This is really interesting. I wonder how red-teams in State
       | sponsored teams operate in real life. I guess every one has an
       | NDA, but would love to get a general idea.
       | 
       | I assume it's a jungle out there, so teams need to protect
       | themselves 24/7/365 and I'm surprised to find no activities in
       | holidays.
        
       | breppp wrote:
       | It seems like the most efficient way of detecting NSA tools is a
       | regular expression of two all caps dictionary words
        
         | contingencies wrote:
         | BadJoke LoveIt.
         | 
         | Similarly, 0day ABNF to identify probable NSA front companies:
         | 
         |  _[optional-firstname] <surname> [optional-adjective]
         | <"systems">_
        
         | lazide wrote:
         | BRILLANT SPECTRE finds your joke in bad taste (/s)
        
       | motohagiography wrote:
       | glad to see the same basic tradecraft from 90s hacking, only very
       | refined and industrialized. it's a durable skill. the focus on
       | switches and routers is very pro, as they are the most opaque
       | infra with the fewest forensic capabilities. iot is less reliable
       | as RE'ing cheap devices and firmware for IoCs is accessible,
       | where almost nobody outside the IC did core gear (word to
       | phenolit from back in the day tho).
       | 
       | the traffic redirection is interesting in that i would be curious
       | if they rate limited it or used on device selectors in their
       | implant to redirect traffic. the trade off between memory caching
       | packets to sort on selectors vs.stealthy throughput would have
       | been a fun design meeting.
       | 
       | hunting these kinds of actors would be supremely fun. the main
       | thing that protects them is few outside massive bureaucracies
       | really care enough or find it economical, as the rewards are more
       | in finding new zero day and not hunting state level threat
       | actors. the exceptions who do (p0, citizenlab etc) are attached
       | to massive orgs and dont really led themselves to privateering.
       | amazing write up anyway.
        
       | thaumasiotes wrote:
       | > These insights stem from extensive research I did on Weixin
       | 
       | Someone doing extensive research on Weixin might ordinarily
       | realize that it's called "Wechat" in English.
        
         | boston_clone wrote:
         | Wechat is the internationalized version; Weixin is for mainland
         | China.
         | 
         | https://duckduckgo.com/?q=weixin+vs+wechat
        
           | thaumasiotes wrote:
           | I guess if ChatGPT told you to glue the cheese onto your
           | pizza, you'd eat it that way.
           | 
           | Wechat is also the mainland version. It's always been Wechat,
           | and in particular it was Wechat years before they kicked me
           | off of the mainland Chinese version+ for registering an
           | American phone number. The reality is exactly what I already
           | told you: the app's name is Wei Xin  in Chinese and Wechat in
           | English. This is why coverage of Wechat's extensive market
           | penetration in China always calls it "Wechat".
           | 
           | Don't believe everything you read in the results of the
           | stupidest web search you know how to run. If you try facts,
           | you might like them!
           | 
           | + By the way, "version" is _really_ stretching things. There
           | is no difference in the app. They don 't keep your data
           | within China, you go into a different advertising segment,
           | and by default you connect to a different in-app sticker
           | shop.
        
             | boston_clone wrote:
             | That would have been great to include with your initial
             | comment instead of seemingly picking at nits and then
             | making inflammatory comments.
             | 
             | Always love the use of a dagger though, I don't see them
             | too often online!
        
       | kridsdale1 wrote:
       | I love the Windows 98 clip art.
        
       | alphalite wrote:
       | I originally came here to comment how crazy it seems that DoD
       | employees at NSA cannot be bothered to cover their tracks by
       | working nonstandard hours/holidays (obviously Mil & Intel folks
       | do this, they even get deployed!). But the thought occurred to me
       | that attribution to NSA was likely a desired outcome here ("We
       | can hack you too") and there are probably many people at NSA
       | working nonstandard hours/days to prevent attribution.
       | 
       | I think the English language aspect is much more interesting and
       | difficult/impossible to prevent.
        
         | quanto wrote:
         | I agree, but I would go further and say (written) English
         | language is as easy to emulate. There are technical people with
         | great written English skills who will give away their non-
         | Anglophone identities at the first sentence they speak.
        
         | maxglute wrote:
         | Technical talent with transferable skills for higher paying
         | work aren't incentivized to work on deployment schedule. But
         | really, why assume NSA capable of obfuscating against PRC also
         | stacked with talent. The parsimonious answer is then why
         | bother, everyone knows they're deep in each others networks for
         | decades and will continue to be. So let the hackers have their
         | weekends.
        
       | quanto wrote:
       | > Chinese cyber organizations openly acknowledge and publicize
       | their partnerships. This openness was particularly interesting to
       | observe and may be influenced by cultural factors, such as the
       | Confucian emphasis on shared knowledge and a political framework
       | that encourages collective efforts.
       | 
       | I or anyone outside obviously cannot verify the technical
       | details. However, the above statement struck as particularly
       | uninformed. As any engineer in East Asia can tell you, there is
       | nothing especially collaborative about tech in Confucian culture;
       | if anything, the engineers in that region admire the free speech
       | and discussion traditionally prized in the Western culture.
       | Calling Chinese political framework, especially in the context of
       | national security, conducive to open public discussion was quite
       | ironic to see.
       | 
       | Edit: the punchline is this. If a friend who is always secretive
       | and deceptive about his personal life is suddenly openly
       | discussing his life, what does that say about the details he just
       | disclosed and/or the situation he is currently in?
       | 
       | source: I regularly work with engineers from that culture and
       | studied relevant geopolitics.
        
       | dmix wrote:
       | > In total, 54 jump servers and 5 proxy servers were used to
       | perform the attack coming from 17 different countries including
       | Japan, South Korea, Sweden, Poland and Ukraine with 70% of the
       | attacks coming from China's neighbouring countries.
       | 
       | I'm guessing this is so when they do data exfiltration (and
       | hosted MITM) it's not sending a ton of data to a single server,
       | but spreads them out.
       | 
       | > SECONDDATE: This tool was allegedly used by TAO (NSA) to hack
       | into the office intranet of the University. Attribution of
       | SECONDDATE was discovered through collaboration with other
       | industry partners. They found thousands of network devices
       | running this spyware - where the communications went back to NSA
       | servers located in Germany, Japan, South Korea and Taiwan. This
       | tool was used to redirect user traffic to the FOXACID platform.
       | 
       | > SECONDDATE - Backdoor installed on network edge devices such as
       | gateways and border routers to filter, and hijack mass amounts of
       | data in a MiTM. This was placed on the border routers of the
       | University to hijack traffic to redirect to NSA's FOXACID
       | platform.
        
       | ThinkBeat wrote:
       | Given how US is attacking their enemies and at times their
       | allies, 24/7 it is amazing how little we ever hear about it.
        
         | Mountain_Skies wrote:
         | If we were in Russia or China, we'd likely hear about US
         | actions in this area quite a bit more. With allies, well,
         | there's a lot of mutual back scrubbing going on.
        
         | WarOnPrivacy wrote:
         | Regarding unwarranted surveillance of Americans not suspected
         | of a crime (and by extension, our allies):
         | 
         | Throughout my longish life, these things have not changed.
         | 
         | ~All federal politicians support/expand it and then obfuscate
         | their part.
         | 
         | News orgs don't/won't cover it (most of the time). The reason
         | is every possible reason. Stated differently: Reluctance is a
         | forgone conclusion; every editor/journalist has their own why.
         | 
         | There is an excess of voters who compulsively give Gov the
         | benefit of the doubt. At least where Gov favors it's interests
         | over ours. (modern version: Where Gov acts in good faith and
         | places our interest first, wound-up voters endlessly crap all
         | over that [because agendas].)
        
         | markus_zhang wrote:
         | China did publish some information once for a while. But the
         | information is usually in Chinese and lacking details.
        
       ___________________________________________________________________
       (page generated 2025-02-19 23:00 UTC)