Showing posts with label Equation Group. Show all posts
Showing posts with label Equation Group. Show all posts

Thursday, June 29, 2017

NSA-Linked Hackers Raise Price Of Monthly Subscription to $61,000 After Tuesday's Cyberattack

In the wake of Tuesday’s massive global ransomware attack, the hacker group called the Shadow Brokers is again trying to capitalize on its reputation as a source of leaked NSA hacking exploits, saying it will up the price of a subscription service launched earlier this month, while also introducing a new “premium” feature.


The group introduced a monthly subscription service following last month’s WannaCry attack, after initially trying to sell its entire cache of NSA-funded cyberweapons for a staggering one million bitcoin (worth $2.5 billion at current prices). Both WannaCry and Tuesday’s attack, which has been blamed on the “Goldeneye” strain of the “Petya” ransomware, were aided by exploits that the Shadowbrokers allegedly stole from an NSA special-ops crew called “the Equation Group.”





Now, the Shadowbrokers are marketing their wares not only at hackers, but at corporations who’d like to buy insurance against being hacked.


Here’s the Shadowbrokers, in their characteristic broken English, as reported by The Hill.





"Another global cyber attack is fitting end for first month of theshadowbrokers dump service. There is much theshadowbrokers can be saying about this but what is point and having not already being said? So to business! Time is still being left to make subscribe and getting June dump. Don’t be let company fall victim to next cyber attack, maybe losing big bonus or maybe price on stock options be going down after attack. June dump service is being great success for theshadowbrokers, many many subscribers, so in July theshadowbrokers is raising price," the ShadowBrokers wrote in an online message released early Wednesday.”



The Shadowbrokers launched its monthly subscription document leaks service this month at a price of $27,000 a month in digital currency. Their new release more than doubles the price to $61,000.  The group also announced a new premium service allowing customers to make requests for assistance or specific document releases.


The group has been active since August 2016, when it began leaking hacking tools that were allegedly developed by the NSA. It has also leaked documents appearing to show the NSA hacked a Middle Eastern banking services company to try and get at the company’s clients, according to the Hill.


One of the exploits released by the group back in April, known as EternalBlue, was instrumental in aiding last month’s WannaCry cyberattack. Both WannaCry and another NSA exploit were allegedly intrumental in Tuesday"s attack.


The group also publicly released a password to what Edward Snowden called the NSA’s “top-secret arsenal of digital weapons.” Back in April, the group released passwords to hacking tool binaries developed by the NSA in 2013 as a “protest” against President Donald Trump, whom they accused of betraying his base by launching a missile strike against a Syrian government airfield and for backing away from his commitment to combating globalism.  


The first reports of organizations being hit by Tuesday’s attack were from Russia and Ukraine, but the impact quickly spread westwards to computers in Romania, the Netherlands, Norway, and Britain. Companies affected included German pharmaceutical company Merck, Russia"s Rosneft and metals giant Evraz, Danish shipper Maersk, UK ad company WPP, and both the Ukrainian and Russian central banks.


Already, Ukrainian government officials are blaming the attack on a Russian entity – likely government-sponsored – claiming that the virus’s code was written in Russian, ignoring the fact that Russian firms were also attacked, and mirroring the laughable conclusion that the North Korean government was somehow responsible for the original WannaCry attack.


With two global attacks unfolding in the span of two months, it’s incredible that the public – not to mention investors – aren’t more worried. How long until these attacks become a weekly, or even daily, occurrence. And more importantly, how long until they begin to seriously disrupt the functioning of private infrastructure.


At least one former NSA employee chimed in with his two cents about the agency’s role in making these attacks possible.






Nobody has been able to say for certain who or what the Shadowbrokers are. But at least one famed NSA whistleblower has a theory:


William Binney - who exposed the NSA"s pervasive surveillance of Americans long before Snowden confirmed it - said he and his colleagues are fairly certain the Shadowbrokers aren"t really a group of rogue actors, but rather an insider employee at NSA.

Saturday, May 20, 2017

"ShadowBrokers" Hacking Group Launches Subscription Service Selling Nuclear Secrets

The hacking group known as "The Shadow Brokers" is pushing a monthly subscription service offering members top secret information including "compromised network data" from the nuclear and ballistic missile programs of Russia, China, North Korea and Iran.



As a reminder, we have noted in the past, many security experts believe the Equation Group is the National Security Agency, and that the Shadow Brokers may be part of a psychological operations campaign run by Russian intelligence.





Shadow Brokers first emerged last August, offering to auction hacking exploits it said were used by the NSA’s elite hacking team known as Equation Group (officially named Tailored Access Operations). NSA whistleblower Edward Snowden and others confirmed the leak was authentic.



In December, Shadow Brokers cancelled its auction and offered to sell the exploits.



In April, the group released passwords to the rest of the hacking exploits in a move described as a protest against President Donald Trump for abandoning his base.



The release included a Windows SMB [Server Message Block] exploit, EternalBlue, which was leveraged in the recent WannaCry global ransomware attack.



In its Tuesday blog post, the group expressed its surprise that governments or tech companies didn’t bid in its past auctions.



It said is has always been about “the shadowbrokers vs theequation group,” and implied the NSA is a cohort of tech companies like Microsoft.


And now, as RT reports, the group’s monthly data dump could also include hacking exploits for web browsers, routers, and operating systems including Windows 10.





"TheShadowBrokers Data Dump of the Month" is a new monthly subscription model, the group said.



Payment will likely be made in the cryptocurrency Bitcoin given the group’s ransom demands in previous cyber attacks.



The group also promised to include compromised financial data from the SWIFT international payment order system, used by banks to transfer trillions of dollars each day, as well as confidential data from several central banks.



In a blog post published Tuesday, titled, ‘Oh Lordy! Comey Wanna Cry Edition’ the group accused the NSA of paying Microsoft to keep vulnerabilities in its software (and did not hold back in its accusations)





If theshadowbrokers is telling the peoples theequationgroup is paying U.S technology companies NOT TO PATCH vulnerabilities until public discovery, is this being Fake News or Conspiracy Theory?



Why Microsoft patching SMB vulnerabilities in secret? Microsoft is being embarrassed because theequationgroup is lying to Microsoft. TheEquationGroup is not telling Microsoft about SMB vulnerabilities, so Microsoft not preparing with quick fix patch. More important theequationgroup not paying Microsoft for holding vulnerability. Microsoft is thinking it knowing all the vulnerabilities theEquationGroup is using and paying for holding patch.



Douche bag, dumbass, libtard, rich prick Head Microsoft Lawyer is running his cock holster because he is having ruff weekend doing real work. Head Microsoft Lawyer being angry because he is missing leisurely weekend playing the skin flute behind the country club.



Real work is not being for executives. Real work is being for dirty foreign H1B workforce, happily working for less than stupid lazy American workers.



Shadow Brokers finished its post saying if a responsible party were to buy “all lost data before it is being sold to the peoples” then the group would have no more financial incentives and would “go dark permanently.”

Thursday, May 18, 2017

"It's Much Bigger Than WannaCry": New Stealthy Cyberattack Could Dwarf Last Week's Global Worm Epidemic

Another large-scale, stealthy cyberattack is underway on a scale that could dwarf last week"s assault on computers worldwide, a global cybersecurity firm told AFP on Wednesday.



Meet Adylkuzz - the new cyberattack that "is much bigger than WannaCry."





Instead of completely disabling an infected computer by encrypting data and seeking a ransom payment, Adylkuzz uses the machines it infects to "mine" in a background task a virtual currency, Monero, and transfer the money created to the authors of the virus.



Proofpoint said in a blog that symptoms of the attack include loss of access to shared Windows resources and degradation of PC and server performance, effects which some users may not notice immediately.



"As it is silent and doesn"t trouble the user, the Adylkuzz attack is much more profitable for the cyber criminals. It transforms the infected users into unwitting financial supporters of their attackers," said Godier.



Proofpoint said it has detected infected machines that have transferred several thousand dollars worth of Monero to the creators of the virus. The firm believes Adylkuzz has been on the loose since at least May 2, and perhaps even since April 24, but due to its stealthy nature was not immediately detected. Proofpoint"s vice president for email products, Robert Holmes, told AFP...





"We don"t know how big it is" but "it"s much bigger than WannaCry",



"We have seen that before -- malwares mining cryptocurrency -- but not this scale," said Holmes.



It uses the hacking tools recently disclosed by the NSA "in a more stealthy manner and for a different purpose." As InfoRiskToday details...





The SMB flaw (file-sharing network protocol) targeted by this Adylkuzz campaign existed in all versions of Windows since XP and came to light in April, via a dump of "Equation Group" tools released by the Shadow Brokers.



Many security experts believe the Equation Group is the National Security Agency, and that the Shadow Brokers may be part of a psychological operations campaign run by Russian intelligence.



One of the Equation Group exploits included in the April dump, called EternalBlue, is designed to exploit the SMB flaw in Windows. If successful, the Equation Group would then often install a backdoor called DoublePulsar onto the exploited endpoint to give it persistent, quiet access to the system.



Rather than freeze files demanding a ransom, Adylkuzz uses the hundreds of thousands of infected computers to mine virtual currency... As InfoRiskToday details...





The WannaCry outbreak began May 12. But Proofpoint says that the Adylkuzz campaign that targeted DoublePulsar and EternalBlue appears to have begun as early as April 24 - nearly three weeks earlier - and hasn"t stopped.



"This attack is ongoing and, while less flashy than WannaCry, is nonetheless quite large and potentially quite disruptive," Kafeine says in a Monday blog post.



In addition, Proofpoint reports that multiple outbreaks that were attributed to the WannaCry campaign, but which involved no ransom notice, may, in fact, have instead been part of the Adylkuzz campaign.



As with WannaCry, the Adylkuzz malware first attempts to exploit a system via EternalBlue, and if successful then infects the endpoint with DoublePulsar, Kafeine says.





"Once running, Adylkuzz will first stop any potential instances of itself already running and block SMB communication to avoid further infection, Kafeine says. "It then determines the public IP address of the victim and download the mining instructions, cryptominer, and cleanup tools."



This Adylkuzz campaign is mining not for the world"s most well-known cryptocurrency, but rather for monero.



Also known as XMR, InfoRiskToday notes that the creators of the cryptocurrency claim that it"s more private and difficult to trace than bitcoin. Unlike bitcoin, it also has no hardcoded block size limit, meaning that - at least in theory - an infinite amount of monero could be mined.


So far it"s not clear who"s behind this cryptocurrency mining operation. A version of WannaCry seen in February contains code that was used in a 2015 attack tied to Lazarus - a hacking group security experts say ties to North Korea. But anyone could have reused the 2015 code, which is publicly available, Matt Suiche, managing director at incident response firm Comae Technologies, tells Cyberscoop.





"Attribution can always be faked, as it"s only a matter of moving bytes around," he says.



As InfoRiskToday.com concludes ominously, the discovery of the cryptocurrency mining botnet shows that organizations that fail to patch their systems aren"t just at risk from flashy attacks, such as WannaCry, but also stealthier attacks that don"t always announce their presence.

Sunday, April 9, 2017

Hacker Group Releases Password To NSA's "Top Secret Arsenal" In Protest Of Trump Betrayal

Last August, the intel world was abuzz following the news that a previously unknown hacker collective, "The Shadow Brokers" had hacked and released legitimate hacking tools from the NSA"s own special-ops entity, the "Equation Group", with initial speculation emerging that the Russians may have penetrated the US spy agency as suggested by none other than Edward Snowden. The Shadow Brokers released a bunch of the organization"s hacking tools, and were asking for 1 million bitcoin (around $568 million at the time) to release more files, however failed to find a buyer.


Attention then shifted from Russians after some speculated that the agency itself may be housing another "mole" insider. At the time, a former NSA source told Motherboard, that “it’s plausible” that the leakers are actually a disgruntled insider, claiming that it’s easier to walk out of the NSA with a USB drive or a CD than hack its servers." As famed NSA whistleblower William Binney - who exposed the NSA"s pervasive surveillance of Americans long before Snowden confirmed it - said, “My colleagues and I are fairly certain that this was no hack, or group for that matter, This ‘Shadow Brokers’ character is one guy, an insider employee."


In a subsequent Reuters op-ed by cybersecurity expert James Bamford, author of The Shadow Factory: The Ultra-Secret NSA From 9/11 to the Eavesdropping on America, and columnist for Foreign Policy magazine, he said that seemed as the most probable explanation, and that Russia had nothing to do with this latest - and most provocative yet - hack.


Since then, the Shadow Broker group, whose origin and identity still remains a mystery, disappeared from the radar only to emerge today, when in an article posted on Medium, the group wrote an op-ed, much of it in broken English, in which it slammed Donald Trump"s betrayal of his core "base", and the recent attack on Syria, urging Trump to revert to his original promises and not be swept away by globalist and MIC interests, but far more imporantly, released the password which grants access to what Edward Snowden moments ago called the NSA"s "Top Secret arsenal of digital weapons."


The article begins with the group explaining why it is displeased with Trump.





Don’t Forget Your Base



Respectfully, what the fuck are you doing? TheShadowBrokers voted for you. TheShadowBrokers supports you. TheShadowBrokers is losing faith in you. Mr. Trump helping theshadowbrokers, helping you. Is appearing you are abandoning “your base”, “the movement”, and the peoples who getting you elected.



Good Evidence:



#1—Goldman Sach (TheGlobalists) and Military Industrial Intelligence Complex (MIIC) cabinet
#2—Backtracked on Obamacare
#3—Attacked the Freedom Causcus (TheMovement)
#4—Removed Bannon from the NSC
#5—Increased U.S. involvement in a foreign war (Syria Strike)



The peoples whose voted for you, voted against the Republican Party, the party that tried to destroying your character in the primaries. The peoples who voted for you, voted against the Democrat Party, the party that hates, mocks, and laughs at you. Without the support of the peoples who voted for you, what do you think will be happening to your Presidency? Without the support of the people who voted for you, do you think you’ll be still making America great again? Do you be remembering when you were sitting there at the Obama Press Party and they were all laughing at you? Do you be remembering when you touring the country and all those peoples believed in you and supported you? You were those peoples hope. How do you be thinking it will be feeling when those people turn on you? Will they be laughing at you, hating you, and mocking you too?



TheShadowBrokers doesn’t want this to be happening to you, Mr. Trump. TheShadowBrokers is wanting to see you succeed.



The hackers then ask Trump whose war is he fighting:





 If you made deal(s) be telling the peoples about them, peoples is appreciating transparency. But what kind of deal can be resulting in chemical weapons used in Syria, Mr. Bannon’s removal from the NSC, US military strike on Syria, and successful vote for SCOTUS without change rules? Mr. Trump whose war are you fighting? Israeli Nationalists’ (Zionist) and Goldman Sachs’ war? Chinese Globalists’ and Goldman Sachs war? Is not looking like you fighting the domestic wars, the movement elected you to be fighting. You not being in office three months and already you looking like the MIIC’s bitch with John McCain and Chuck Schumer double dutch ruddering each other in the corner over dead corpses.



The post continues by exposing what the ShadowBrokers believe is the general mindset of Trump"s support base:





Your Supporters:


  • Don’t care what is written in the NYT, Washington Post, or any newspaper, so just ignore it.

  • Don’t care if you swapped wives with Mr Putin, double down on it, “Putin is not just my firend he is my BFF”.

  • Don’t care if the election was hacked or rigged, celebrate it “so what if I did, what are you going to do about it”.

  • Don’t care if your popular or nice, get er done, Obama’s fail, thinking he could create compromise. No compromise.

  • Don’t want foreign wars, Do want domestic wars, “drain the swamp”, “destroy the nanny state”

  • Don’t care about your faith, you sound like a smuck when you try to say god things

  • DO support the ideologies and policies of Steve Bannon, Anti-Globalism, Anti-Socialism, Nationalism, Isolationism


In the article, the ShadowBrokers also touch upon what until recently was the primary topic of the daily news cycle, namely the whether Russia is behind this (and any other black hat intel hacking operation):





For peoples still being confused about TheShadowBrokers and Russia. If theshadowbrokers being Russian don’t you think we’d be in all those U.S. government reports on Russian hacking? TheShadowBrokers isn’t not fans of Russia or Putin but “The enemy of my enemy is my friend.” We recognize Americans’ having more in common with Russians than Chinese or Globalist or Socialist. Russia and Putin are nationalist and enemies of the Globalist, examples: NATO encroachment and Ukraine conflict. Therefore Russia and Putin are being best allies until the common enemies are defeated and America is great again.



The report than goes on to suggest that the hacking group is in fact comprised mostly of former US spies: "President Trump, theshadowbrokers is offering our services to you and your administration. Did you know most of theshadowbrokers’ members have taken the oath “…to protect and defend the constitution of the United States against all enemies foreign and domestic…”. Yes sir! Most of us used to be TheDeepState everyone is talking about."


Then something changed, and the collective notes that "TheDeepState is being the enemy of the constitution, individualism, life, liberty, and the pursuit of happiness. With the right funding we can recruit some of the best hacker intel peoples in United States and world. “Unmasking” is being new buzz word, so we use. TheShadowBrokers is being happy to unmask anyone we considering to be an enemy of the Constitution of the United States."





Enemies like John McCain. Something doesn’t rub theshadowbrokers rite about Vietnam War POW who at every opportunity seeks to do violence to others via the proxy of young service men and women. If anyone should be being pacifist, slow to pick fight it should be being former POW. TheShadowBrokers is sure if we “unmasking”, Senator McCain, Magog itself might come out, many defense contractors, Saudi Princes, and possibly little Vietnamese boy he shares with Senator Lindsey Graham, not cool! Mr. Trump we know you are having DOJ and FBI, so why you be needing theShadowBrokers? You don’t, but theshadowbrokers is confused. Why haven’t you served search warrant to NYT, Washington Post, Goldman Sacks, Jeff Bezos, and all other Globalist for investigation and prosecution of treason, sedition, and un-American activities during a time of war? The



It was the conclusion to the post, however, that was most interesting - in it the Shadow Brokers urges Trump to be the "real deal" and has released the password to the NSA hacking tool binaries that made so much news last summer:





Mr. President Trump theshadowbrokers sincerely is hoping you are being the real deal and that you received this as constructive criticism toward #MAGA. Some American’s consider or maybe considering TheShadowBrokers traitors. We disagreeing. We view this as keeping our oath to protect and defend against enemies foreign and domestic. TheShadowBrokers wishes we could be doing more, but revolutions/civil wars taking money, time, and people. TheShadowBrokers has is having little of each as our auction was an apparent failure. Be considering this our form of protest. The password for the EQGRP-Auction-Files is CrDj”(;Va.*NdlnzB9M?@K2)#>deB7mN



Shortly after the blog post hit, Wikileaks noticed:



Even Edward Snowden got involved







As per Wikileaks, the released information include "browsable decrypted Shadow Brokers "NSA" hacking tools+docs files corresponding to password released today", and that "Hundreds of NSA cyber weapons variants publicly released including code showing hacking of Pakistan mobile system"




The github depository of the released code can be found here.



Other hackers organizations confirm, the key released by the ShadowBrokers has been verified:



Inside the NSA dump among many other findings, we find hundreds of NSA attacks on China, as well as penetration attempts in which the NSA "pretends" to be China so one wonders how difficult it would be for the NSA to pretend they are, oh, say Russia?


Additionally, today"s revelation exposes hacking attacks on EU states, as well as Latin America, Russia, China, Japan and South East Asia.  Among the contents one also finds the hacking configuration for China Mobile, the world"s largest mobile telecom company by number of subscribers (just under 900 million) and market cap.


Another example shows the NSA"s EquationGroup tool (ELECTRICSLIDE) impersonating a Chinese browser with fake Accept-Language.



We are in the process of further exploring the disclosed data, and will present any notable revelations in due course, however we find it quite interesting that now that the "rogue" element in the intel community appears to have given up on Trump, they are bypassing the president and taking their war with the "deep state" directly to the people.


Finally, a rhetorical question from Julian Assange on today"s revelations: