Rechercher dans ce blog

Sunday, December 13, 2020

US Commerce, Treasury Hit in Network Intrusions - BankInfoSecurity.com

3rd Party Risk Management , Critical Infrastructure Security , Cyberwarfare / Nation-State Attacks

FireEye Finds Trojanized Software Updates in SolarWinds' Orion Product
US Commerce, Treasury Hit in Network Intrusions
The U.S. Treasury. (Sealy J. via Wikipedia/CC)

Network intrusions at the U.S. Commerce department, the U.S. Treasury and FireEye appeared to be linked to tampered software updates for a network monitoring product called Orion, made by SolarWinds.

See Also: The SASE Model: A New Approach to Security

On Sunday, the U.S. Commerce Department confirmed it had been targeted by hackers, and the U.S. Treasury has also reportedly been struck.

Reuters first reported the incidents, with the Washington Post suggesting that a Russian group known as Cozy Bear, or APT29, is the source.

The Post reported last week the same group was behind an attack against computer security firm FireEye (see FireEye Says Nation-State Attackers Stole Pen Test Tools).

In an update late Sunday, FireEye warned that software updates for SolarWinds' Orion product had been subverted with backdoors it dubbed SUNBURST. The malicious software updates, which were signed with valid digital signatures, could steal files, profile systems and disable system services.

FireEye warned that "the actors behind this campaign gained access to numerous public and private organizations around the world."

The Commerce Department says "we can confirm there has been a breach in one of our bureaus. We have asked CISA [Cybersecurity Infrastructure and Security Agency] and the FBI to investigate, and we cannot comment further at this time."

The Post reports that the National Telecommunications and Information Administration (NTIA), which advises the president on telecommunications issues, was also attacked. Reuters reports the attacks are considered so serious that the National Security Council held an emergency meeting on Saturday.

SolarWinds Connection

Aspects of the attacks are unclear, such as exactly what the attackers stole and the immediate impacts to U.S. national security. The New York Times reports that the attackers had access the Treasury and Commerce department's email systems.

On Sunday, SolarWinds disclosed that it is investigating a "potential vulnerability" that may be linked to software updates for its Orion network monitoring platform. The updates were released between March and June, according to a statement. It also mentioned FireEye.

SolarWinds was relisted on the New York Stock Exchange in 2018. (Source: SolarWinds).

"We believe that this vulnerability is the result of a highly-sophisticated, targeted and manual supply chain attack by a nation state," SolarWinds says. "We are acting in close coordination with FireEye, the Federal Bureau of Investigation, the intelligence community and other law enforcement to investigate these matters. As such, we are limited as to what we can share at this time."

FireEye's description of the attack meant that organizations using SolarWinds' software would have had little defense against being infected. Software updates are "signed" using public key cryptography, and updates that contain invalid keys would not be accepted. But tampered software that has a valid key would pass.

The key that generates that signature is a closely guarded secret. FireEye's post means that the attackers have somehow gained deep access into SolarWinds' software signing infrastructure.

FireEye published this example of a tampered SolarWinds software update that carried a valid digital signature. (Source: FireEye)

This type of software supply chain attack has been used to devastating effect before. The NotPetya ransomware attack of 2017 started when software updates for accounting software called M.E. Doc were altered with backdoors (see NotPetya Patient Zero: Ukrainian Accounting Software Vendor).

The backdoor in Orion is stealthy and lays dormant for about two weeks. To hide its network traffic, it uses a protocol native to Orion's software called the Orion Improvement Program. It also "reconnaissance results within legitimate plugin configuration files allowing it to blend in with legitimate SolarWinds activity," FireEye says.

The attackers also took great care to avoid detection. They chose IP addresses in the same country as their victims when remotely accessing their victims' systems. FireEye says they also set hostnames on their command and control infrastructure to match a legitimate hostname within victims' infrastructure. Also, they would use valid login credentials once inside systems, which again is a method to avoid detection.

Attack Impact

The attack again SolarWinds will send a shiver through the IT security community and could have far-ranging consequences depending on how many organizations have been infected.

The company is a popular managed service provider that provides a range of tools and services for organizations to manage their IT infrastructure. Information security experts often warn of the danger and power of supply-chain attacks that leverage widely-used software components or products.

According to its website, SolarWinds customers include the five branches of the U.S. military, the Pentagon, State Department, NASA, NSA, Postal Service, NOAA, the Justice Department and the White House. It also serves hundreds of other large companies, including 425 of the Fortune 500 companies.

Its Orion platform is a way for IT shops to pull data from various systems and display it one console. They're also used to control those systems.

SolarWinds' products have administrative access to organization's networks, tweets Dmitri Alperovitch, the co-founder and former CTO of the computer security company CrowdStrike.

"Monday may be a bad day for lots of security teams," Alperovitch writes.

Network management systems such as Orion are prime targets for attackers since they may have access to all systems on a network, writes Jake Williams, a former operator with the National Security Agency and founder of the Atlanta-based security company Rendition Infosec, in a Twitter thread.

Even if a network management system only has read access, attackers that control one can still use it "to read configurations, which often include enough information for attackers to laterally move to those systems," he writes.

Williams advises that companies using network management software should closely monitor access to administrator interfaces and traffic going into the system. Indicators-of-compromise, which are forensic clues about attacks, should be released for the latest attacks within a few weeks. He warned that illicit access is serious.

"I'll close by reiterating that hitting an NMS like SolarWinds often gives attackers keys to the kingdom," Williams writes. "It's like domain admin++."

Investigation Underway

CISA says in a statement "we have been working closely with our agency partners regarding recently discovered activity on government networks."

"CISA is providing technical assistance to affected entities as they work to identify and mitigate any potential compromises," it says.

The intrusions come at a fragile and unstable time for the U.S., which is facing a dangerous surge in coronavirus cases and navigating a rocky presidential transition.

President Donald Trump's efforts to overturn the election on unverified claims of fraud have met repeated defeat in the court. A lawsuit by Texas against four other states that aimed to throw out election results was unanimously rejected by the Supreme Court on Friday.

Further, Trump fired former CISA Director Christopher Krebs in November after claiming Krebs made false statements regarding the election. Krebs, as well as other government agencies and election officials, said the U.S. election was the most secure one ever held (see Analysis: Does Krebs' Firing Leave US Vulnerable to Attack?).

The election was free from successful cyberattacks, but experts have long kept a close on Cozy Bear. Cozy Bear is believed to be affiliated with Russia's SVR intelligence service. A long list of intrusions have been linked to Cozy Bear, including against Democratic National Committee officials in 2016.

In July, the U.S., U.K. and Canada also accused the group of targeting agencies and companies involved in Covid-19 research (see APT Groups Target Firms Working on COVID-19 Vaccines).

Let's block ads! (Why?)



"network" - Google News
December 14, 2020 at 10:33AM
https://ift.tt/3mfSr6v

US Commerce, Treasury Hit in Network Intrusions - BankInfoSecurity.com
"network" - Google News
https://ift.tt/2v9ojEM
Shoes Man Tutorial
Pos News Update
Meme Update
Korean Entertainment News
Japan News Update

No comments:

Post a Comment

Search

Featured Post

Comcast reluctantly agrees to stop its misleading “10G Network” claims - Ars Technica

Enlarge Comcast Comcast has reluctantly agreed to discontinue its "Xfinity 10G Network" brand name after losing an appeal of...

Postingan Populer