- Bug lets Twitter save your DMs—even after you delete them Friday 7:21 PM
- Guy mansplains song to Japanese Breakfast, the female artist who wrote the song Friday 6:38 PM
- Ann Coulter’s Twitter bio links to a vulgar parody account Friday 5:22 PM
- Popular YouTube music channel gets income yanked for ‘repetitious’ content Friday 4:14 PM
- New website will endlessly generate fake faces thanks to AI Friday 3:41 PM
- Man fakes getting stood up at Outback Steakhouse Friday 3:03 PM
- FCC looks to tackle robocalls and spoofed texts Friday 2:57 PM
- How to protect yourself from the data breach that affected 744 million accounts Friday 12:56 PM
- How to stream Rob Brant vs. Khasan Baysangurov online for free Friday 12:21 PM
- No, Ocasio-Cortez doesn’t have her boyfriend on her payroll Friday 12:20 PM
- Writers want this book canceled for misgendering its protagonist Friday 12:15 PM
- Trump Jr’s meme about his dad’s border wall doesn’t get how Congress works Friday 11:44 AM
- FBI reportedly looking into Ryan Adams’ communications with underage girl Friday 11:25 AM
- Trump does Chinese accent, declares national emergency, bewilders the internet Friday 11:21 AM
- Chrissy Teigen throws shade at Logan Paul-Kaitlin Bennett pairing Friday 10:48 AM
Cybersecurity firm ‘highly confident’ Russian military hacked DNC based on new evidence
The malware has been traced to previous attacks in Ukraine.
CrowdStrike, a California-based cybersecurity firm, now says it is confident that the group who hacked the Democratic National Committee this summer has direct ties to the Kremlin.
The firm was hired by the Democratic Party this summer to investigate an attack that exposed thousands of embarrassing emails, through WikiLeaks and other online outlets, which raised ethical questions about how the party was overseeing its presidential primary election.
Prior to its nominating convention, party leaders were pelted with accusations that the DNC had worked to undermine the campaign of Sen. Bernie Sanders (D-Vt). Ultimately, the scandal led the DNC’s chair, Rep. Debbie Wasserman Schultz (D-Fla.), to resign.
CrowdStrike now claims to have nearly incontrovertible proof that the malware used in the DNC intrusion also helped the attackers break into an Android app used by the Ukrainian field artillery units from late 2014 through 2016.
The malware is said to have been spread by way of Ukrainian military forums “within a legitimate Android application developed by Ukrainian artillery officer Yaroslav Sherstuk.” The purpose of the Sherstuk’s app was to help artillery forces “more rapidly process targeting data for the Soviet-era D-30 Howitzer” used by the Ukrainian forces. More than 9,000 artillery personnel are reported to use the application, according to CrowdStrike, citing press reports.
CrowdStrike co-founder Dmitri Alperovitch told the Washington Post that the firm now has “high confidence” that the unit responsible for hacking the DNC works for the GRU, Russia’s military intelligence service. The hacking group responsible CrowdStrike has dubbed “Fancy Bear.”
Attribution with regards to cyberattacks is difficult and often problematic.
Cybersecurity expert Jeffrey Carr, the founder of Taia Global, raised concerns this summer about the process of attributing the attack to Moscow based solely on the origin of the malware involved.
Of course, malware can be stolen; it can be re-packaged and sold on the black market; and it can be used as well to throw off investigators.
“In the physical world of crime investigation,” Carr wrote, “common sense dictates that the perpetrator of a crime may use any weapon and not just one made in the country of his birth, and that the developer or manufacturer of the weapon most likely isn’t the criminal. And yet, those seemingly crazy assumptions are made every day by cybersecurity companies involved in incident response and threat intelligence.”
“The malware was written in Russian? It was a Russian who attacked you,” continued Carr, sardonically. “Chinese characters in the code? You’ve been hacked by the Peoples Liberation Army.”
Dell Cameron was a reporter at the Daily Dot who covered security and politics. In 2015, he revealed the existence of an American hacker on the U.S. government's terrorist watchlist. He is a co-author of the Sabu Files, an award-nominated investigation into the FBI's use of cyber-informants. He became a staff writer at Gizmodo in 2017.