Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits
Full article876 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
After "going dark" in January, the group released a password Saturday that unlocks a full suite of exploits.
The Shadow Brokers, the mysterious group linked to exploits stolen from the National Security Agency, released a large catalog of files Saturday that give further insight into the elite spy agency’s hacking methods.
In a lengthy blog post on Medium, the group reveals a password that unlocks an encrypted folder full of files the group previously tried to sell in an online auction. The group says the motive for unlocking the files is disappointment with the actions of President Donald Trump since he assumed office, including missile strikes on a Syrian air base earlier this week.
“TheShadowBrokers doesn’t want this to be happening to you, Mr. Trump,” the group wrote in the rambling, grammatically poor post. “TheShadowBrokers is wanting to see you succeed. TheShadowBrokers is wanting America to be great again. TheShadowBrokers acknowledging, we don’t be having all the inside information you do, things might look different inside the bubble. TheShadowBrokers is having suggestion. Maybe you be making YouTube video is in order, to be explaining to your voters, your supporters, you didn’t f*** them all over. Because from theshadowbrokers seat is looking really bad.”
Security researchers have started poring over the files, with many saying on Twitter that some date back as far as the 1990s. The catalog’s exploits look to primarily focus on Linux.
https://twitter.com/osxreverser/status/850682774398922752
https://twitter.com/osxreverser/status/850686589130985473
This is the most "single target" exploit I have ever seen in the wild (OK, sort of wild)… Linux on DEC Alpha… 10 machines worldwide? https://t.co/woml2xrXi9
— Arrigo Triulzi (@cynicalsecurity) April 8, 2017
Prominent NSA whistleblower Edward Snowden said the files fall short of the agency’s full exploit catalog, and should be filled with clues that give investigators a better idea of the leak’s origin.
…much here that NSA should be able to instantly identify where this set came from and how they lost it. If they can't, it's a scandal.
— Edward Snowden (@Snowden) April 8, 2017
Previously, The Shadow Brokers had tried to auction this catalog of exploits for roughly $7,070,300 in bitcoin. The most the group received was $9,000 earlier this year.
The dump is the first since the group released a trove of active Microsoft Windows software exploits in January. That release accompanied a farewell message, in which the group claimed they were “making [an] exit” and “going dark.”
The Shadow Brokers first came to light last August when downloadable samples of exploit code were posted on several websites, detailing a series offensive cyber tools reportedly once used by the Equation Group, a cadre that has been linked to the NSA.
After the initial leak, the FBI arrested former NSA contractor Harold Martin for stealing an immense trove of classified material. Martin allegedly stole more than 50 terabytes worth of data over the course of two decades while working for both the NSA and Office of the Director of National Intelligence, or ODNI.
Martin is one of the prime suspects behind the Shadow Brokers case, but direct connection between Martin and the mysterious group remains unclear.
The Shadow Brokers leak comes less than 24 hours after WikiLeaks released another entry in their #Vault7 series, which contained documents from the CIA’s Grasshopper framework, a platform used to build customized malware payloads for Microsoft Windows operating systems.
More Scoops
Chinese researchers accuse NSA of being behind a powerful exploit
Chinese researchers are stepping up their attribution game.
Chinese hackers stole another NSA-linked hacking tool, research finds
After Assange indictment, DDoSecrets publishes old WikiLeaks chats, strategy sessions
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/shadow-brokers-linux-nsa-donald-trump-syria/