ZeroHour
CyberScooppublished ()ingested @gregotto

Shadow Brokers re-emerge, drop large catalog of stolen NSA exploits

criticalExploit / PoC exploited in the wildimportance 60
Full article876 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

After "going dark" in January, the group released a password Saturday that unlocks a full suite of exploits.

(Getty Images)

The Shadow Brokers, the mysterious group linked to exploits stolen from the National Security Agency, released a large catalog of files Saturday that give further insight into the elite spy agency’s hacking methods.

In a lengthy blog post on Medium, the group reveals a password that unlocks an encrypted folder full of files the group previously tried to sell in an online auction. The group says the motive for unlocking the files is disappointment with the actions of President Donald Trump since he assumed office, including missile strikes on a Syrian air base earlier this week.

“TheShadowBrokers doesn’t want this to be happening to you, Mr. Trump,” the group wrote in the rambling, grammatically poor post. “TheShadowBrokers is wanting to see you succeed. TheShadowBrokers is wanting America to be great again. TheShadowBrokers acknowledging, we don’t be having all the inside information you do, things might look different inside the bubble. TheShadowBrokers is having suggestion. Maybe you be making YouTube video is in order, to be explaining to your voters, your supporters, you didn’t f*** them all over. Because from theshadowbrokers seat is looking really bad.”

Security researchers have started poring over the files, with many saying on Twitter that some date back as far as the 1990s. The catalog’s exploits look to primarily focus on Linux.

https://twitter.com/osxreverser/status/850682774398922752

https://twitter.com/osxreverser/status/850686589130985473

This is the most "single target" exploit I have ever seen in the wild (OK, sort of wild)… Linux on DEC Alpha… 10 machines worldwide? https://t.co/woml2xrXi9

— Arrigo Triulzi (@cynicalsecurity) April 8, 2017

Prominent NSA whistleblower Edward Snowden said the files fall short of the agency’s full exploit catalog, and should be filled with clues that give investigators a better idea of the leak’s origin.

…much here that NSA should be able to instantly identify where this set came from and how they lost it. If they can't, it's a scandal.

— Edward Snowden (@Snowden) April 8, 2017

Previously, The Shadow Brokers had tried to auction this catalog of exploits for roughly $7,070,300 in bitcoin. The most the group received was $9,000 earlier this year.

The dump is the first since the group released a trove of active Microsoft Windows software exploits in January. That release accompanied a farewell message, in which the group claimed they were “making [an] exit” and “going dark.”

The Shadow Brokers first came to light last August when downloadable samples of exploit code were posted on several websites, detailing a series offensive cyber tools reportedly once used by the Equation Group, a cadre that has been linked to the NSA.

After the initial leak, the FBI arrested former NSA contractor Harold Martin for stealing an immense trove of classified material. Martin allegedly stole more than 50 terabytes worth of data over the course of two decades while working for both the NSA and Office of the Director of National Intelligence, or ODNI.

Martin is one of the prime suspects behind the Shadow Brokers case, but direct connection between Martin and the mysterious group remains unclear.

The Shadow Brokers leak comes less than 24 hours after WikiLeaks released another entry in their #Vault7 series, which contained documents from the CIA’s Grasshopper framework, a platform used to build customized malware payloads for Microsoft Windows operating systems.

More Scoops

A sign for the National Security Agency (NSA), U.S. Cyber Command and Central Security Service, is seen near the visitor’s entrance to the headquarters of the NSA at the entrance in Fort Meade, Maryland, February 14, 2018. (Photo by SAUL LOEB/AFP via Getty Images)

Chinese researchers accuse NSA of being behind a powerful exploit

Chinese researchers are stepping up their attribution game.

NSA, National Security Agency, RSA 2019, china nsa hacking tools, NSA cybersecurity directorate, ghidra vulnerability
(Scoop News Group photo)

Chinese hackers stole another NSA-linked hacking tool, research finds

Julian Assange protest
A sign at a protest in support of Julian Assange outside the British Consulate in New York City, Feb. 24, 2020. (Pamela Drew / Flickr)

After Assange indictment, DDoSecrets publishes old WikiLeaks chats, strategy sessions

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/shadow-brokers-linux-nsa-donald-trump-syria/