Shadow Brokers investigation is focusing on former NSA insider
Full article721 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The probe includes the threat of a current intelligence community employee being connected to the Shadow Brokers, who have leaked NSA tools over the past year.
The U.S. government’s counterintelligence investigation into the so-called Shadow Brokers group is currently focused on a former U.S. intelligence community insider, multiple people familiar with the matter told CyberScoop.
Sources tell CyberScoop that former NSA employees have been contacted by investigators in the probe to discover how a bevy of elite computer hacking tools fell into the Shadow Brokers’ possession.
Those sources asked for anonymity due to the sensitive nature of this investigation.
While investigators believe that a former insider is involved, the expansive probe also spans other possibilities, including the threat of a current intelligence community employee being connected to the mysterious group.
The investigatory effort is being led by a combination of professionals from the FBI, National Counterintelligence and Security Center (NCSC), and NSA’s internal policing group known as Q Group, among other offices.
It’s not clear if the former insider was once a contractor or in-house employee of the secretive agency. Two people familiar with the matter said the investigation “goes beyond” Harold Martin, the former Booz Allen Hamilton contractor who is currently facing charges for taking troves of classified material outside a secure environment.
The NSA did not respond to multiple requests for comment.
The Shadow Brokers are an enigmatic group that has been publishing classified documents and the code for computer exploits once used by the agency. As the exploits have been released, they have been co-opted into worldwide attacks, including the WannaCry ransomware attack in May.
Security experts have theorized over the last year that the Shadow Brokers are hackers who broke into a faulty NSA attack server to steal tools and other secretive information. This remains a possibility, but it does not explain why the group was able to publish an internal powerpoint presentation, which would not be stored on such a system, former U.S. intelligence officials tell CyberScoop.
Others have claimed the operation carries certain hallmarks indicative of a nation state, like Russia, who are conceivably trying to discredit or damage the U.S. intelligence community by sharing — and therefore burning — certain cyber espionage capabilities.
After nearly a year in the limelight, the Shadow Brokers’ behavior has changed somewhat in recent months. Although many of the group’s messages appear relatively similar, the manner in which they are sharing classified information has shifted.
On Thursday, the Shadow Brokers advertised, once again, a subscription service where they would share additional NSA hacking tools with those who are willing to pay thousands of dollars for access.
Rep. Will Hurd, R-Texas, said in a recent phone interview with CyberScoop, that “understanding what’s happened” is a “serious priority” for the intelligence community and House Intelligence Committee, for which he is a member of. Hurd is one of the only lawmakers to publicly comment on the group. Congress has largely chosen to remain silent on the issue, which now spans almost a year of leaks and other involuntary disclosures of classified information.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/shadow-brokers-investigation-nsa-former-insider-fbi-q-group/