Some comments regarding what's been posted here regarding the recent SolarWinds cyberattack. I am most definitely not an expert in these matters; but have read some of what people who are experts have written.
-
Who did it and the methods employed for attribution of the attack to Russia: No—it wasn't based on anything as simple as tracing an IP address. Those were faked and appeared as legitimate trusted IP addresses that each of the individually hacked networks used routinely. The attribution is based on things previously observed from known sources of attack, such as: techniques used; established methods and tactics of intrusion, code deployment, and detection evasion; the operational capabilities required and displayed in those things previously mentioned; and examination of the embedded malicious code for fingerprints or traces of known code attributes which point to a specific source. Expert cybersecurity investigators, in both the private and government sectors, say this hack points to a very specific Russian government actor. It was first detected by FireEye, a prominent global cybersecurity company, who was itself attacked and compromised.
-
Who was targeted:
First, companies that are a major part of the infrastructure backbone of network communication and security. Among the initial targets were major companies in the supply of widely used products for building secure networks: SolarWinds (systems management and monitoring for networks and security); FireEye (cybersecurity and network protection); and Microsoft (network systems and security applications). Those targets and more were not just penetrated; they had products and services infected with malicious code and/or cybersecurity defense, detection tools, and methods compromised.
This went on for several months before being detected. SolarWinds was the entry point for infecting the other initial targets because their products and services are so widely used that it enabled intrusion across the supply chain of other critical network component suppliers.
-
Why they were the first targets: The first companies targeted are part of a chain of trusted network links that form a security foundation relied on for day-to-day network operations across a landscape of businesses, institutions, and government agencies. They are used both for local network control and security and trusted secure network communication between those entities. FireEye, for example, provides cybersecurity software and services for cloud services, financial services, government, healthcare, and industrial control infrastructure.
-
Second stage targets: Critical businesses and institutions that utilize and rely on the products and services from the first stage targets for their network integrity and communications.
-
Classified government information: There is no indication or likelihood that any highly classified government documents were the target of the attack. Highly classified government information isn't stored in ways that are vulnerable to internet intrusion for obvious reasons. Lower levels of confidential information would have lower levels of security. For the higher classification levels a human source inside an agency would be needed for any espionage attempts.
-
The purpose and what information was obtained: It's still too early to tell. Given what is known it would appear to be a project that successfully obtained intrusion, knowledge, and insight into a framework of common cybersecurity and network infrastructure across very specific sectors and targets. Beyond that, it will take months of investigation to determine what was accessed and gather together detailed information on the specifics of the attack. Some of this may not be revealed publicly for a very long time due to security concerns of the companies and agencies involved or to avoid adverse publicity.
-
Why it's of concern: First, the breadth and depth of the attack. Second, that it remained undetected for so long. Third, the narrowly focused targets of the attack. This was not your ordinary front door cyberattack on a single network to obtain some trade secrets or financial gain. It was specifically targeted at critical network security components and the companies that provide them to other companies and institutions, who rely on them as part of their network infrastructure for day-to-day operations.
https://arstechnica.com/information-technology/2020/12/russias-hacking-frenzy-is-a-reckoning/The longer range goal of the attack, though still not clear, is still concerning. Russia has been stepping up their abilities to undermine essential infrastructures as illustrated in this article.
https://www.wired.com/story/russian-hackers-attack-ukraine/How an Entire Nation Became Russia's Test Lab for Cyberwar. Blackouts in Ukraine were just a trial run. Russian hackers are learning to sabotage infrastructure and the US could be next.