WEBVTT

00:00.990 --> 00:04.890
It's time for another ethical hacking in the headlines.

00:05.310 --> 00:12.210
It's time for us to talk about one of the most sophisticated attacks of all time.

00:12.630 --> 00:14.970
It's the SolarWinds attack of 2020.

00:15.450 --> 00:15.870
No.

00:16.040 --> 00:17.670
Wasn't the most devastating.

00:17.700 --> 00:19.440
We'll talk about that one later on.

00:19.740 --> 00:22.350
But it was one of the most interesting.

00:22.560 --> 00:30.840
And some say one of the most, if not the most creative and elegant.

00:31.290 --> 00:32.160
Let's talk about it.

00:32.940 --> 00:43.230
So SolarWinds in 2020 was just going about their everyday business and they were rolling out an update

00:43.230 --> 00:50.250
to a popular application that they have four monitoring networks called Orion.

00:50.850 --> 00:53.030
Yeah, monitoring networks and their nodes.

00:53.040 --> 00:57.630
So this is software that does real good for a whole bunch of companies.

00:58.410 --> 01:08.010
So they deliver the update and the update is installed and any machines that had this update installed

01:08.430 --> 01:10.710
that had Internet connectivity.

01:10.830 --> 01:16.500
And as you might guess, this was an awful lot of machines were subject to the malware.

01:16.770 --> 01:17.670
How did this happen?

01:18.180 --> 01:27.150
Well, as incredible as this sounds, the hackers got their malicious code into the distro.

01:27.600 --> 01:28.080
That's right.

01:28.080 --> 01:31.350
This is a true distribution style of attack.

01:31.800 --> 01:39.120
Yeah, they got their code, their malicious code into the update that was sent out by SolarWinds.

01:39.540 --> 01:40.590
Oh, my gosh.

01:40.600 --> 01:44.340
Think of how incredibly sophisticated that is.

01:44.850 --> 01:53.490
They had to fool the software repository, the get system, and I mean, they had all these kinds of

01:54.330 --> 02:03.810
elements in play so that they could take their code and get it in the code of the product and then have

02:03.810 --> 02:04.650
it distributed.

02:05.050 --> 02:06.390
Incredible.

02:06.870 --> 02:11.130
100 companies, it is estimated, were impacted.

02:11.340 --> 02:19.500
12 of those were government agencies, including, embarrassingly, the Cybersecurity and Infrastructure

02:19.500 --> 02:20.940
Security Agency.

02:21.240 --> 02:25.200
So Sisa was one of the many agencies affected.

02:25.920 --> 02:27.950
I'd say 100 companies were affected.

02:27.960 --> 02:29.580
That's what we know of.

02:29.760 --> 02:31.590
And some of those were big.

02:32.040 --> 02:35.250
Intel, Cisco, Microsoft.

02:35.700 --> 02:36.240
Yikes.

02:36.690 --> 02:39.420
So this was quite the attack.

02:40.230 --> 02:48.480
In fact, there were a lot of folks mobilizing on this one because it was feared that this would be

02:48.480 --> 02:50.880
another attack on the scale of not Petya.

02:51.150 --> 02:57.150
We will talk about the attack in an upcoming Ethical Hacking in the Headlines segment.

02:58.020 --> 03:05.340
Now let's talk a little bit more about just how stealthy and clever this all wants.

03:06.150 --> 03:12.120
They had nine months of access to the compromised systems.

03:12.750 --> 03:16.950
It does not appear they did any damage anywhere.

03:17.070 --> 03:20.760
But can you imagine the amount of reconnaissance that was done?

03:21.420 --> 03:29.370
The other thing, the biggest fear about this is if they successfully got their malicious code into

03:29.370 --> 03:37.110
that software, what software updates out there are waiting to release their damaging payload.

03:37.230 --> 03:37.770
Yikes.

03:38.010 --> 03:41.010
So that's a huge concern about this attack.

03:41.940 --> 03:46.230
They modified the sealed software code.

03:46.230 --> 03:49.050
Again, that's one of the amazing things about this.

03:49.380 --> 03:57.240
And in fact, they even engineered their own system for selecting the targets of the attack.

03:57.270 --> 03:59.940
That's why Internet access was required.

04:00.270 --> 04:06.930
And one of the things they did incredibly well to cover their tracks is that the functioning of the

04:06.930 --> 04:13.380
malware mimicked the Orion protocols that are used in the actual application.

04:13.710 --> 04:22.470
So everything that was occurring by the malware looked all completely normal to SolarWinds and SolarWinds

04:22.470 --> 04:23.160
customers.

04:23.640 --> 04:32.400
They also took great pains to close back doors up and just do everything they could to very effectively

04:32.400 --> 04:34.590
make sure all of their tracks were removed.

04:35.590 --> 04:46.150
All of this now we know, stems back to September 12th, 2019, when they successfully these Russian

04:46.150 --> 04:49.240
hackers believed to be Russian hackers.

04:49.600 --> 04:57.700
In September 12th of 2019, they got a harmless sample code into Orion.

04:57.910 --> 05:00.220
Yeah, that was discovered after the fact.

05:00.460 --> 05:02.500
So think of how clever they were.

05:03.040 --> 05:08.170
They did a little piece of non malicious test code.

05:08.500 --> 05:11.610
They got that into the Orion product.

05:11.620 --> 05:15.880
That was their proof of concept back in September 12th, 2019.

05:16.570 --> 05:23.020
And then they waited five months while they perfected the code they ended up injecting.

05:23.470 --> 05:31.480
So what a slow, methodical, elegant, sophisticated attack.

05:31.690 --> 05:38.650
And it's one that is often studied now, because this is absolutely something that we need to guard

05:38.650 --> 05:44.740
against where we're having updates that might contain malicious code.

05:44.920 --> 05:47.530
My goodness, that is a nightmare.

05:47.800 --> 05:48.590
Think about it.

05:48.760 --> 05:55.060
We're stressed enough when we apply updates because we don't want those updates to inadvertently knock

05:55.060 --> 05:56.860
out services we might rely on.

05:56.890 --> 06:00.910
I mean, we get stressed enough when it comes to updates failing.

06:01.120 --> 06:07.810
We don't need the fear of malicious code in these sealed, digitally sealed updates.

06:08.920 --> 06:10.450
Well, all right.

06:10.450 --> 06:16.060
I want to thank you so much for joining me for this episode of Ethical Hacking in the Headlines.

06:16.090 --> 06:24.550
It's always great to study what's really going on outside of academia, and we learn that all this academia

06:24.550 --> 06:30.910
pays off because it is the very techniques that we're discussing that are employed.

06:31.780 --> 06:32.800
Thanks so much for watching.
