Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

FBI Says a Mysterious Hacking Group Has Had Access to US Govt Files for Years
Motherboard ^ | 04/04/2016 | Lorenzo Franceschi-Bicchierai

Posted on 04/12/2016 2:26:50 PM PDT by unixfox

The feds warned that “a group of malicious cyber actors,” whom security experts believe to be the government-sponsored hacking group known as APT6, “have compromised and stolen sensitive information from various government and commercial networks” since at least 2011, according to an FBI alert obtained by Motherboard.

The alert, which is also available online, shows that foreign government hackers are still successfully hacking and stealing data from US government’s servers, their activities going unnoticed for years. This comes months after the US government revealed that a group of hackers, widely believed to be working for the Chinese government, had for more than a year infiltrated the computer systems of the Office of Personnel Management, or OPM. In the process, they stole highly sensitive data about several millions of government workers and even spies.

In the alert, the FBI lists a long series of websites used as command and control servers to launch phishing attacks “in furtherance of computer network exploitation (CNE) activities [read: hacking] in the United States and abroad since at least 2011.”

Domains controlled by the hackers were “suspended” as of late December 2015, according to the alert, but it’s unclear if the hackers have been pushed out or they are still inside the hacked networks.

“Anybody who’s been in that network all this long, they could be anywhere and everywhere.”

“Looks like they were in for years before they were caught, god knows where they are,” Michael Adams, an information security expert who served more than two decades in the US Special Operations Command, and who has reviewed the alert, told Motherboard. “Anybody who’s been in that network all this long, they could be anywhere and everywhere.”

For Adams, this alert shows that the US government still is not in control of what’s going on inside its most sensitive networks. This alert, he said, is an admission of that.

“It’s just flabbergasting,” he told me. “How many times can this keep happening before we finally realize we’re screwed?”

The FBI wouldn’t comment on the alert, only saying that it was just another example of a routine notice to private partners, “provided in order to help systems administrators guard against the actions of persistent cyber criminals.”

This group of “persistent cyber criminals” is especially persistent. The group is none other than the “APT6” hacking group, according to sources within the antivirus and threat intelligence industry. There isn’t much public literature about the group, other than a couple of old reports, but APT6, which stand for Advanced Persistent Threat 6, is a codename given to a group believed to be working for the Chinese government.

“This is one of the earlier APTs, they definitely go back further than 2011 [...] more like 2008.”

“This is one of the earlier APTs, they definitely go back further than 2011 or whatever—more like 2008 I believe,” Kurt Baumgartner, a researcher at the Russian security firm Kaspersky Lab, told me. (Baumgartner declined to say whether the group was Chinese or not, but said its targets align with the interest of a state-sponsored attacker.)

Kyrk Storer, a spokesperson with FireEye, confirmed that the domains listed in the alert “were associated with APT6 and one of their malware backdoors,” and that the hackers “targeted the US and UK defense industrial base.”

APT6 is ”likely a nation-state sponsored group based in China,” according to FireEye, which ”has been dormant for the past several years.”

Another researcher at a different security company, who spoke on condition of anonymity because he wasn’t authorized to speak publicly about the hacker’s activities, said this was the “current campaign of an older group,” and said there “likely” was an FBI investigation ongoing. (Several other security companies declined to comment for this story.)

At this point, it’s unclear whether the FBI’s investigation will lead to any concrete result. But two years after the US government charged five Chinese military members for hacking US companies, it’s clear hackers haven’t given up attacking US targets. --


TOPICS: Canada; Crime/Corruption; Government; Russia; US: Arkansas; US: Nevada; US: New York; US: South Carolina; US: Texas; War on Terror
KEYWORDS: 2008; 2011; 201512; 2016election; apartment6; apt6; arkansas; benghazi; blackberry; canada; clintoncash; clintonfoundation; cybersecurity; cyberwar; cyberwarfare; domains; election2016; fbi; hackers; hacking; hillary; hillaryclinton; hitlery; humaabedin; iran; kurtbaumgartner; libya; newyork; opm; pages; peterschweizer; russia; southcarolina; treygowdy; trollfarm; uranium; waronterror; wipewater
Navigation: use the links below to view more comments.
first previous 1-2021-4041-50 last
To: stephenjohnbanker
What in hell happened to our FBI ?......

Simple answer. Holder would not allow any investigations like this while he was Obama's Chief thug/AG!

41 posted on 04/12/2016 3:46:27 PM PDT by Grampa Dave (When The Ballot Box No Longer Counts, The Ammo Box Does! What's In Your Ammo Box?(US Conservative)!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: elpadre
How about based in the White House?? ....and sold to the highest bidder.

You are definitely not alone with that hyposis!

42 posted on 04/12/2016 3:49:03 PM PDT by Grampa Dave (When The Ballot Box No Longer Counts, The Ammo Box Does! What's In Your Ammo Box?(US Conservative)!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: unixfox

Guaranteed if they admit to 5 years, it’s been going on for 5 times that long and longer.


43 posted on 04/12/2016 4:05:21 PM PDT by bgill (CDC site, "We still do not know exactly how people are infected with Ebola")
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox
Thank You Hillary Clinton! "Hillary Rodham Clinton served as United States Secretary of State under President Barack Obama from 2009 to 2013."

Guccifer used to Read her emails and then go out and do the gardening! More info: Hillary's Server Conundrum: Is it going away? and Hillary Clinton's Email and Server Scandal: Summary Review and Recommendations If she's not indicted, we're done as a nation.

Any hacker worth their salt knew Hillary's email server was a back door to our whole Federal database.

When are Hillary Clinton and the guy who knew about her private server, Barack Obama, going to be arrested for Treason? They both knew it would be easily hacked. Did they help them get in? Give them passwords? I wouldn't put it past both of them.

BTW, Guccifer was supposedly extradited here to testify. Does anyone know if he testified, and to whom? Did he talk to the FBI or CIA? Anyone have 'the word' what he said? Will it help Hillary's indictment, especially the back door National Security data taken + all the skinny at the Clinton Foundation and Global Initiative. Is Guccifer still alive? Any word on his whereabouts?

From March 8 Daily Mail: Romanian hacker 'Guccifer' who released some of Hillary Clinton's private emails and George Bush's family photos to be extradited to US

We're either a Nation of Laws, or We are Not.

Hey James Comey, What say You? Are we there yet?

44 posted on 04/12/2016 4:11:06 PM PDT by Art in Idaho (Conservatism is the only Hope for Western Civilization.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Grampa Dave
From the article:

"Anybody who’s been in that network all this long, they could be anywhere and everywhere."

"“This is one of the earlier APTs, they definitely go back further than 2011 [...] more like 2008."

Banging head against the wall.

I hope Comey is enough of a Patriot to blow the lid off of all of this. C'mon James, go Full Monte on them and release all the information after Lynch and Obama refuse to indict! America will love you for it! There are enough American Patriots out here, so don't worry. Hell, you can stay at my place. : )

45 posted on 04/12/2016 4:42:17 PM PDT by Art in Idaho (Conservatism is the only Hope for Western Civilization.)
[ Post Reply | Private Reply | To 40 | View Replies]

To: IYAS9YAS

Yes, I think you’re right, it was Elementary.

Not much of an air-gapped server if you can send email from it of course.


46 posted on 04/12/2016 5:51:03 PM PDT by Darth Reardon (Would I lie to you?)
[ Post Reply | Private Reply | To 30 | View Replies]

To: unixfox

I don’t know how startups are supposed to afford a high level security infrastructure to defend their systems from these intruders.


47 posted on 04/12/2016 5:56:43 PM PDT by Read Write Repeat
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox

NSA?


48 posted on 04/12/2016 6:54:50 PM PDT by GingisK
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox

Maybe Pakistanis?


49 posted on 08/26/2017 12:39:52 AM PDT by piasa
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox

bump


50 posted on 02/24/2018 5:05:18 AM PST by piasa (Attitude adjustments offered here free of charge)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-50 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson