Russia vs. Ukraine: The Biggest Cyber Attack EveršŸŽ™Darknet Diaries Ep. 54: NotPetya

Russia vs. Ukraine: The Biggest Cyber Attack EveršŸŽ™Darknet Diaries Ep. 54: NotPetya

Jack Rhysider

0:00 JACK: Hey, before we get started, check out the episode right before this one.

0:04 It’s called Shadow Brokers.

0:05 It kind of sets you up for this one.

0:08 [MUSIC] This is the story of NotPetya and it took place in the spring of 2017.

0:14 There was some weird tension between the US and Russia during that time.

0:17 Donald Trump was President of the US and it’s widely-known that the Russians used the internet

0:21 to meddle with the election.

0:23 I mean, the FBI has indicted twelve hackers who were working with the Russian government

0:26 that have allegedly hacked the DNC and Clinton’s e-mail servers which had a critical role in

0:31 the 2016 election.

0:33 The relationship between Trump and Putin is weird and mysterious; a ton of allegations

0:38 are floating around that a lot of back channel support is given to Trump from Russia.

0:43 But what is clear is that Russia likes to quarrel with Ukraine.

0:47 They’ve been fighting over things for a long time but in the last eight years, things

0:51 have really heated up.

0:53 Russia decided to take a territory of land from Ukraine called Crimea and besides that,

0:57 Russia has been deploying troops into Ukraine, pretty much occupying the area.

1:01 The stuff going on in the Donbass region is just crazy.

1:04 This made tensions between Russia and Ukraine even more elevated.

1:08 Now, for the last six years, Russian troops are still occupying places of Ukraine.

1:13 This was the most blatant land-grab in Europe since World War II and it all happened in

1:17 the last half decade.

1:19 But taking over a large region of Ukraine and occupying them with troops was not the

1:23 extent of what Russia did to Ukraine.

1:25 There’s so much more terrifying and scary stuff that Russia has done to Ukraine over

1:30 the internet.

1:31 In fact, in this rare case, I’ll even go so far as to say this is a cyber-war.

1:38 JACK (INTRO): [INTRO MUSIC] These are true stories from the dark side of the internet.

1:46 I’m Jack Rhysider.

1:51 This is Darknet Diaries.

1:54 [INTRO MUSIC ENDS]

2:01 JACK: I recently read the book Sandworm.

2:10 It just came out.

2:11 It’s so good; so good that I wanted to have the author come on the show.

2:15 ANDY: Yeah, I’m Andy Greenberg and I’m a senior writer for Wired Magazine and I’m

2:19 the author of this book, Sandworm.

2:21 JACK: A few years back, Wired asked Andy to investigate whether or not there’s been

2:24 a hack so devastating that it would be considered a cyber-war.

2:28 Andy found some very interesting stuff going on in Ukraine at that time and decided to

2:31 look there.

2:32 He got to work researching this and was finding the story was just getting deeper and bigger

2:36 than he expected.

2:38 He found so much stuff that he decided to not just write a magazine article about it,

2:42 but instead a whole book.

2:43 ANDY: I’ve been working on this book Sandworm since about late 2016.

2:49 It tells the unfolding story of this cyber-war in Ukraine.

2:53 In the midst of that, NotPetya happens, this biggest cyber-attack in history.

3:00 I was kind of primed to investigate that and then I spent probably nine months of the book

3:08 research time digging into NotPetya specifically, trying to find really everyone who was willing

3:15 to talk about the experience of witnessing NotPetya unfold, being a victim of this global

3:23 cyber-attack, experts who pulled apart the code, forensic analysts who tied it back to

3:29 known hacker crews.

3:31 This is really the story at the heart of the book that I’ve been working on for about

3:35 three years.

3:36 JACK: Let’s get into what Andy found in his years of research which led him to NotPetya,

3:40 the biggest cyber-attack in history.

3:42 Now, I’m pretty sure the goal of this was to create a devasting worm.

3:47 A worm is a virus that will self-replicate and spread among many other computers in the

3:51 network, infecting them, too.

3:53 Then, after it spread, they wanted to take that computer offline permanently, basically

3:57 destroying it and everything on it.

4:00 To accomplish this, they needed a few hacker tools.

4:03 Now, these hackers had a plan for how to get their worm onto computers initially, and we’ll

4:07 get into that later.

4:09 But now let’s think; once you get your worm onto just one computer [00:05:00] in a network,

4:13 how can you get it to spread to many others?

4:16 Whatever method you use, you want it to work very well, meaning you don’t want it to

4:19 be stopped by someone who’s just patched their computer or has Antivirus on.

4:23 No, this worm has to cut through all of that, so the hackers used a tool called Mimikatz.

4:29 [MUSIC] Mimikatz is crazy and amazing and one of the most frustrating things I’ve

4:33 ever seen.

4:34 I could talk about Mimikatz for hours.

4:36 It’s nuts.

4:37 But the skinny of it is this; on Windows computers is a program called lsass.exe.

4:43 This process is one that’s responsible for enforcing security on Windows computers.

4:48 Yeah, well, get this; when someone logs into a Windows computer, LSASS stores your username

4:53 and password in clear text in the memory.

4:56 Now, this is so LSASS can authenticate that person to other things like shared drives,

5:01 e-mail, SharePoint, etc, without having to ask the user for their password again and

5:05 again.

5:06 This is all fine and good until a French researcher named Benjamin Delpy, or the gentilkiwi, took

5:11 a look in the memory.

5:13 He used a tool to examine what LSASS put in the memory and was amazed to see it storing

5:18 usernames and passwords in clear text, not encrypted at all.

5:23 He built a tool to extract this username and password to display it to anyone who wants

5:27 to see it.

5:28 That tool he made is called Mimikatz and he made it open-source for anyone to use it.

5:33 He kept building on it, teaching it how to trick Windows and authenticating in so many

5:37 other ways like passing hashes and tokens.

5:40 It’s incredibly powerful and insanely successful because get this; suppose you break into a

5:45 computer or sit down at someone else’s computer.

5:47 If you download and run Mimikatz, you can suddenly see every single user who’s logged

5:52 into that computer since it was rebooted.

5:55 Not just their username, but you can see their full password, too.

5:58 On a shared computer like a central jump server, you can potentially get the passwords to a

6:03 huge number of employees and possibly an admin account, too.

6:07 The thing that frustrates me the most about Mimikatz is that for years, Microsoft refused

6:11 to fix this problem.

6:12 They just didn’t acknowledge it or understand it.

6:15 In recent versions of Windows, they have fixed some of it, but Mimikatz continues to evolve,

6:20 getting around whatever fix Microsoft comes up with.

6:23 Even today, on a brand-new Windows computer, it’s not secure against Mimikatz by default.

6:28 This is why it’s such a powerful exploit.

6:31 Now, once the worm infects a computer and spreads, the last thing it needs to do is

6:36 destroy that computer.

6:38 The goal of this attack was to permanently destroy as many computers as possible.

6:42 The best way to do that remotely is to encrypt everything on it, make it useless unless you

6:46 have the decryption key.

6:48 This is typically known as ransomware but I don’t think these hackers had any intension

6:52 on making money off this.

6:53 Their goal was to destroy computers and ransomware was just the perfect tool to do that.

6:58 The name of the ransomware they decided to use was a modified version of Petya.

7:02 It’ll infect the system at the master boot record, instruct the machine to reboot, and

7:07 upon rebooting it’ll encrypt that file system, preventing it from working at all anymore.

7:12 It’ll then show this screen saying your files have been encrypted and you need to

7:16 pay to get it unencrypted.

7:18 Now you combine these two tools into a worm and instruct it to spread through the network.

7:22 It’s very effective just this by itself.

7:26 Computers that are fully-patched and updated can get their passwords taken from memory

7:29 and use that to spread to other computers quite easily.

7:32 The more systems it gets into, the more usernames and passwords it collects, and it just becomes

7:37 unstoppable at some point.

7:39 It could potentially encrypt all hard drives in a network but even though that’s a powerful

7:44 one-two combo, it might not be a knockout blow.

7:48 What if those computers it initially infects didn’t have any extra passwords to steal

7:52 or something?

7:53 Hm, so another tool was added to this worm, something called EternalBlue.

7:58 ANDY: [MUSIC] EternalBlue was probably the most powerful of all of the hacking tools

8:04 dumped onto the internet by this very mysterious group called the Shadow Brokers.

8:09 The Shadow Brokers appeared in the summer of 2016 and just started periodically leaking

8:14 NSA hacking tools onto the internet.

8:17 These are full, working, zero-day exploits in some cases.

8:20 JACK: Yeah, in the previous episode we heard all about what the Shadow Brokers did, but

8:25 it was their last dump where they handed the world a devastating hacker tool.

8:29 ANDY: It included this hacking tool called EternalBlue which exploited a vulnerability

8:36 in a Windows function called Server Message Block that allows machines to essentially

8:42 share information between themselves.

8:45 By exploiting that SMB vulnerability, EternalBlue could basically run code remotely on any Windows

8:53 machine that was vulnerable anywhere in the world.

8:58 It turned out that the NSA had actually worked with Microsoft to try to warn everyone about

9:04 this zero-day when the Shadow Brokers first appeared.

9:07 There was a patch for this SMB vulnerability but of course, as with [00:10:00] all patches,

9:12 it was kind of an epidemiological problem trying to get people all around the world

9:16 to implement this patch.

9:18 When EternalBlue went public, there were still countless thousands, or hundreds of thousands

9:24 of machines, really, that were still vulnerable.

9:25 JACK: With EternalBlue in the hands of every hacker, the world was about to be sucker-punched

9:30 in ways it never imagined.

9:32 EternalBlue is an exploit to get into Windows computers.

9:35 It just bypasses the username and password altogether and lets the hacker right in.

9:39 From there, they can look at files, upload things, issue commands, do whatever they want.

9:44 Yeah, while Windows had a patch for this, not everyone was applying their patches, so

9:50 the chances of this working – they’re still high, probably twenty to fifty percent,

9:55 and that just might be enough to get that worm through some difficult places that Mimikatz

10:00 couldn’t get into.

10:02 Here’s the combo for this hack; [MUSIC] first, if the worm could get onto a system

10:07 somehow and then run Mimikatz to get all the usernames and passwords that have logged into

10:11 that computer, then it could take those usernames and passwords and try to log into all its

10:16 neighbors’ computers to see maybe it can get into those too, and collect more usernames

10:21 and passwords along the way.

10:22 By golly, with a list of usernames and passwords to try, it would be able to successfully get

10:27 into a lot of computers to infect them, too.

10:30 But if it couldn’t login like that, it would then try to use EternalBlue to see if that

10:35 system was unpatched and exploit it that way.

10:38 The worm would try two very powerful and dangerous ways to get into every computer on the network.

10:45 Once the virus tried to spread as far as it could, it would then infect it with ransomware,

10:51 encrypting the whole thing, making it useless, and then rebooting the machine so it’s unusable.

10:56 This would be an extremely powerful combo that certainly could be a knockout blow.

11:02 Now, the target of this attack was Ukraine and the goal was to take out as many computers

11:06 as possible in Ukraine; businesses, government agencies, doesn’t matter.

11:11 Everything.

11:12 Take down all of Ukraine’s network.

11:14 But how can you target an entire country?

11:17 This is both a wide-scale attack but it’s also limited in size.

11:21 They didn’t want it to spread through the whole world, just Ukraine.

11:24 Hm, this is a very interesting question and something I bet the hackers thought a long

11:29 time about.

11:30 They ultimately chose to target a small company called Linkos Group.

11:35 ANDY: Linkos Group is a pretty small family-run software business based in a building in western

11:42 Kiev, the capital of Ukraine, in this nondescript building in a kind of dingy neighborhood on

11:49 the edges of Podil, a kind of hipster neighborhood in Kiev.

11:53 In the third floor of that building is a server room full of these pizza box-sized servers

11:59 stacked up.

12:00 One of them was responsible for sending updates to MeDoc, this accounting software that Linkos

12:07 Group sold, their flagship product.

12:08 It’s really like the QuickBooks or TurboTax of Ukraine.

12:16 Anyone who files taxes in Ukraine or really who wants to do business in Ukraine uses this

12:20 software, MeDoc.

12:21 JACK: Hm, you see where this is going?

12:24 MeDoc is like TurboTax but for Ukraine.

12:28 People who need to file their taxes in Ukraine use this software, so if the hackers could

12:33 infect MeDoc with this worm, a spreading, replicating virus, then the attack would only

12:39 hit people who have to do taxes in Ukraine.

12:41 ANDY: In June of 2017, a group of hackers took over that update server and they hijacked

12:48 MeDoc’s update mechanism to push out their own malware.

12:53 Everyone everywhere in the world who had MeDoc installed suddenly has NotPetya, this worm,

12:58 installed as well.

13:00 JACK: We don’t know how, but they got into that MeDoc update server; maybe a phishing

13:05 e-mail or something.

13:07 But it didn’t matter.

13:08 The stage was set and the biggest cyber-attack in history was about to be launched.

13:13 [MUSIC] On Tuesday, June 27th, 2017, the virus was placed on the MeDoc update server and

13:21 an update was sent to thousands of computers in Ukraine.

13:26 Each and every one of those computers were infected by this virus.

13:30 The seed was planted and was instantly spreading.

13:33 As soon as someone got the update, they were infected, and immediately the worm spread

13:38 to another machine, and another machine, and another, grabbing usernames and trying to

13:43 log into its neighbor, and then using those passwords it would get along the way to spread

13:47 to as many computers as it could in the network, as well as using EternalBlue to get into computers

13:52 it didn’t have the password for.

13:54 As soon as it was infecting a computer, it was rebooting it and encrypting it, rendering

13:58 it useless.

13:59 In a matter of minutes, entire organizations were seeing their networks just go down, like

14:05 a shadow being cast on all the computers.

14:08 Now, all this happened on the day before Ukraine’s [00:15:00] constitution day which is the day

14:14 Ukraine celebrates their independence from Russia.

14:17 What was typically supposed to be a slow day leading up to a holiday was a day that some

14:21 people will never forget.

14:23 ANDY: Oleksiy Yasinskiy, this forensic analyst and incident responder for a company in Ukraine

14:28 called Information System Security Partners, described the experience of going to one of

14:34 their clients early that morning, one of the very first victims of NotPetya, Oschadbank,

14:40 this former national bank of Ukraine.

14:44 As he went in, he described entering a building where everyone seemed to be in a kind of state

14:49 of shock because all of their systems had been shut down simultaneously.

14:53 [MUSIC] Around ninety percent of all of the computers in Oschadbank had been hit with

14:57 this mysterious ransomware worm.

15:00 It looked at first like a normal piece of ransomware which encrypts all of your files.

15:05 In fact, in this case, encrypts the entire operating system of the computer.

15:09 There was a message on the screens of Oschadbank’s PCs demanding $300 in Bitcoin as a ransom

15:16 before the attackers would unlock the computers.

15:20 But Oleksiy Yasinskiy says that he pretty quickly, as he was doing incident response

15:25 for Oschadbank, could tell that this was something unusual, at least in the sense that it was

15:30 extremely virulent.

15:32 The worm had essentially rampaged through Oschadbank’s network until it got access

15:37 to an administrator’s credentials.

15:39 Then it had used those credentials to jump out to every machine that that administrator

15:43 had access to, very quickly just saturating the entire network and shutting it down.

15:50 JACK: That day the bank could not do business.

15:53 The people came to work but their terminals were all encrypted and frozen.

15:56 Customers and employees were both very upset that systems were down.

16:00 ANDY: Every one of these computers that had been hit was completely locked and showing

16:04 this ransomware screen demanding $300 in Bitcoin before the hackers would decrypt it and give

16:09 Oschadbank’s staff back access to that machine.

16:15 But Oleksiy Yasinskiy and ISSP, over the next hours, would very quickly come to the conclusion

16:24 that this was not really ransomware.

16:25 It was a destructive worm posing as ransomware.

16:30 Even if you paid that $300 in Bitcoin, you were not going to get your files back.

16:33 That was just a kind of thin ruse hiding an act of cyber-war.

16:38 JACK: As incident responders investigated this, they found that the ransomware was similar

16:43 to the Petya ransomware.

16:45 It was originally thought to be Petya but some additional research went into it and

16:49 found this is a new strain.

16:52 It was not Petya.

16:54 Since there was so many people saying that it was not Petya, that’s the name that stuck

16:59 for this virus.

17:01 This would become known as the NotPetya attack on Ukraine.

17:05 After the break, we’ll hear just how destructive NotPetya became.

17:09 NotPetya was not just hitting this one bank; it was initially infecting networks through

17:14 the MeDoc software update and then spreading into hundreds of networks, hitting thousands

17:18 of computers through the whole country of Ukraine.

17:20 ANDY: At the same time as Oschadbank was being taken down by NotPetya, it in fact was spreading

17:25 across the entire country of Ukraine.

17:27 JACK: [MUSIC] In just a short time, in a matter of hours, a massive amount of networks and

17:33 computers were permanently down, infected by NotPetya.

17:37 One researcher claimed that over three hundred companies were brought down in Ukraine over

17:41 this attack.

17:42 Pretty much the whole country was infected by this in some way; either you personally

17:46 were down, or your supplier was down, or your neighbor was down, or your client was down.

17:50 It was a catastrophe.

17:52 ANDY: But NotPetya didn’t stop spreading at the borders of Ukraine.

17:56 I mean, no cyber-attack cares about borders, obviously.

18:02 Really, any multinational company that had MeDoc installed was also instantly infected

18:08 with NotPetya.

18:09 That included FedEx, Maersk, the world’s largest [00:20:00] shipping firm, Merck, the

18:15 New Jersey-based pharmaceutical company, Saint-Gobain, the French construction firm, Reckitt Benckiser,

18:21 this UK manufacturing firm, Mondelez, the food company that owns Nabisco and Cadbury,

18:28 and countless others.

18:29 We just knew that initial list that I just named because they were the ones who were

18:33 public companies that had to declare their damages to shareholders.

18:37 But we may never know the full extent of all of the companies that were hit by NotPetya.

18:42 JACK: Of course, if these companies either had MeDoc or were connected to networks of

18:47 companies in Ukraine, or were sharing computers with infected companies, they were also getting

18:52 infected with NotPetya, too.

18:54 ANDY: Counterintuitively, NotPetya also spread into Russia and did really serious damage

18:59 there to the state oil company Rosneft, to the steel maker EVRAZ, to the medical technology

19:06 firm In Vitro.

19:08 Really, everyone who touched Ukraine in any way which of course includes Russia, suffered

19:13 damages from this.

19:14 JACK: Companies all over were scrambling to figure out what happened.

19:19 How do we fix this?

19:20 Is there a way to recover or undo this?

19:24 How do we get stuff working again?

19:25 ANDY: All across Ukraine, essentially, people were figuring out that it was better just

19:30 to shut down your entire network, turn everything off, than watch it be devoured by NotPetya.

19:37 Really, every government agency; the postal service, all of these companies, they were,

19:42 in many cases, shutting down their own networks but usually it was too late.

19:46 NotPetya had often infected the majority of their systems before they could even pull

19:49 the plug.

19:50 JACK: With so many computers down all over the city and country, the feeling must have

19:55 been surreal.

19:56 ANDY: The personal experience of being in the middle of this; I heard it best from this

20:02 guy Pavlo Bondarenko who was an IT administrator at the Ukrainian Health Ministry.

20:07 He had, very early in the day, figured out that they needed to pull the ministry’s

20:13 network offline.

20:14 That probably spared the Health Ministry from some terrible damage but nonetheless, he spent

20:19 the whole day fighting off NotPetya and then at the end of the day, he left the office

20:24 to go home, tried to get on the subway [BEEPING], found that NotPetya had actually destroyed

20:32 the contactless payment system that he usually used to swipe in to get onto the Kiev metro.

20:37 [MUSIC] He had to go out to find an ATM where he could get cash to buy a token.

20:42 All of the ATMs that he tried were also paralyzed by NotPetya, one after another.

20:48 [BEEPING] Until he found one ATM that was still working but had a very small cash limit

20:55 and this long line of people trying to get cash.

20:57 He waited in line, got the cash, bought the token, got onto the subway, went to his neighborhood,

21:02 got out, and tried to go grocery shopping.

21:05 [BEEPING] Found that the payment system at the grocery store was down.

21:09 He had to get more cash ā€˜cause he had run out, so he had to find another ATM among all

21:15 of the paralyzed ATMs where he could take cash out again.

21:18 Pavlo described that experience as not just being kind of annoying but being disorienting.

21:25 He had found himself in a world where everything was suddenly broken.

21:30 [BEEPING] He described it as a natural disaster except that it was entirely man-made and that

21:38 things had gone very quickly from just seeing what was new on Facebook to asking questions

21:43 like, did he have enough money to buy food for the next week?

21:47 People were asking did they have the medicines that they needed?

21:51 Would they be able to get to work and back?

21:54 It was a kind of fundamental cyber-attack against the basic infrastructure of people’s

22:02 lives that we had really never seen before.

22:05 JACK: This really scares me.

22:09 This is a major disaster unlike anything any country has ever seen.

22:15 For so much of the country’s infrastructure to be down like this?

22:19 It’s chaos.

22:20 I am not prepared for something like this to happen where I live; to suddenly and without

22:25 notice to not be able to get gas, food, or money?

22:29 To have hospitals turning away people because their network is down?

22:32 In disasters, there isn’t enough emergency crews to help everyone.

22:36 You’re on your own or you’re at the whim or someone else willing to help you.

22:40 I just think of how connected our whole world is now and to see it so fragile like this

22:46 where one well-crafted, well-timed, well-executed virus can do such an enormous amount of destruction?

22:54 I’m shaken.

22:55 ANDY: I would say that the cyber-war began in Ukraine much earlier.

23:01 [MUSIC] As soon as Ukraine came under repeated, sustained, disruptive cyber-attacks starting

23:08 in the fall of 2015, culminating in two blackouts in late 2015 [00:25:00] and then late 2016,

23:14 that was cyber-war but this was kind of a new stage of the cyber-war, a kind of carpet

23:22 bombing of the whole country’s digital systems.

23:24 In terms of what is cyber war, I would say that Richard Clarke got it right in his book

23:31 in 2009, I think it was, his book Cyber War where he basically defined it as an act by

23:37 a nation state’s hackers designed to disrupt an adversary’s systems.

23:45 I think that that’s at least the most basic definition for cyber-war.

23:50 I think other things that make something a cyber-war are that it affects critical infrastructure,

23:58 that it is massive in scale, that it takes place in the midst of a physical war.

24:06 All of those things are true of – in fact, the entire campaign of cyber-attacks carried

24:11 out against Ukraine but especially NotPetya, this kind of climax of that whole series of

24:17 attacks.

24:18 JACK: Okay, alright.

24:20 I’m back now.

24:22 I had to pause there for a second and go build my 72-hour kit because this is freaking me

24:28 out.

24:29 I don’t know what to think of this.

24:30 I guess I’m just lucky this didn’t hit the US.

24:32 ANDY: Yeah, I mean, I think a lot of people see what happened to Ukraine and they think

24:36 phew, that could have been us.

24:39 That’s scary.

24:40 But in fact, what I keep trying to emphasize is that NotPetya did hit us, too.

24:44 It didn’t hit us at the same national scale as Ukraine but it hit American companies.

24:49 It hit western companies; FedEx, I’m talking about FedEx and Merck in New Jersey, and Maersk’s

24:56 Terminal also in New Jersey.

24:59 Somehow New Jersey got a lot of damage here.

25:02 But this was not a Ukrainian attack.

25:04 This was an attack that spilled out from Ukraine to the entire world and immediately included

25:08 us, too.

25:09 JACK: Okay, so let’s talk about Maersk.

25:11 Maersk is not a Ukrainian company; it’s a Danish company.

25:14 They’ve been the largest shipping company in the world for the last three decades.

25:18 Picture those huge container ships at sea carrying tons of those big metal container

25:22 boxes full of goods.

25:24 They’re headquartered in Copenhagen in Denmark, but they were impacted by this, too.

25:29 ANDY: Maersk had one office in Odessa on the Black Sea coast on the south of Ukraine.

25:34 In that office they had one computer, that I know about at least, that had MeDoc installed.

25:38 That was all that it took for Maersk’s entire global network to be infected.

25:43 [MUSIC] At Maersk’s global headquarters in Copenhagen, this beautiful, blue-windowed

25:49 building on the Copenhagen harbor’s promenade, staff just noticed all of a sudden on the

25:57 afternoon of June 27th, that screens around the whole building were just turning black.

26:03 One staffer described seeing a wave of screens turning black all around him; black, black,

26:08 black.

26:09 Some staffers started to crowd around the Help Desk in the basement of the building

26:13 but very soon it was clear that this was much larger than that, that every computer in the

26:18 building was being infected.

26:19 IT administrators were soon running down hallways, unplugging computers, running into meeting

26:25 rooms to unplug computers in the middle of meetings, jumping over turnstiles because

26:30 even the turnstiles that control the physical security of the building had been paralyzed

26:34 by this attack.

26:37 They were rushing to really turn off all of the systems because they knew that every second

26:41 meant hundreds or even thousands of more machines that would be compromised.

26:45 But that was really just the digital part of the attack on Maersk.

26:52 Maersk runs this massive global shipping machine with these container ships the size of the

26:59 Empire State Building with another Empire State Building’s worth of cargo on top of

27:03 them.

27:04 All around the world, those ships were starting to arrive at Maersk-owned terminals everywhere

27:09 in the world, and their systems had been shut down so that nobody even knew what was on

27:14 these gargantuan ships.

27:16 They couldn’t even figure out how to unload them.

27:19 Meanwhile, the real choke point’s at seventeen terminals that were shut down by this.

27:25 Seventeen ports, essentially, all around the world were the gates outside where the trucks

27:31 lined up at the Elizabeth New Jersey APM Terminal owned by Maersk.

27:36 It’s a full square mile-size patch of land in the harbor.

27:42 These massive ships pull up but so do thousands of trucks every day, and they come to this

27:48 checkpoint outside the terminal where they’re told over this voiceover IP system where to

27:55 go, what to pick up or drop off, and all of that on June 27th instantly shut down.

28:03 [MUSIC] Trucks were arriving at that gate outside the terminal and nobody was talking

28:09 to them.

28:10 They were locked out.

28:11 They had no idea what was going on.

28:13 Maersk couldn’t [00:30:00] even send them an e-mail to explain.

28:16 The trucking companies were entirely in the dark, people were getting furious, the port

28:21 police started to tell them you need to turn your truck around and leave, but they had

28:25 stuff that they had to ship somehow for just-in-time manufacturing processes and perishable goods

28:31 that had to be refrigerated.

28:33 It was just a fiasco and soon, tens of thousands of trucks were lining up at seventeen of Maersk’s

28:41 terminals all around the world from Los Angeles to New Jersey.

28:45 JACK: Tens of thousands?

28:46 ANDY: Tens of thousands of trucks in total, yeah, certainly.

28:48 Each one of these terminals had lines of trucks that were miles long.

28:54 From Los Angeles to New Jersey to Algeciras in Spain to the Rotterdam in the Netherlands

29:00 to Mumbai in India; this was a significant chunk of the entire physical operation of

29:08 the world’s largest shipping conglomerate just shut down in an instant.

29:12 JACK: That’s so frightening.

29:14 ANDY: Yeah, I mean, it’s hard to get your head around the scale of this in physical

29:21 terms.

29:22 It’s interesting in part because we’ve always been scared, or I’ve always been

29:26 scared of these attacks that directly interact with physical infrastructure like Stuxnet.

29:31 Some of the Ukraine attacks were like that too, the ones that turned off the power and

29:35 utilities, causing the first-ever blackouts caused by hackers.

29:39 But it turns out that if you just destroy tens and tens of thousands of computers, just

29:45 the computers around the world, you can maybe do more physical disruption just by taking

29:51 out all of that digital equipment.

29:54 The data alone, just paralyzing the brains of a corporation like Maersk can do more physical

30:00 disruption than directly attacking the physical equipment.

30:02 I don’t know if that’s an idea you really care about, but it’s…

30:06 JACK: Yeah, it puts me in deep thought, this whole thing.

30:09 Everything is on those shipping things, everywhere from diapers to food to medical supplies.

30:14 ANDY: Yeah, yeah.

30:15 What did their ships contain?

30:16 It was just absolutely everything that the modern economy runs on, from manufacturing

30:21 components to food, consumer goods that are part of a just-in-time supply chain.

30:27 I mean, Maersk is really at the heart of the global economy and its operations just kind

30:33 of instantaneously winked out of existence.

30:37 JACK: Hearing this just reminds me about where we were in 2008.

30:42 Certain banks were facing financial crisis in the US and they were deemed too big to

30:45 fail because they were so integrated into our lives.

30:48 The US government bailed them out, giving them billions of dollars to re-stabilize the

30:52 nation.

30:53 I’m starting to think that Maersk is also so interconnected into the US that they might

30:59 also be too big to fail.

31:00 Each ship has one million items on it, crucial items that we need in order to live, but as

31:06 far as I know, the US government or any government did not help Maersk.

31:11 Yeah, the FBI called them to investigate the case but that’s about it.

31:16 Maersk could not solve this problem by themselves and the citizens of the US would suffer until

31:20 Maersk could get back on their feet.

31:22 Because not just the US; the whole world relies on deliveries from Maersk.

31:27 They have shipping yards all over the planet.

31:29 NotPetya had a clear global impact.

31:33 Maersk absolutely needed help.

31:35 Something like 49,000 of their computers were down worldwide which was 100% of the Windows

31:41 computers they had in their network.

31:43 100% of them.

31:45 The only computers that weren’t encrypted were either Linux or Unix systems, or the

31:49 ones that were down before this attack or were offline for this attack.

31:53 Because their network would periodically sync to backups, all their backups and disaster

31:58 recovery centers were wiped, too.

32:00 Their e-mails were down, phones were down.

32:02 You couldn’t even see your contact list on your mobile phone because that relied on

32:05 exchange being up.

32:07 Maersk was in trouble.

32:08 [MUSIC] It wasn’t clear to them at first who was threatening them or what, or why.

32:12 There was so much chaos everywhere, you just didn’t know who all the victims were yet.

32:16 But they called up Microsoft right away and spoke to someone very high up there to discuss

32:21 options.

32:22 Microsoft got busy trying to find solutions to this and they heard lots of complaints

32:26 from other people, too.

32:27 A few days later, they had some news; Microsoft called back Maersk and told them they cracked

32:33 a decryption key to decrypt the ransomware but the bad news was is they only cracked

32:38 the decryption key for one computer.

32:40 The other problem is that it took them 22,000 compute hours to crack that single key for

32:45 one computer.

32:47 Maersk had 49,000 computers so this wouldn’t work.

32:51 There was no choice; Maersk had lost everything, with no help in sight.

32:54 They didn’t seem to have any way to recover.

32:57 Everything was gone, all backups, too.

33:00 Ransomware was holding it all hostage.

33:01 Now, I heard from a few places that Maersk got in contact with the hackers who made this

33:06 ransomware and there was discussion about prices on it and how much it would cost to

33:11 unlock all of Maersk’s computers.

33:13 [00:35:00] This conversation went back and forth between the hackers and Maersk for a

33:17 little while.

33:18 The story goes is that the hackers said themselves that they didn’t expect this to spread so

33:22 far, so quickly.

33:24 It sounds like even the hacker was impressed by how effective it was.

33:28 Ultimately, Maersk decided not to pay for a number of reasons.

33:32 For one, it paints a target on Maersk’s back as someone who pays ransoms but also,

33:37 security researchers were suggesting that this isn’t a ransomware; it’s a wiper

33:41 and that even if you had the decryption keys, you’re not gonna get your data back.

33:45 There was doubt that this could even be recovered this way.

33:48 But more importantly, Maersk knew they needed to rebuild their network anyway.

33:52 Even with decryption keys, they still needed to go through every computer, unlock it, reconfigure

33:57 it, secure it, check it for any tampering or misconfigurations, and get it back to working

34:01 again.

34:02 They opted just to ignore the ransom and start from scratch.

34:06 But still, this meant a lot of work to do.

34:11 Where do you even start to recover a network this big?

34:14 Well, stay with us because after the break, we’ll hear how they got their cargo moving

34:20 again.

34:23 Maersk was screwed without a functioning network so the only option they had was to rebuild

34:27 everything from scratch, their entire network infrastructure.

34:31 They hired Deloitte, a consulting company, to come and help them do incident response.

34:36 ANDY: But they also set up their own emergency recovery center in this building outside of

34:41 London in this town called Maidenhead.

34:44 That building just was swarming with everyone who vaguely worked in IT for Maersk anywhere

34:52 in the world who were all kind of shipped in within days to work 24/7, more or less,

34:59 to rebuild Maersk’s global network.

35:01 JACK: Because everyone’s computers weren’t working and they wanted to get people stood

35:04 up again quickly, they came up with a few different plans to get everyone back online.

35:09 They decided to deploy USB sticks to employees with operating systems installed.

35:15 With this, the IT team could stick a bootable operating system on a USB drive, then hand

35:20 it to an employee, and they could just boot to the USB drive and have a working computer.

35:24 Of course, it doesn’t have all their stuff, but at least it’s something.

35:27 If that computer went down, they could just grab a new USB stick and boot up, and they’re

35:31 online again.

35:32 It’s a quick band-aid to get some systems back up.

35:35 It’s a good idea, so Maersk tried to buy three thousand USB drives.

35:40 But this was a problem because even big-box stores like Staples or Best Buy, they only

35:44 have a couple dozen in stock and they needed thousands.

35:48 They quickly wiped the USB supply of anyone who was willing to sell it to them, and then

35:52 they began buying directly from the manufacturer to get them in bulk.

35:56 How long is that gonna take, right?

35:58 Days?

35:59 Weeks?

36:00 This was slowly getting individual users back online but they still needed to rebuild the

36:03 entire IT infrastructure, all the servers and stuff.

36:07 ANDY: As Maersk started that recovery process, really throwing everything they had into that

36:11 Maidenhead building where people were trying to rebuild their network from scratch, the

36:16 very first hurdle that they encountered was that they didn’t have a backup copy of their

36:21 domain controllers which are a kind of core backbone of their network.

36:27 [MUSIC] Maersk has more than a hundred domain controllers and each of them is designed to

36:31 kind of backup to each other.

36:35 If one goes down, it’s no big deal because it’s backed up to all the other ones.

36:39 It’s this massive redundancy system but what they hadn’t planned for is a situation

36:44 where every single domain controller is wiped at the same time.

36:47 That is exactly what NotPetya did.

36:49 JACK: All of their domain controllers were ruined, wiped, destroyed.

36:54 It was catastrophic.

36:55 This is the heart of the network, the thing that knows everyone’s profile and logins,

37:00 and passwords, and permissions, and so, so much more.

37:03 [00:40:00] It was totally gone.

37:04 Now, typically, you’re gonna have backups for this and they did have backups and redundancy,

37:10 but this worm infected their backups and redundant domain controllers too, so they were gone.

37:15 Maybe in a company this big, you might want to do some sort of weekly snapshot and then

37:20 take that snapshot to some offsite location so in case something like this does happen,

37:25 you can at least go back a week and get something from there.

37:29 But it didn’t seem like they had any of this and they were stuck with pretty much

37:34 no network.

37:35 ANDY: These frantic IT administrators are calling around to every Maersk facility everywhere

37:40 in the world looking for any backup of the domain controllers.

37:43 They finally found it in one place; it was in a datacenter in Ghana that had experienced

37:49 electrical blackouts, just a normal loss of electricity, but the result was that that

37:57 one domain controller had had its data preserved.

38:00 It hadn’t been infected by NotPetya ā€˜cause it wasn’t online.

38:03 JACK: One domain controller in Ghana is still working.

38:08 This could be the domain controller that could help stand up all of Maersk’s network.

38:12 It became a critical mission to get this domain controller to the disaster recovery center.

38:19 ANDY: They had to get that data from Ghana to Maidenhead.

38:23 They first tried to set up a secure remote connection but the bandwidth of the Ghanaian

38:28 data center wasn’t fast enough so they tried to fly someone from Ghana to London, but the

38:34 Ghanaians didn’t have the right VISAs, so they had to do this kind of crazy relay race

38:39 thing where people flew from London to Nigeria.

38:44 The Ghanaians flew to Nigeria too, and they handed off the data on some sort of physical

38:48 medium and then carried it back to London, drove to Maidenhead, and that was the beginning

38:52 of this weeks and ultimately months-long process of rebuilding Maersk’s network.

38:57 JACK: With this one domain controller, they were able to start restoring the network.

39:04 Phew.

39:05 Maersk needed even more help, though.

39:07 They didn’t have a functioning network so they asked partners and clients if they could

39:11 use their network.

39:13 But of course, nobody wanted Maersk on their network since Maersk had a horrible virus.

39:17 Maersk tried hiring more IT people but they couldn’t find anyone qualified or available,

39:23 so they called up whatever companies that were partners and clients and friends of theirs

39:27 and asked could they just hire their IT staff?

39:30 These companies were like, no.

39:32 But they did loan out a few of the IT staff to Maersk; forty engineers, analysts, and

39:37 IT experts were loaned to Maersk and flown in to help recover the network.

39:43 After about nine days of working on it 24/7, they were able to have a functioning network

39:49 again.

39:50 This ultimately cost Maersk 350 million dollars.

39:55 That’s just the story of how Maersk handled this problem.

39:59 There were over three hundred other organizations that were also hit.

40:03 ANDY: It would hit pretty much every Ukrainian government agency.

40:06 The Minister of Infrastructure, Volodymyr Omelyan, told me that the government was dead

40:13 and it spread to the postal service.

40:16 The entire postal service of Ukraine shut down which includes all of their payment systems

40:20 for sending money, their functions for handing out pensions to people in the country, newspaper

40:26 delivery.

40:27 JACK: But there’s also 74,000 employees at the post office.

40:30 How are those checks going to be issued when all the computers are down?

40:33 Ukraine’s Ministry of Health thought they were going to be infected so they just unplugged

40:37 their entire network, forcing themselves to go down which is unthinkable; to unplug yourself

40:42 on purpose.

40:43 ANDY: Twenty-two banks were shut down by NotPetya, six power companies, two airports, four hospitals

40:50 in Kiev alone, the card payment systems in the metro in Kiev and other cities, all of

40:59 the ATMs across the country.

41:00 This was the kind of, I don’t know what you would call it, a kind of full-spectrum

41:05 cyber-war that had really never been seen anywhere else before and it hit Ukraine at

41:11 a national scale.

41:12 JACK: This was a national disaster, an epidemic that caused panic and chaos everywhere.

41:18 Yeah, this is an intentional man-made disaster, an attack that someone wanted to inflict on

41:27 the country of Ukraine.

41:29 Yeah, I think this is a cyber-war which is the first time I’ve ever admitted to saying

41:36 that myself.

41:38 ANDY: [MUSIC] About a week after NotPetya hit, vans full of these militarized Ukrainian

41:47 police pulled up to the Linkos Group headquarters and poured out into the building, up the stairs

41:56 as if they were raiding the Bin Laden compound, pointing semi-automatic rifles at staff, kicking

42:01 down a door.

42:02 [00:45:00] It was all to grab this one server on the third floor of the building that had

42:08 been, in some ways, the genesis of the NotPetya attack.

42:13 But of course, what’s very ironic about that is that it was not the genesis of the

42:18 attack; it was just an instrument of it.

42:20 The real source of that attack was somewhere far away across the internet, ultimately,

42:26 almost certainly in Moscow, hundreds of miles from Kiev.

42:30 JACK: Ah, yes, now we get into the who would do such a thing part of our story.

42:35 Andy here thinks it’s Moscow but that’s no easy conclusion to get to.

42:40 Just because Russia and Ukraine are enemies isn’t enough.

42:42 You need more evidence than just that.

42:44 I mean, it might have just been a criminal group of hackers.

42:47 An investigation began on trying to find out what the evidence was behind who did this.

42:52 Of course, that Linkos Group server and their network was analyzed to see what the intrusion

42:56 there looked like.

42:57 Were there any clues left behind with that?

43:00 How did they get in?

43:01 The virus was also analyzed to see if any notes were left on there.

43:04 Maybe some comments or variable names or documentation might give us a clue.

43:08 The virus was analyzed over and over and you can also look at compile times.

43:13 At what time of day was the virus made?

43:15 Like, 1:00 p.m. in Moscow is 5:00 a.m. in the US.

43:19 All these things are worth investigation and writing down.

43:22 ANDY: [MUSIC] Within days of NotPetya hitting, the Slovakian cyber-security firm ESET had

43:30 started to pull together forensic evidence that tied NotPetya to the earlier waves of

43:35 attacks against Ukraine that included the data-destructive attacks against Ukrainian

43:40 companies and government agencies and the blackout attacks that had hit in late 2015,

43:46 late 2016.

43:47 Those attacks, in turn, had been tied to this group Sandworm.

43:50 JACK: The security company ESET got ahold of a copy of NotPetya and studied it extensively.

43:55 They published a report showing all of the evidence that ties this to Sandworm.

44:00 ANDY: Sandworm, this little company iSIGHT Partners had found in 2014, had a Russian

44:07 language how-to manual for using their trojan on an open directory of their command and

44:12 control server.

44:13 If you follow that forensic line all the way back to 2014, it’s pretty clear, first of

44:19 all, that who else is gonna be attacking Ukraine for years on end other than the country that

44:24 has also launched a physical invasion into the east of the country and seized Crimea?

44:29 That’s just common sense but also, we know that this group was Russian-speaking because

44:35 of that file found on the open directory.

44:39 Within days of NotPetya, it was pretty clear to me that this was part of the larger Russian

44:43 cyber-war against Ukraine; that this was not a criminal act, that it was in fact the climax

44:48 of a nation state-sponsored, escalating series of cyber-attacks against a military target.

44:55 For almost nine months I was kind of going crazy trying to understand why none of these

45:01 victims were naming Russia; no government had actually named Russia, NATO had not said

45:06 anything.

45:07 It was weird enough that we had watched this Russian cyber-war unfold in Ukraine for years

45:12 but now it had even hit these multinational companies, many of which were based in the

45:16 west, and still nobody was calling out Russia for this worst-ever-in-history cyber-attack.

45:24 Until finally, nine months after NotPetya hit, the White House put out a statement,

45:29 a very, very short statement that just said yes, NotPetya was the worst cyber-attack in

45:34 history and it was deployed by the Russian military against Ukraine and that there will

45:39 be consequences.

45:41 That statement was in turn backed up with similar statements from all the four other

45:46 Five Eyes, English-speaking nations’ intelligence agencies.

45:52 The US, Canada, New Zealand, Australia, and the UK all simultaneously called out Russia

45:56 as the perpetrator of NotPetya.

45:58 There are still people, and in particular Russians, who question whether NotPetya was

46:03 really a Russian state act but I don’t think we’ve ever had all five Five Eyes agree

46:10 publically to call out someone like this before.

46:13 I don’t think there’s really much room for doubt.

46:16 JACK: The FBI also did their own investigation working with some of these international companies

46:20 and Ukrainian companies to learn more.

46:22 But still today, we have no idea what the FBI found in their investigation but for Andy,

46:28 he wanted to learn more about what happened there, so he packed his bags and flew to Ukraine

46:34 to investigate.

46:35 ANDY: [MUSIC] When I was in Ukraine, I talked to the SBU, the Ukrainian equivalent of the

46:43 NSA, and they had told me flat-out that Sandworm was Fancy Bear, APT28, this other Russian

46:52 hacker group that had been named for years as linked to the GRU, Russia’s military

47:00 intelligence agency.

47:01 [00:50:00] I had suspected for a long time, and I’ve heard this from American sources

47:06 too, but it was kind of unsubstantiated that Sandworm was likely the GRU and they were

47:12 the most likely candidate because they’re part of Russia’s military, Russia’s military

47:18 was invading Ukraine, the GRU had been very active in that invasion.

47:22 But when the Five Eyes said that the Russian military had carried out NotPetya, that for

47:27 me was ultimately the confirmation.

47:29 I should give some credit here also to the Washington Post who, in a story before that

47:35 announcement, said simply that NotPetya was carried out by the GRU.

47:39 JACK: The GRU is Russia’s military intelligence agency.

47:43 Within the GRU are hackers.

47:45 In fact, the FBI has indicted twelve GRU hackers from meddling with the 2016 US election for

47:52 hacking into the DNC.

47:53 Robert Mueller is who brought this indictment forward and I read through it; it’s twenty-six

47:57 pages and it explains a lot of details about the GRU and how they hacked the 2016 election.

48:03 It even lists the street address of where these hackers work out of.

48:07 It’s a fascinating read but so far nobody has been indicted for NotPetya and there’s

48:11 been no FBI report for that, either.

48:14 The GRU hackers behind the 2016 election hacking, that hacking group has been called Fancy Bear

48:21 but this group that did NotPetya, something was a little different here.

48:25 It didn’t have the same MO as Fancy Bear so a different name was given to them; Sandworm.

48:32 It might be the same group as Fancy Bear.

48:34 We don’t know.

48:35 My guess is that it’s another hacker team just down the hall from Fancy Bear, or on

48:39 another floor working in the same building as Fancy Bear.

48:42 But what we believe is that both Sandworm and Fancy Bear are hacking groups both working

48:47 for Russia’s GRU in Moscow.

48:51 With the address in hand from the earlier indictment, Andy decided to take a trip to

48:54 Moscow to learn more.

48:56 He went right up to the tower that GRU works out of and looked at it.

49:00 ANDY: When I went to Moscow and stood there in the shadow of the tower, this glass building

49:08 on the Moscow canal in northern Moscow that maybe I believed housed Sandworm, the hackers

49:17 responsible for all of this destruction, I had a feeling of futility; that I was so close

49:24 physically to the perpetrators of these attacks and yet I wasn’t gonna get any closer.

49:30 Just as distance had not been a kind of defense against NotPetya, proximity wasn’t really

49:37 enough to bring me any closer to these attackers.

49:40 They were behind a locked gate with armed security guards.

49:46 I knew that I couldn’t just ask for an interview.

49:49 As close as I was to these hackers, that was kind of the end of the story for me and I

49:53 don’t know if I will ever get any closer.

49:58 JACK: [MUSIC] The estimated damages from this attack totaled ten billion dollars.

50:10 This is why this is the largest cyber-attack in history.

50:13 No attack has come close to this amount of damage ever.

50:17 Ten billion dollars; this was catastrophic, enormous.

50:21 It set new records and was very scary.

50:25 It’s scary that all this was done with hacking tools that anyone had access to.

50:29 There was no super-secret hacking tool used here.

50:33 Mimikatz is open-source for anyone to use and EternalBlue was dumped by the Shadow Brokers

50:37 just six months before.

50:40 You could slap any good ransomware on top of it and there you go.

50:43 But wait a minute, this makes me think if Russia were the ones behind Shadow Brokers

50:49 and Russia’s the one that did NotPetya, then why wouldn’t they just keep EternalBlue

50:54 to themselves?

50:55 I wondered this and asked Jake Williams from the last episode.

51:00 Why would they give away EternalBlue and then use it to hack Ukraine, right?

51:05 You would keep that.

51:06 JAKE: Oh, see, I disagree with that.

51:08 I’ve thought a lot about this as well.

51:11 You know, if you look at the NotPetya attack, I’m not sure that when – a couple things;

51:17 first off, I’m positive that they got better return on investment if it wasn’t information

51:23 operation releasing it and then using it than they would have just using it as an 0-day.

51:27 I think as an 0-day it would have caused absolute panic and honestly the damage from it would

51:32 have been so much more outside of Ukraine.

51:35 I personally don’t believe that the Russians anticipated the level of damage outside of

51:41 Ukraine that actually occurred.

51:43 Honestly, I don’t think the InfoSec community did, either.

51:46 I think that the why did they use it down the road was out there.

51:51 Why give it up in the first place?

51:54 I think a couple things; first off, I have no doubt that they have a similar capability

51:58 or we said at the time, had a similar capability remotely exploited with SMB [00:55:00] vulnerability.

52:04 I think that’s one.

52:05 JACK: Oh, that’s an interesting – I got your theory right away on that, ā€˜cause if

52:08 they publically post it, then they don’t have to expose their zero-day but they can

52:13 expose NSA’s zero-day.

52:15 JAKE: Exactly, exactly.

52:17 Separately from that, they take out – suppose that in April when they go to release this,

52:23 they don’t know that they’re gonna do NotPetya, right?

52:25 I think that’s actually, I have to tell you, I think that that’s a reasonable assertion

52:29 at that point.

52:31 I think they know they’re gonna do something.

52:33 I don’t think anybody’s got – I know, at that point, I think it’s clear they know

52:36 they’re doing a destructive cyber-attack around MeDoc in Ukraine but I don’t think

52:41 it’s clear they’re gonna worm anything.

52:42 I don’t think that was ever part of the decision calculus for release.

52:47 But taking NotPetya completely out of it for a minute; if you are a nation state operation,

52:51 so roll back to the blog post that I was pushing where I was like hey, it is likely – basically,

52:58 whoever this is, is operating in the interest of Russia where they are effectively shutting

53:03 down or – I say shutting down; they’re effectively taking control of the InfoSec/technology

53:10 news cycle with these releases.

53:12 JACK: Hm, besides that, it throws NSA into chaos, right?

53:16 As soon as Shadow Brokers dumps their stuff, there has to be a mad scramble at NSA to try

53:21 to look around at what got dumped and who did it and why and what.

53:25 At the same time, it makes NSA look bad which gives the GRU some top cover to move into

53:30 position and stage a massive attack while the world was dealing with EternalBlue.

53:35 [MUSIC] Gosh, what a future we have set for ourselves, because I don’t think the world

53:40 has learned from this lesson.

53:41 There are still hundreds of thousands of Windows computers still vulnerable to EternalBlue

53:45 out there right now.

53:47 You can just update this any moment and protect yourself.

53:50 But Microsoft, Microsoft still hasn’t patched Mimikatz.

53:54 I mean, they have, okay?

53:56 They’ve fixed it but more people just find more flaws in the authentication of Windows

54:00 and Mimikatz works again.

54:02 From what I’ve been told, this will never be fixed.

54:05 Not that Microsoft isn’t working hard on it; they are.

54:07 They release fixes all the time.

54:09 They’ve created this tool called the Microsoft Windows Credential Guard which protects against

54:14 this.

54:15 But if that’s the case, then why isn’t that enabled by default?

54:17 Or why can’t the defaults just be secure and then a system admin is the one who has

54:22 to click the button to make it insecure?

54:24 Insecure by default is never a solution.

54:27 The reason why Mimikatz isn’t just fixed once and for all is because there’s something

54:31 inherently flawed with the way Windows authentication works just as a whole.

54:35 It’s like every door or window in your house; these are the weak points by design because

54:40 they’re literally holes in your house that things can go in and out of.

54:44 Mimikatz just makes me really mad because it’s still a problem and it was used in

54:48 this attack that brought down Ukraine and cost the world ten billion dollars.

54:53 I mean, is there a scenario that’s so devastating to the world that somebody finally does something

54:59 about Windows authentication to make it secure?

55:01 I don’t know, and this is what really makes me mad.

55:05 Aah!

55:06 I will not fear.

55:07 Fear is the mind-killer.

55:09 I will let this pass over me.

55:13 Okay, so while this is the story of NotPetya, it’s just a small part of the story.

55:19 Andy Greenberg, our guest in this episode, just published this book called Sandworm which

55:24 goes into great detail about it.

55:26 I mean, the guy flew to Ukraine and Moscow to get to the bottom of all this.

55:30 This is not the only cyber-attack Russia has done to Ukraine; the book outlines so many

55:35 more attacks that are equally as serious and scary you should be aware of.

55:40 In fact, I want to say that this episode only covered like, a fifth of the book, so go get

55:45 Sandworm in any bookstore right now, or get the audiobook and dive in and enjoy because

55:51 it’s fantastic.

56:31 JACK (OUTRO): [OUTRO MUSIC] A big

58:28 thank you to Andy Greenberg.

58:30 Your book is amazing, the story is amazing, and I appreciate all the research you’ve

58:33 done and coming on the show to tell us this story.

58:41 To learn more about Andy, visit andygreenberg.net or find him on Twitter as @a_greenberg.

58:47 I’ll also have affiliate links to the Sandworm book in the show notes.

58:52 Thanks to Jake Williams once again.

58:54 This show is made by me, harkonen, Jack Rhysider.

58:57 Sound design was done by the dual-eared Andrew Meriwether, editing help this episode by the

59:02 clip-happy Damienne, and our theme music is by the bouncing Breakmaster Cylinder.

59:07 Even though people turn off their phone, yank the battery out, and go sit in that corner

59:11 of their house that gets no WiFi every time I say it, this is Darknet Diaries.

Study with Looplines Download Captions Watch on YouTube