Russia vs. Ukraine: The Biggest Cyber Attack EveršDarknet Diaries Ep. 54: NotPetya
Jack Rhysider
0:00 JACK: Hey, before we get started, check out the episode right before this one.
0:04 Itās called Shadow Brokers.
0:05 It kind of sets you up for this one.
0:08 [MUSIC] This is the story of NotPetya and it took place in the spring of 2017.
0:14 There was some weird tension between the US and Russia during that time.
0:17 Donald Trump was President of the US and itās widely-known that the Russians used the internet
0:21 to meddle with the election.
0:23 I mean, the FBI has indicted twelve hackers who were working with the Russian government
0:26 that have allegedly hacked the DNC and Clintonās e-mail servers which had a critical role in
0:31 the 2016 election.
0:33 The relationship between Trump and Putin is weird and mysterious; a ton of allegations
0:38 are floating around that a lot of back channel support is given to Trump from Russia.
0:43 But what is clear is that Russia likes to quarrel with Ukraine.
0:47 Theyāve been fighting over things for a long time but in the last eight years, things
0:51 have really heated up.
0:53 Russia decided to take a territory of land from Ukraine called Crimea and besides that,
0:57 Russia has been deploying troops into Ukraine, pretty much occupying the area.
1:01 The stuff going on in the Donbass region is just crazy.
1:04 This made tensions between Russia and Ukraine even more elevated.
1:08 Now, for the last six years, Russian troops are still occupying places of Ukraine.
1:13 This was the most blatant land-grab in Europe since World War II and it all happened in
1:17 the last half decade.
1:19 But taking over a large region of Ukraine and occupying them with troops was not the
1:23 extent of what Russia did to Ukraine.
1:25 Thereās so much more terrifying and scary stuff that Russia has done to Ukraine over
1:30 the internet.
1:31 In fact, in this rare case, Iāll even go so far as to say this is a cyber-war.
1:38 JACK (INTRO): [INTRO MUSIC] These are true stories from the dark side of the internet.
1:46 Iām Jack Rhysider.
1:51 This is Darknet Diaries.
1:54 [INTRO MUSIC ENDS]
2:01 JACK: I recently read the book Sandworm.
2:10 It just came out.
2:11 Itās so good; so good that I wanted to have the author come on the show.
2:15 ANDY: Yeah, Iām Andy Greenberg and Iām a senior writer for Wired Magazine and Iām
2:19 the author of this book, Sandworm.
2:21 JACK: A few years back, Wired asked Andy to investigate whether or not thereās been
2:24 a hack so devastating that it would be considered a cyber-war.
2:28 Andy found some very interesting stuff going on in Ukraine at that time and decided to
2:31 look there.
2:32 He got to work researching this and was finding the story was just getting deeper and bigger
2:36 than he expected.
2:38 He found so much stuff that he decided to not just write a magazine article about it,
2:42 but instead a whole book.
2:43 ANDY: Iāve been working on this book Sandworm since about late 2016.
2:49 It tells the unfolding story of this cyber-war in Ukraine.
2:53 In the midst of that, NotPetya happens, this biggest cyber-attack in history.
3:00 I was kind of primed to investigate that and then I spent probably nine months of the book
3:08 research time digging into NotPetya specifically, trying to find really everyone who was willing
3:15 to talk about the experience of witnessing NotPetya unfold, being a victim of this global
3:23 cyber-attack, experts who pulled apart the code, forensic analysts who tied it back to
3:29 known hacker crews.
3:31 This is really the story at the heart of the book that Iāve been working on for about
3:35 three years.
3:36 JACK: Letās get into what Andy found in his years of research which led him to NotPetya,
3:40 the biggest cyber-attack in history.
3:42 Now, Iām pretty sure the goal of this was to create a devasting worm.
3:47 A worm is a virus that will self-replicate and spread among many other computers in the
3:51 network, infecting them, too.
3:53 Then, after it spread, they wanted to take that computer offline permanently, basically
3:57 destroying it and everything on it.
4:00 To accomplish this, they needed a few hacker tools.
4:03 Now, these hackers had a plan for how to get their worm onto computers initially, and weāll
4:07 get into that later.
4:09 But now letās think; once you get your worm onto just one computer [00:05:00] in a network,
4:13 how can you get it to spread to many others?
4:16 Whatever method you use, you want it to work very well, meaning you donāt want it to
4:19 be stopped by someone whoās just patched their computer or has Antivirus on.
4:23 No, this worm has to cut through all of that, so the hackers used a tool called Mimikatz.
4:29 [MUSIC] Mimikatz is crazy and amazing and one of the most frustrating things Iāve
4:33 ever seen.
4:34 I could talk about Mimikatz for hours.
4:36 Itās nuts.
4:37 But the skinny of it is this; on Windows computers is a program called lsass.exe.
4:43 This process is one thatās responsible for enforcing security on Windows computers.
4:48 Yeah, well, get this; when someone logs into a Windows computer, LSASS stores your username
4:53 and password in clear text in the memory.
4:56 Now, this is so LSASS can authenticate that person to other things like shared drives,
5:01 e-mail, SharePoint, etc, without having to ask the user for their password again and
5:05 again.
5:06 This is all fine and good until a French researcher named Benjamin Delpy, or the gentilkiwi, took
5:11 a look in the memory.
5:13 He used a tool to examine what LSASS put in the memory and was amazed to see it storing
5:18 usernames and passwords in clear text, not encrypted at all.
5:23 He built a tool to extract this username and password to display it to anyone who wants
5:27 to see it.
5:28 That tool he made is called Mimikatz and he made it open-source for anyone to use it.
5:33 He kept building on it, teaching it how to trick Windows and authenticating in so many
5:37 other ways like passing hashes and tokens.
5:40 Itās incredibly powerful and insanely successful because get this; suppose you break into a
5:45 computer or sit down at someone elseās computer.
5:47 If you download and run Mimikatz, you can suddenly see every single user whoās logged
5:52 into that computer since it was rebooted.
5:55 Not just their username, but you can see their full password, too.
5:58 On a shared computer like a central jump server, you can potentially get the passwords to a
6:03 huge number of employees and possibly an admin account, too.
6:07 The thing that frustrates me the most about Mimikatz is that for years, Microsoft refused
6:11 to fix this problem.
6:12 They just didnāt acknowledge it or understand it.
6:15 In recent versions of Windows, they have fixed some of it, but Mimikatz continues to evolve,
6:20 getting around whatever fix Microsoft comes up with.
6:23 Even today, on a brand-new Windows computer, itās not secure against Mimikatz by default.
6:28 This is why itās such a powerful exploit.
6:31 Now, once the worm infects a computer and spreads, the last thing it needs to do is
6:36 destroy that computer.
6:38 The goal of this attack was to permanently destroy as many computers as possible.
6:42 The best way to do that remotely is to encrypt everything on it, make it useless unless you
6:46 have the decryption key.
6:48 This is typically known as ransomware but I donāt think these hackers had any intension
6:52 on making money off this.
6:53 Their goal was to destroy computers and ransomware was just the perfect tool to do that.
6:58 The name of the ransomware they decided to use was a modified version of Petya.
7:02 Itāll infect the system at the master boot record, instruct the machine to reboot, and
7:07 upon rebooting itāll encrypt that file system, preventing it from working at all anymore.
7:12 Itāll then show this screen saying your files have been encrypted and you need to
7:16 pay to get it unencrypted.
7:18 Now you combine these two tools into a worm and instruct it to spread through the network.
7:22 Itās very effective just this by itself.
7:26 Computers that are fully-patched and updated can get their passwords taken from memory
7:29 and use that to spread to other computers quite easily.
7:32 The more systems it gets into, the more usernames and passwords it collects, and it just becomes
7:37 unstoppable at some point.
7:39 It could potentially encrypt all hard drives in a network but even though thatās a powerful
7:44 one-two combo, it might not be a knockout blow.
7:48 What if those computers it initially infects didnāt have any extra passwords to steal
7:52 or something?
7:53 Hm, so another tool was added to this worm, something called EternalBlue.
7:58 ANDY: [MUSIC] EternalBlue was probably the most powerful of all of the hacking tools
8:04 dumped onto the internet by this very mysterious group called the Shadow Brokers.
8:09 The Shadow Brokers appeared in the summer of 2016 and just started periodically leaking
8:14 NSA hacking tools onto the internet.
8:17 These are full, working, zero-day exploits in some cases.
8:20 JACK: Yeah, in the previous episode we heard all about what the Shadow Brokers did, but
8:25 it was their last dump where they handed the world a devastating hacker tool.
8:29 ANDY: It included this hacking tool called EternalBlue which exploited a vulnerability
8:36 in a Windows function called Server Message Block that allows machines to essentially
8:42 share information between themselves.
8:45 By exploiting that SMB vulnerability, EternalBlue could basically run code remotely on any Windows
8:53 machine that was vulnerable anywhere in the world.
8:58 It turned out that the NSA had actually worked with Microsoft to try to warn everyone about
9:04 this zero-day when the Shadow Brokers first appeared.
9:07 There was a patch for this SMB vulnerability but of course, as with [00:10:00] all patches,
9:12 it was kind of an epidemiological problem trying to get people all around the world
9:16 to implement this patch.
9:18 When EternalBlue went public, there were still countless thousands, or hundreds of thousands
9:24 of machines, really, that were still vulnerable.
9:25 JACK: With EternalBlue in the hands of every hacker, the world was about to be sucker-punched
9:30 in ways it never imagined.
9:32 EternalBlue is an exploit to get into Windows computers.
9:35 It just bypasses the username and password altogether and lets the hacker right in.
9:39 From there, they can look at files, upload things, issue commands, do whatever they want.
9:44 Yeah, while Windows had a patch for this, not everyone was applying their patches, so
9:50 the chances of this working ā theyāre still high, probably twenty to fifty percent,
9:55 and that just might be enough to get that worm through some difficult places that Mimikatz
10:00 couldnāt get into.
10:02 Hereās the combo for this hack; [MUSIC] first, if the worm could get onto a system
10:07 somehow and then run Mimikatz to get all the usernames and passwords that have logged into
10:11 that computer, then it could take those usernames and passwords and try to log into all its
10:16 neighborsā computers to see maybe it can get into those too, and collect more usernames
10:21 and passwords along the way.
10:22 By golly, with a list of usernames and passwords to try, it would be able to successfully get
10:27 into a lot of computers to infect them, too.
10:30 But if it couldnāt login like that, it would then try to use EternalBlue to see if that
10:35 system was unpatched and exploit it that way.
10:38 The worm would try two very powerful and dangerous ways to get into every computer on the network.
10:45 Once the virus tried to spread as far as it could, it would then infect it with ransomware,
10:51 encrypting the whole thing, making it useless, and then rebooting the machine so itās unusable.
10:56 This would be an extremely powerful combo that certainly could be a knockout blow.
11:02 Now, the target of this attack was Ukraine and the goal was to take out as many computers
11:06 as possible in Ukraine; businesses, government agencies, doesnāt matter.
11:11 Everything.
11:12 Take down all of Ukraineās network.
11:14 But how can you target an entire country?
11:17 This is both a wide-scale attack but itās also limited in size.
11:21 They didnāt want it to spread through the whole world, just Ukraine.
11:24 Hm, this is a very interesting question and something I bet the hackers thought a long
11:29 time about.
11:30 They ultimately chose to target a small company called Linkos Group.
11:35 ANDY: Linkos Group is a pretty small family-run software business based in a building in western
11:42 Kiev, the capital of Ukraine, in this nondescript building in a kind of dingy neighborhood on
11:49 the edges of Podil, a kind of hipster neighborhood in Kiev.
11:53 In the third floor of that building is a server room full of these pizza box-sized servers
11:59 stacked up.
12:00 One of them was responsible for sending updates to MeDoc, this accounting software that Linkos
12:07 Group sold, their flagship product.
12:08 Itās really like the QuickBooks or TurboTax of Ukraine.
12:16 Anyone who files taxes in Ukraine or really who wants to do business in Ukraine uses this
12:20 software, MeDoc.
12:21 JACK: Hm, you see where this is going?
12:24 MeDoc is like TurboTax but for Ukraine.
12:28 People who need to file their taxes in Ukraine use this software, so if the hackers could
12:33 infect MeDoc with this worm, a spreading, replicating virus, then the attack would only
12:39 hit people who have to do taxes in Ukraine.
12:41 ANDY: In June of 2017, a group of hackers took over that update server and they hijacked
12:48 MeDocās update mechanism to push out their own malware.
12:53 Everyone everywhere in the world who had MeDoc installed suddenly has NotPetya, this worm,
12:58 installed as well.
13:00 JACK: We donāt know how, but they got into that MeDoc update server; maybe a phishing
13:05 e-mail or something.
13:07 But it didnāt matter.
13:08 The stage was set and the biggest cyber-attack in history was about to be launched.
13:13 [MUSIC] On Tuesday, June 27th, 2017, the virus was placed on the MeDoc update server and
13:21 an update was sent to thousands of computers in Ukraine.
13:26 Each and every one of those computers were infected by this virus.
13:30 The seed was planted and was instantly spreading.
13:33 As soon as someone got the update, they were infected, and immediately the worm spread
13:38 to another machine, and another machine, and another, grabbing usernames and trying to
13:43 log into its neighbor, and then using those passwords it would get along the way to spread
13:47 to as many computers as it could in the network, as well as using EternalBlue to get into computers
13:52 it didnāt have the password for.
13:54 As soon as it was infecting a computer, it was rebooting it and encrypting it, rendering
13:58 it useless.
13:59 In a matter of minutes, entire organizations were seeing their networks just go down, like
14:05 a shadow being cast on all the computers.
14:08 Now, all this happened on the day before Ukraineās [00:15:00] constitution day which is the day
14:14 Ukraine celebrates their independence from Russia.
14:17 What was typically supposed to be a slow day leading up to a holiday was a day that some
14:21 people will never forget.
14:23 ANDY: Oleksiy Yasinskiy, this forensic analyst and incident responder for a company in Ukraine
14:28 called Information System Security Partners, described the experience of going to one of
14:34 their clients early that morning, one of the very first victims of NotPetya, Oschadbank,
14:40 this former national bank of Ukraine.
14:44 As he went in, he described entering a building where everyone seemed to be in a kind of state
14:49 of shock because all of their systems had been shut down simultaneously.
14:53 [MUSIC] Around ninety percent of all of the computers in Oschadbank had been hit with
14:57 this mysterious ransomware worm.
15:00 It looked at first like a normal piece of ransomware which encrypts all of your files.
15:05 In fact, in this case, encrypts the entire operating system of the computer.
15:09 There was a message on the screens of Oschadbankās PCs demanding $300 in Bitcoin as a ransom
15:16 before the attackers would unlock the computers.
15:20 But Oleksiy Yasinskiy says that he pretty quickly, as he was doing incident response
15:25 for Oschadbank, could tell that this was something unusual, at least in the sense that it was
15:30 extremely virulent.
15:32 The worm had essentially rampaged through Oschadbankās network until it got access
15:37 to an administratorās credentials.
15:39 Then it had used those credentials to jump out to every machine that that administrator
15:43 had access to, very quickly just saturating the entire network and shutting it down.
15:50 JACK: That day the bank could not do business.
15:53 The people came to work but their terminals were all encrypted and frozen.
15:56 Customers and employees were both very upset that systems were down.
16:00 ANDY: Every one of these computers that had been hit was completely locked and showing
16:04 this ransomware screen demanding $300 in Bitcoin before the hackers would decrypt it and give
16:09 Oschadbankās staff back access to that machine.
16:15 But Oleksiy Yasinskiy and ISSP, over the next hours, would very quickly come to the conclusion
16:24 that this was not really ransomware.
16:25 It was a destructive worm posing as ransomware.
16:30 Even if you paid that $300 in Bitcoin, you were not going to get your files back.
16:33 That was just a kind of thin ruse hiding an act of cyber-war.
16:38 JACK: As incident responders investigated this, they found that the ransomware was similar
16:43 to the Petya ransomware.
16:45 It was originally thought to be Petya but some additional research went into it and
16:49 found this is a new strain.
16:52 It was not Petya.
16:54 Since there was so many people saying that it was not Petya, thatās the name that stuck
16:59 for this virus.
17:01 This would become known as the NotPetya attack on Ukraine.
17:05 After the break, weāll hear just how destructive NotPetya became.
17:09 NotPetya was not just hitting this one bank; it was initially infecting networks through
17:14 the MeDoc software update and then spreading into hundreds of networks, hitting thousands
17:18 of computers through the whole country of Ukraine.
17:20 ANDY: At the same time as Oschadbank was being taken down by NotPetya, it in fact was spreading
17:25 across the entire country of Ukraine.
17:27 JACK: [MUSIC] In just a short time, in a matter of hours, a massive amount of networks and
17:33 computers were permanently down, infected by NotPetya.
17:37 One researcher claimed that over three hundred companies were brought down in Ukraine over
17:41 this attack.
17:42 Pretty much the whole country was infected by this in some way; either you personally
17:46 were down, or your supplier was down, or your neighbor was down, or your client was down.
17:50 It was a catastrophe.
17:52 ANDY: But NotPetya didnāt stop spreading at the borders of Ukraine.
17:56 I mean, no cyber-attack cares about borders, obviously.
18:02 Really, any multinational company that had MeDoc installed was also instantly infected
18:08 with NotPetya.
18:09 That included FedEx, Maersk, the worldās largest [00:20:00] shipping firm, Merck, the
18:15 New Jersey-based pharmaceutical company, Saint-Gobain, the French construction firm, Reckitt Benckiser,
18:21 this UK manufacturing firm, Mondelez, the food company that owns Nabisco and Cadbury,
18:28 and countless others.
18:29 We just knew that initial list that I just named because they were the ones who were
18:33 public companies that had to declare their damages to shareholders.
18:37 But we may never know the full extent of all of the companies that were hit by NotPetya.
18:42 JACK: Of course, if these companies either had MeDoc or were connected to networks of
18:47 companies in Ukraine, or were sharing computers with infected companies, they were also getting
18:52 infected with NotPetya, too.
18:54 ANDY: Counterintuitively, NotPetya also spread into Russia and did really serious damage
18:59 there to the state oil company Rosneft, to the steel maker EVRAZ, to the medical technology
19:06 firm In Vitro.
19:08 Really, everyone who touched Ukraine in any way which of course includes Russia, suffered
19:13 damages from this.
19:14 JACK: Companies all over were scrambling to figure out what happened.
19:19 How do we fix this?
19:20 Is there a way to recover or undo this?
19:24 How do we get stuff working again?
19:25 ANDY: All across Ukraine, essentially, people were figuring out that it was better just
19:30 to shut down your entire network, turn everything off, than watch it be devoured by NotPetya.
19:37 Really, every government agency; the postal service, all of these companies, they were,
19:42 in many cases, shutting down their own networks but usually it was too late.
19:46 NotPetya had often infected the majority of their systems before they could even pull
19:49 the plug.
19:50 JACK: With so many computers down all over the city and country, the feeling must have
19:55 been surreal.
19:56 ANDY: The personal experience of being in the middle of this; I heard it best from this
20:02 guy Pavlo Bondarenko who was an IT administrator at the Ukrainian Health Ministry.
20:07 He had, very early in the day, figured out that they needed to pull the ministryās
20:13 network offline.
20:14 That probably spared the Health Ministry from some terrible damage but nonetheless, he spent
20:19 the whole day fighting off NotPetya and then at the end of the day, he left the office
20:24 to go home, tried to get on the subway [BEEPING], found that NotPetya had actually destroyed
20:32 the contactless payment system that he usually used to swipe in to get onto the Kiev metro.
20:37 [MUSIC] He had to go out to find an ATM where he could get cash to buy a token.
20:42 All of the ATMs that he tried were also paralyzed by NotPetya, one after another.
20:48 [BEEPING] Until he found one ATM that was still working but had a very small cash limit
20:55 and this long line of people trying to get cash.
20:57 He waited in line, got the cash, bought the token, got onto the subway, went to his neighborhood,
21:02 got out, and tried to go grocery shopping.
21:05 [BEEPING] Found that the payment system at the grocery store was down.
21:09 He had to get more cash ācause he had run out, so he had to find another ATM among all
21:15 of the paralyzed ATMs where he could take cash out again.
21:18 Pavlo described that experience as not just being kind of annoying but being disorienting.
21:25 He had found himself in a world where everything was suddenly broken.
21:30 [BEEPING] He described it as a natural disaster except that it was entirely man-made and that
21:38 things had gone very quickly from just seeing what was new on Facebook to asking questions
21:43 like, did he have enough money to buy food for the next week?
21:47 People were asking did they have the medicines that they needed?
21:51 Would they be able to get to work and back?
21:54 It was a kind of fundamental cyber-attack against the basic infrastructure of peopleās
22:02 lives that we had really never seen before.
22:05 JACK: This really scares me.
22:09 This is a major disaster unlike anything any country has ever seen.
22:15 For so much of the countryās infrastructure to be down like this?
22:19 Itās chaos.
22:20 I am not prepared for something like this to happen where I live; to suddenly and without
22:25 notice to not be able to get gas, food, or money?
22:29 To have hospitals turning away people because their network is down?
22:32 In disasters, there isnāt enough emergency crews to help everyone.
22:36 Youāre on your own or youāre at the whim or someone else willing to help you.
22:40 I just think of how connected our whole world is now and to see it so fragile like this
22:46 where one well-crafted, well-timed, well-executed virus can do such an enormous amount of destruction?
22:54 Iām shaken.
22:55 ANDY: I would say that the cyber-war began in Ukraine much earlier.
23:01 [MUSIC] As soon as Ukraine came under repeated, sustained, disruptive cyber-attacks starting
23:08 in the fall of 2015, culminating in two blackouts in late 2015 [00:25:00] and then late 2016,
23:14 that was cyber-war but this was kind of a new stage of the cyber-war, a kind of carpet
23:22 bombing of the whole countryās digital systems.
23:24 In terms of what is cyber war, I would say that Richard Clarke got it right in his book
23:31 in 2009, I think it was, his book Cyber War where he basically defined it as an act by
23:37 a nation stateās hackers designed to disrupt an adversaryās systems.
23:45 I think that thatās at least the most basic definition for cyber-war.
23:50 I think other things that make something a cyber-war are that it affects critical infrastructure,
23:58 that it is massive in scale, that it takes place in the midst of a physical war.
24:06 All of those things are true of ā in fact, the entire campaign of cyber-attacks carried
24:11 out against Ukraine but especially NotPetya, this kind of climax of that whole series of
24:17 attacks.
24:18 JACK: Okay, alright.
24:20 Iām back now.
24:22 I had to pause there for a second and go build my 72-hour kit because this is freaking me
24:28 out.
24:29 I donāt know what to think of this.
24:30 I guess Iām just lucky this didnāt hit the US.
24:32 ANDY: Yeah, I mean, I think a lot of people see what happened to Ukraine and they think
24:36 phew, that could have been us.
24:39 Thatās scary.
24:40 But in fact, what I keep trying to emphasize is that NotPetya did hit us, too.
24:44 It didnāt hit us at the same national scale as Ukraine but it hit American companies.
24:49 It hit western companies; FedEx, Iām talking about FedEx and Merck in New Jersey, and Maerskās
24:56 Terminal also in New Jersey.
24:59 Somehow New Jersey got a lot of damage here.
25:02 But this was not a Ukrainian attack.
25:04 This was an attack that spilled out from Ukraine to the entire world and immediately included
25:08 us, too.
25:09 JACK: Okay, so letās talk about Maersk.
25:11 Maersk is not a Ukrainian company; itās a Danish company.
25:14 Theyāve been the largest shipping company in the world for the last three decades.
25:18 Picture those huge container ships at sea carrying tons of those big metal container
25:22 boxes full of goods.
25:24 Theyāre headquartered in Copenhagen in Denmark, but they were impacted by this, too.
25:29 ANDY: Maersk had one office in Odessa on the Black Sea coast on the south of Ukraine.
25:34 In that office they had one computer, that I know about at least, that had MeDoc installed.
25:38 That was all that it took for Maerskās entire global network to be infected.
25:43 [MUSIC] At Maerskās global headquarters in Copenhagen, this beautiful, blue-windowed
25:49 building on the Copenhagen harborās promenade, staff just noticed all of a sudden on the
25:57 afternoon of June 27th, that screens around the whole building were just turning black.
26:03 One staffer described seeing a wave of screens turning black all around him; black, black,
26:08 black.
26:09 Some staffers started to crowd around the Help Desk in the basement of the building
26:13 but very soon it was clear that this was much larger than that, that every computer in the
26:18 building was being infected.
26:19 IT administrators were soon running down hallways, unplugging computers, running into meeting
26:25 rooms to unplug computers in the middle of meetings, jumping over turnstiles because
26:30 even the turnstiles that control the physical security of the building had been paralyzed
26:34 by this attack.
26:37 They were rushing to really turn off all of the systems because they knew that every second
26:41 meant hundreds or even thousands of more machines that would be compromised.
26:45 But that was really just the digital part of the attack on Maersk.
26:52 Maersk runs this massive global shipping machine with these container ships the size of the
26:59 Empire State Building with another Empire State Buildingās worth of cargo on top of
27:03 them.
27:04 All around the world, those ships were starting to arrive at Maersk-owned terminals everywhere
27:09 in the world, and their systems had been shut down so that nobody even knew what was on
27:14 these gargantuan ships.
27:16 They couldnāt even figure out how to unload them.
27:19 Meanwhile, the real choke pointās at seventeen terminals that were shut down by this.
27:25 Seventeen ports, essentially, all around the world were the gates outside where the trucks
27:31 lined up at the Elizabeth New Jersey APM Terminal owned by Maersk.
27:36 Itās a full square mile-size patch of land in the harbor.
27:42 These massive ships pull up but so do thousands of trucks every day, and they come to this
27:48 checkpoint outside the terminal where theyāre told over this voiceover IP system where to
27:55 go, what to pick up or drop off, and all of that on June 27th instantly shut down.
28:03 [MUSIC] Trucks were arriving at that gate outside the terminal and nobody was talking
28:09 to them.
28:10 They were locked out.
28:11 They had no idea what was going on.
28:13 Maersk couldnāt [00:30:00] even send them an e-mail to explain.
28:16 The trucking companies were entirely in the dark, people were getting furious, the port
28:21 police started to tell them you need to turn your truck around and leave, but they had
28:25 stuff that they had to ship somehow for just-in-time manufacturing processes and perishable goods
28:31 that had to be refrigerated.
28:33 It was just a fiasco and soon, tens of thousands of trucks were lining up at seventeen of Maerskās
28:41 terminals all around the world from Los Angeles to New Jersey.
28:45 JACK: Tens of thousands?
28:46 ANDY: Tens of thousands of trucks in total, yeah, certainly.
28:48 Each one of these terminals had lines of trucks that were miles long.
28:54 From Los Angeles to New Jersey to Algeciras in Spain to the Rotterdam in the Netherlands
29:00 to Mumbai in India; this was a significant chunk of the entire physical operation of
29:08 the worldās largest shipping conglomerate just shut down in an instant.
29:12 JACK: Thatās so frightening.
29:14 ANDY: Yeah, I mean, itās hard to get your head around the scale of this in physical
29:21 terms.
29:22 Itās interesting in part because weāve always been scared, or Iāve always been
29:26 scared of these attacks that directly interact with physical infrastructure like Stuxnet.
29:31 Some of the Ukraine attacks were like that too, the ones that turned off the power and
29:35 utilities, causing the first-ever blackouts caused by hackers.
29:39 But it turns out that if you just destroy tens and tens of thousands of computers, just
29:45 the computers around the world, you can maybe do more physical disruption just by taking
29:51 out all of that digital equipment.
29:54 The data alone, just paralyzing the brains of a corporation like Maersk can do more physical
30:00 disruption than directly attacking the physical equipment.
30:02 I donāt know if thatās an idea you really care about, but itāsā¦
30:06 JACK: Yeah, it puts me in deep thought, this whole thing.
30:09 Everything is on those shipping things, everywhere from diapers to food to medical supplies.
30:14 ANDY: Yeah, yeah.
30:15 What did their ships contain?
30:16 It was just absolutely everything that the modern economy runs on, from manufacturing
30:21 components to food, consumer goods that are part of a just-in-time supply chain.
30:27 I mean, Maersk is really at the heart of the global economy and its operations just kind
30:33 of instantaneously winked out of existence.
30:37 JACK: Hearing this just reminds me about where we were in 2008.
30:42 Certain banks were facing financial crisis in the US and they were deemed too big to
30:45 fail because they were so integrated into our lives.
30:48 The US government bailed them out, giving them billions of dollars to re-stabilize the
30:52 nation.
30:53 Iām starting to think that Maersk is also so interconnected into the US that they might
30:59 also be too big to fail.
31:00 Each ship has one million items on it, crucial items that we need in order to live, but as
31:06 far as I know, the US government or any government did not help Maersk.
31:11 Yeah, the FBI called them to investigate the case but thatās about it.
31:16 Maersk could not solve this problem by themselves and the citizens of the US would suffer until
31:20 Maersk could get back on their feet.
31:22 Because not just the US; the whole world relies on deliveries from Maersk.
31:27 They have shipping yards all over the planet.
31:29 NotPetya had a clear global impact.
31:33 Maersk absolutely needed help.
31:35 Something like 49,000 of their computers were down worldwide which was 100% of the Windows
31:41 computers they had in their network.
31:43 100% of them.
31:45 The only computers that werenāt encrypted were either Linux or Unix systems, or the
31:49 ones that were down before this attack or were offline for this attack.
31:53 Because their network would periodically sync to backups, all their backups and disaster
31:58 recovery centers were wiped, too.
32:00 Their e-mails were down, phones were down.
32:02 You couldnāt even see your contact list on your mobile phone because that relied on
32:05 exchange being up.
32:07 Maersk was in trouble.
32:08 [MUSIC] It wasnāt clear to them at first who was threatening them or what, or why.
32:12 There was so much chaos everywhere, you just didnāt know who all the victims were yet.
32:16 But they called up Microsoft right away and spoke to someone very high up there to discuss
32:21 options.
32:22 Microsoft got busy trying to find solutions to this and they heard lots of complaints
32:26 from other people, too.
32:27 A few days later, they had some news; Microsoft called back Maersk and told them they cracked
32:33 a decryption key to decrypt the ransomware but the bad news was is they only cracked
32:38 the decryption key for one computer.
32:40 The other problem is that it took them 22,000 compute hours to crack that single key for
32:45 one computer.
32:47 Maersk had 49,000 computers so this wouldnāt work.
32:51 There was no choice; Maersk had lost everything, with no help in sight.
32:54 They didnāt seem to have any way to recover.
32:57 Everything was gone, all backups, too.
33:00 Ransomware was holding it all hostage.
33:01 Now, I heard from a few places that Maersk got in contact with the hackers who made this
33:06 ransomware and there was discussion about prices on it and how much it would cost to
33:11 unlock all of Maerskās computers.
33:13 [00:35:00] This conversation went back and forth between the hackers and Maersk for a
33:17 little while.
33:18 The story goes is that the hackers said themselves that they didnāt expect this to spread so
33:22 far, so quickly.
33:24 It sounds like even the hacker was impressed by how effective it was.
33:28 Ultimately, Maersk decided not to pay for a number of reasons.
33:32 For one, it paints a target on Maerskās back as someone who pays ransoms but also,
33:37 security researchers were suggesting that this isnāt a ransomware; itās a wiper
33:41 and that even if you had the decryption keys, youāre not gonna get your data back.
33:45 There was doubt that this could even be recovered this way.
33:48 But more importantly, Maersk knew they needed to rebuild their network anyway.
33:52 Even with decryption keys, they still needed to go through every computer, unlock it, reconfigure
33:57 it, secure it, check it for any tampering or misconfigurations, and get it back to working
34:01 again.
34:02 They opted just to ignore the ransom and start from scratch.
34:06 But still, this meant a lot of work to do.
34:11 Where do you even start to recover a network this big?
34:14 Well, stay with us because after the break, weāll hear how they got their cargo moving
34:20 again.
34:23 Maersk was screwed without a functioning network so the only option they had was to rebuild
34:27 everything from scratch, their entire network infrastructure.
34:31 They hired Deloitte, a consulting company, to come and help them do incident response.
34:36 ANDY: But they also set up their own emergency recovery center in this building outside of
34:41 London in this town called Maidenhead.
34:44 That building just was swarming with everyone who vaguely worked in IT for Maersk anywhere
34:52 in the world who were all kind of shipped in within days to work 24/7, more or less,
34:59 to rebuild Maerskās global network.
35:01 JACK: Because everyoneās computers werenāt working and they wanted to get people stood
35:04 up again quickly, they came up with a few different plans to get everyone back online.
35:09 They decided to deploy USB sticks to employees with operating systems installed.
35:15 With this, the IT team could stick a bootable operating system on a USB drive, then hand
35:20 it to an employee, and they could just boot to the USB drive and have a working computer.
35:24 Of course, it doesnāt have all their stuff, but at least itās something.
35:27 If that computer went down, they could just grab a new USB stick and boot up, and theyāre
35:31 online again.
35:32 Itās a quick band-aid to get some systems back up.
35:35 Itās a good idea, so Maersk tried to buy three thousand USB drives.
35:40 But this was a problem because even big-box stores like Staples or Best Buy, they only
35:44 have a couple dozen in stock and they needed thousands.
35:48 They quickly wiped the USB supply of anyone who was willing to sell it to them, and then
35:52 they began buying directly from the manufacturer to get them in bulk.
35:56 How long is that gonna take, right?
35:58 Days?
35:59 Weeks?
36:00 This was slowly getting individual users back online but they still needed to rebuild the
36:03 entire IT infrastructure, all the servers and stuff.
36:07 ANDY: As Maersk started that recovery process, really throwing everything they had into that
36:11 Maidenhead building where people were trying to rebuild their network from scratch, the
36:16 very first hurdle that they encountered was that they didnāt have a backup copy of their
36:21 domain controllers which are a kind of core backbone of their network.
36:27 [MUSIC] Maersk has more than a hundred domain controllers and each of them is designed to
36:31 kind of backup to each other.
36:35 If one goes down, itās no big deal because itās backed up to all the other ones.
36:39 Itās this massive redundancy system but what they hadnāt planned for is a situation
36:44 where every single domain controller is wiped at the same time.
36:47 That is exactly what NotPetya did.
36:49 JACK: All of their domain controllers were ruined, wiped, destroyed.
36:54 It was catastrophic.
36:55 This is the heart of the network, the thing that knows everyoneās profile and logins,
37:00 and passwords, and permissions, and so, so much more.
37:03 [00:40:00] It was totally gone.
37:04 Now, typically, youāre gonna have backups for this and they did have backups and redundancy,
37:10 but this worm infected their backups and redundant domain controllers too, so they were gone.
37:15 Maybe in a company this big, you might want to do some sort of weekly snapshot and then
37:20 take that snapshot to some offsite location so in case something like this does happen,
37:25 you can at least go back a week and get something from there.
37:29 But it didnāt seem like they had any of this and they were stuck with pretty much
37:34 no network.
37:35 ANDY: These frantic IT administrators are calling around to every Maersk facility everywhere
37:40 in the world looking for any backup of the domain controllers.
37:43 They finally found it in one place; it was in a datacenter in Ghana that had experienced
37:49 electrical blackouts, just a normal loss of electricity, but the result was that that
37:57 one domain controller had had its data preserved.
38:00 It hadnāt been infected by NotPetya ācause it wasnāt online.
38:03 JACK: One domain controller in Ghana is still working.
38:08 This could be the domain controller that could help stand up all of Maerskās network.
38:12 It became a critical mission to get this domain controller to the disaster recovery center.
38:19 ANDY: They had to get that data from Ghana to Maidenhead.
38:23 They first tried to set up a secure remote connection but the bandwidth of the Ghanaian
38:28 data center wasnāt fast enough so they tried to fly someone from Ghana to London, but the
38:34 Ghanaians didnāt have the right VISAs, so they had to do this kind of crazy relay race
38:39 thing where people flew from London to Nigeria.
38:44 The Ghanaians flew to Nigeria too, and they handed off the data on some sort of physical
38:48 medium and then carried it back to London, drove to Maidenhead, and that was the beginning
38:52 of this weeks and ultimately months-long process of rebuilding Maerskās network.
38:57 JACK: With this one domain controller, they were able to start restoring the network.
39:04 Phew.
39:05 Maersk needed even more help, though.
39:07 They didnāt have a functioning network so they asked partners and clients if they could
39:11 use their network.
39:13 But of course, nobody wanted Maersk on their network since Maersk had a horrible virus.
39:17 Maersk tried hiring more IT people but they couldnāt find anyone qualified or available,
39:23 so they called up whatever companies that were partners and clients and friends of theirs
39:27 and asked could they just hire their IT staff?
39:30 These companies were like, no.
39:32 But they did loan out a few of the IT staff to Maersk; forty engineers, analysts, and
39:37 IT experts were loaned to Maersk and flown in to help recover the network.
39:43 After about nine days of working on it 24/7, they were able to have a functioning network
39:49 again.
39:50 This ultimately cost Maersk 350 million dollars.
39:55 Thatās just the story of how Maersk handled this problem.
39:59 There were over three hundred other organizations that were also hit.
40:03 ANDY: It would hit pretty much every Ukrainian government agency.
40:06 The Minister of Infrastructure, Volodymyr Omelyan, told me that the government was dead
40:13 and it spread to the postal service.
40:16 The entire postal service of Ukraine shut down which includes all of their payment systems
40:20 for sending money, their functions for handing out pensions to people in the country, newspaper
40:26 delivery.
40:27 JACK: But thereās also 74,000 employees at the post office.
40:30 How are those checks going to be issued when all the computers are down?
40:33 Ukraineās Ministry of Health thought they were going to be infected so they just unplugged
40:37 their entire network, forcing themselves to go down which is unthinkable; to unplug yourself
40:42 on purpose.
40:43 ANDY: Twenty-two banks were shut down by NotPetya, six power companies, two airports, four hospitals
40:50 in Kiev alone, the card payment systems in the metro in Kiev and other cities, all of
40:59 the ATMs across the country.
41:00 This was the kind of, I donāt know what you would call it, a kind of full-spectrum
41:05 cyber-war that had really never been seen anywhere else before and it hit Ukraine at
41:11 a national scale.
41:12 JACK: This was a national disaster, an epidemic that caused panic and chaos everywhere.
41:18 Yeah, this is an intentional man-made disaster, an attack that someone wanted to inflict on
41:27 the country of Ukraine.
41:29 Yeah, I think this is a cyber-war which is the first time Iāve ever admitted to saying
41:36 that myself.
41:38 ANDY: [MUSIC] About a week after NotPetya hit, vans full of these militarized Ukrainian
41:47 police pulled up to the Linkos Group headquarters and poured out into the building, up the stairs
41:56 as if they were raiding the Bin Laden compound, pointing semi-automatic rifles at staff, kicking
42:01 down a door.
42:02 [00:45:00] It was all to grab this one server on the third floor of the building that had
42:08 been, in some ways, the genesis of the NotPetya attack.
42:13 But of course, whatās very ironic about that is that it was not the genesis of the
42:18 attack; it was just an instrument of it.
42:20 The real source of that attack was somewhere far away across the internet, ultimately,
42:26 almost certainly in Moscow, hundreds of miles from Kiev.
42:30 JACK: Ah, yes, now we get into the who would do such a thing part of our story.
42:35 Andy here thinks itās Moscow but thatās no easy conclusion to get to.
42:40 Just because Russia and Ukraine are enemies isnāt enough.
42:42 You need more evidence than just that.
42:44 I mean, it might have just been a criminal group of hackers.
42:47 An investigation began on trying to find out what the evidence was behind who did this.
42:52 Of course, that Linkos Group server and their network was analyzed to see what the intrusion
42:56 there looked like.
42:57 Were there any clues left behind with that?
43:00 How did they get in?
43:01 The virus was also analyzed to see if any notes were left on there.
43:04 Maybe some comments or variable names or documentation might give us a clue.
43:08 The virus was analyzed over and over and you can also look at compile times.
43:13 At what time of day was the virus made?
43:15 Like, 1:00 p.m. in Moscow is 5:00 a.m. in the US.
43:19 All these things are worth investigation and writing down.
43:22 ANDY: [MUSIC] Within days of NotPetya hitting, the Slovakian cyber-security firm ESET had
43:30 started to pull together forensic evidence that tied NotPetya to the earlier waves of
43:35 attacks against Ukraine that included the data-destructive attacks against Ukrainian
43:40 companies and government agencies and the blackout attacks that had hit in late 2015,
43:46 late 2016.
43:47 Those attacks, in turn, had been tied to this group Sandworm.
43:50 JACK: The security company ESET got ahold of a copy of NotPetya and studied it extensively.
43:55 They published a report showing all of the evidence that ties this to Sandworm.
44:00 ANDY: Sandworm, this little company iSIGHT Partners had found in 2014, had a Russian
44:07 language how-to manual for using their trojan on an open directory of their command and
44:12 control server.
44:13 If you follow that forensic line all the way back to 2014, itās pretty clear, first of
44:19 all, that who else is gonna be attacking Ukraine for years on end other than the country that
44:24 has also launched a physical invasion into the east of the country and seized Crimea?
44:29 Thatās just common sense but also, we know that this group was Russian-speaking because
44:35 of that file found on the open directory.
44:39 Within days of NotPetya, it was pretty clear to me that this was part of the larger Russian
44:43 cyber-war against Ukraine; that this was not a criminal act, that it was in fact the climax
44:48 of a nation state-sponsored, escalating series of cyber-attacks against a military target.
44:55 For almost nine months I was kind of going crazy trying to understand why none of these
45:01 victims were naming Russia; no government had actually named Russia, NATO had not said
45:06 anything.
45:07 It was weird enough that we had watched this Russian cyber-war unfold in Ukraine for years
45:12 but now it had even hit these multinational companies, many of which were based in the
45:16 west, and still nobody was calling out Russia for this worst-ever-in-history cyber-attack.
45:24 Until finally, nine months after NotPetya hit, the White House put out a statement,
45:29 a very, very short statement that just said yes, NotPetya was the worst cyber-attack in
45:34 history and it was deployed by the Russian military against Ukraine and that there will
45:39 be consequences.
45:41 That statement was in turn backed up with similar statements from all the four other
45:46 Five Eyes, English-speaking nationsā intelligence agencies.
45:52 The US, Canada, New Zealand, Australia, and the UK all simultaneously called out Russia
45:56 as the perpetrator of NotPetya.
45:58 There are still people, and in particular Russians, who question whether NotPetya was
46:03 really a Russian state act but I donāt think weāve ever had all five Five Eyes agree
46:10 publically to call out someone like this before.
46:13 I donāt think thereās really much room for doubt.
46:16 JACK: The FBI also did their own investigation working with some of these international companies
46:20 and Ukrainian companies to learn more.
46:22 But still today, we have no idea what the FBI found in their investigation but for Andy,
46:28 he wanted to learn more about what happened there, so he packed his bags and flew to Ukraine
46:34 to investigate.
46:35 ANDY: [MUSIC] When I was in Ukraine, I talked to the SBU, the Ukrainian equivalent of the
46:43 NSA, and they had told me flat-out that Sandworm was Fancy Bear, APT28, this other Russian
46:52 hacker group that had been named for years as linked to the GRU, Russiaās military
47:00 intelligence agency.
47:01 [00:50:00] I had suspected for a long time, and Iāve heard this from American sources
47:06 too, but it was kind of unsubstantiated that Sandworm was likely the GRU and they were
47:12 the most likely candidate because theyāre part of Russiaās military, Russiaās military
47:18 was invading Ukraine, the GRU had been very active in that invasion.
47:22 But when the Five Eyes said that the Russian military had carried out NotPetya, that for
47:27 me was ultimately the confirmation.
47:29 I should give some credit here also to the Washington Post who, in a story before that
47:35 announcement, said simply that NotPetya was carried out by the GRU.
47:39 JACK: The GRU is Russiaās military intelligence agency.
47:43 Within the GRU are hackers.
47:45 In fact, the FBI has indicted twelve GRU hackers from meddling with the 2016 US election for
47:52 hacking into the DNC.
47:53 Robert Mueller is who brought this indictment forward and I read through it; itās twenty-six
47:57 pages and it explains a lot of details about the GRU and how they hacked the 2016 election.
48:03 It even lists the street address of where these hackers work out of.
48:07 Itās a fascinating read but so far nobody has been indicted for NotPetya and thereās
48:11 been no FBI report for that, either.
48:14 The GRU hackers behind the 2016 election hacking, that hacking group has been called Fancy Bear
48:21 but this group that did NotPetya, something was a little different here.
48:25 It didnāt have the same MO as Fancy Bear so a different name was given to them; Sandworm.
48:32 It might be the same group as Fancy Bear.
48:34 We donāt know.
48:35 My guess is that itās another hacker team just down the hall from Fancy Bear, or on
48:39 another floor working in the same building as Fancy Bear.
48:42 But what we believe is that both Sandworm and Fancy Bear are hacking groups both working
48:47 for Russiaās GRU in Moscow.
48:51 With the address in hand from the earlier indictment, Andy decided to take a trip to
48:54 Moscow to learn more.
48:56 He went right up to the tower that GRU works out of and looked at it.
49:00 ANDY: When I went to Moscow and stood there in the shadow of the tower, this glass building
49:08 on the Moscow canal in northern Moscow that maybe I believed housed Sandworm, the hackers
49:17 responsible for all of this destruction, I had a feeling of futility; that I was so close
49:24 physically to the perpetrators of these attacks and yet I wasnāt gonna get any closer.
49:30 Just as distance had not been a kind of defense against NotPetya, proximity wasnāt really
49:37 enough to bring me any closer to these attackers.
49:40 They were behind a locked gate with armed security guards.
49:46 I knew that I couldnāt just ask for an interview.
49:49 As close as I was to these hackers, that was kind of the end of the story for me and I
49:53 donāt know if I will ever get any closer.
49:58 JACK: [MUSIC] The estimated damages from this attack totaled ten billion dollars.
50:10 This is why this is the largest cyber-attack in history.
50:13 No attack has come close to this amount of damage ever.
50:17 Ten billion dollars; this was catastrophic, enormous.
50:21 It set new records and was very scary.
50:25 Itās scary that all this was done with hacking tools that anyone had access to.
50:29 There was no super-secret hacking tool used here.
50:33 Mimikatz is open-source for anyone to use and EternalBlue was dumped by the Shadow Brokers
50:37 just six months before.
50:40 You could slap any good ransomware on top of it and there you go.
50:43 But wait a minute, this makes me think if Russia were the ones behind Shadow Brokers
50:49 and Russiaās the one that did NotPetya, then why wouldnāt they just keep EternalBlue
50:54 to themselves?
50:55 I wondered this and asked Jake Williams from the last episode.
51:00 Why would they give away EternalBlue and then use it to hack Ukraine, right?
51:05 You would keep that.
51:06 JAKE: Oh, see, I disagree with that.
51:08 Iāve thought a lot about this as well.
51:11 You know, if you look at the NotPetya attack, Iām not sure that when ā a couple things;
51:17 first off, Iām positive that they got better return on investment if it wasnāt information
51:23 operation releasing it and then using it than they would have just using it as an 0-day.
51:27 I think as an 0-day it would have caused absolute panic and honestly the damage from it would
51:32 have been so much more outside of Ukraine.
51:35 I personally donāt believe that the Russians anticipated the level of damage outside of
51:41 Ukraine that actually occurred.
51:43 Honestly, I donāt think the InfoSec community did, either.
51:46 I think that the why did they use it down the road was out there.
51:51 Why give it up in the first place?
51:54 I think a couple things; first off, I have no doubt that they have a similar capability
51:58 or we said at the time, had a similar capability remotely exploited with SMB [00:55:00] vulnerability.
52:04 I think thatās one.
52:05 JACK: Oh, thatās an interesting ā I got your theory right away on that, ācause if
52:08 they publically post it, then they donāt have to expose their zero-day but they can
52:13 expose NSAās zero-day.
52:15 JAKE: Exactly, exactly.
52:17 Separately from that, they take out ā suppose that in April when they go to release this,
52:23 they donāt know that theyāre gonna do NotPetya, right?
52:25 I think thatās actually, I have to tell you, I think that thatās a reasonable assertion
52:29 at that point.
52:31 I think they know theyāre gonna do something.
52:33 I donāt think anybodyās got ā I know, at that point, I think itās clear they know
52:36 theyāre doing a destructive cyber-attack around MeDoc in Ukraine but I donāt think
52:41 itās clear theyāre gonna worm anything.
52:42 I donāt think that was ever part of the decision calculus for release.
52:47 But taking NotPetya completely out of it for a minute; if you are a nation state operation,
52:51 so roll back to the blog post that I was pushing where I was like hey, it is likely ā basically,
52:58 whoever this is, is operating in the interest of Russia where they are effectively shutting
53:03 down or ā I say shutting down; theyāre effectively taking control of the InfoSec/technology
53:10 news cycle with these releases.
53:12 JACK: Hm, besides that, it throws NSA into chaos, right?
53:16 As soon as Shadow Brokers dumps their stuff, there has to be a mad scramble at NSA to try
53:21 to look around at what got dumped and who did it and why and what.
53:25 At the same time, it makes NSA look bad which gives the GRU some top cover to move into
53:30 position and stage a massive attack while the world was dealing with EternalBlue.
53:35 [MUSIC] Gosh, what a future we have set for ourselves, because I donāt think the world
53:40 has learned from this lesson.
53:41 There are still hundreds of thousands of Windows computers still vulnerable to EternalBlue
53:45 out there right now.
53:47 You can just update this any moment and protect yourself.
53:50 But Microsoft, Microsoft still hasnāt patched Mimikatz.
53:54 I mean, they have, okay?
53:56 Theyāve fixed it but more people just find more flaws in the authentication of Windows
54:00 and Mimikatz works again.
54:02 From what Iāve been told, this will never be fixed.
54:05 Not that Microsoft isnāt working hard on it; they are.
54:07 They release fixes all the time.
54:09 Theyāve created this tool called the Microsoft Windows Credential Guard which protects against
54:14 this.
54:15 But if thatās the case, then why isnāt that enabled by default?
54:17 Or why canāt the defaults just be secure and then a system admin is the one who has
54:22 to click the button to make it insecure?
54:24 Insecure by default is never a solution.
54:27 The reason why Mimikatz isnāt just fixed once and for all is because thereās something
54:31 inherently flawed with the way Windows authentication works just as a whole.
54:35 Itās like every door or window in your house; these are the weak points by design because
54:40 theyāre literally holes in your house that things can go in and out of.
54:44 Mimikatz just makes me really mad because itās still a problem and it was used in
54:48 this attack that brought down Ukraine and cost the world ten billion dollars.
54:53 I mean, is there a scenario thatās so devastating to the world that somebody finally does something
54:59 about Windows authentication to make it secure?
55:01 I donāt know, and this is what really makes me mad.
55:05 Aah!
55:06 I will not fear.
55:07 Fear is the mind-killer.
55:09 I will let this pass over me.
55:13 Okay, so while this is the story of NotPetya, itās just a small part of the story.
55:19 Andy Greenberg, our guest in this episode, just published this book called Sandworm which
55:24 goes into great detail about it.
55:26 I mean, the guy flew to Ukraine and Moscow to get to the bottom of all this.
55:30 This is not the only cyber-attack Russia has done to Ukraine; the book outlines so many
55:35 more attacks that are equally as serious and scary you should be aware of.
55:40 In fact, I want to say that this episode only covered like, a fifth of the book, so go get
55:45 Sandworm in any bookstore right now, or get the audiobook and dive in and enjoy because
55:51 itās fantastic.
56:31 JACK (OUTRO): [OUTRO MUSIC] A big
58:28 thank you to Andy Greenberg.
58:30 Your book is amazing, the story is amazing, and I appreciate all the research youāve
58:33 done and coming on the show to tell us this story.
58:41 To learn more about Andy, visit andygreenberg.net or find him on Twitter as @a_greenberg.
58:47 Iāll also have affiliate links to the Sandworm book in the show notes.
58:52 Thanks to Jake Williams once again.
58:54 This show is made by me, harkonen, Jack Rhysider.
58:57 Sound design was done by the dual-eared Andrew Meriwether, editing help this episode by the
59:02 clip-happy Damienne, and our theme music is by the bouncing Breakmaster Cylinder.
59:07 Even though people turn off their phone, yank the battery out, and go sit in that corner
59:11 of their house that gets no WiFi every time I say it, this is Darknet Diaries.