Attribution 2.0: When Code Reuse Brings Down the House of Cards

No ratings

Presented at bluehat 2018 by

In June 2016, Motherboard’s Lorenzo Franceschi-Bicchierai interviewed the alleged DNC (hacker Guccifer 2.0. When asked about Russian metadata in the documents he leaked, Guccifer 2.0, a self-proclaimed Romanian, said “it is my ‘filigran’ ”. ‘Filigran’ is an odd word and almost never used in casual conversations; some younger people may have never heard it before. Translated into English however, it means “watermark”. Similarly, translating “watermark” from English into Romanian results in “ filigran ”. This and other “watermarks” effectively gave Guccifer 2.0 away as not being Romanian but simply using Google Translate to talk to journalists. In the end, it was his usage of “watermarks” that exposed him.How about code? Are there such things as “watermarks” for x86 executable code? During 2017, several high-profile incidents occurred that had something in common - they were all difficult to attribute or associate with any previously known actor. These include WannaCry , NotPetya , Shadowpad and the CCleaner supply chain attack. Building on our experience from handling WannaCry and NotPetya and combining it with Yara rules and big data, we have been able to associate Shadowpad with an APT group that uses the Winnti malware and the CCleaner backdoor with the Axiom APT group.